BitcoinCVEs & Vulnerabilities

57 CVEs affecting Bitcoin products, tracked from the National Vulnerability Database, with CVSS/EPSS scores and exploitation status.

Most Affected Products

bitcoin core 311bitcoin-qt 71bitcoind 51wxbitcoin 26bitcoin 3qitcoin-qt 2
CVE-2012-2459MEDIUM

Unspecified vulnerability in bitcoind and Bitcoin-Qt before 0.4.6, 0.5.x before 0.5.5, 0.6.0.x before 0.6.0.7, and 0.6.x before 0.6.2 allows remote attackers to cause a denial of service (block-processing outage and incorrect block count) via unknown behavior on a Bitcoin network.

6 Aug 2012
5.0
CVSS
CVE-2012-1910HIGH

Bitcoin-Qt 0.5.0.x before 0.5.0.5; 0.5.1.x, 0.5.2.x, and 0.5.3.x before 0.5.3.1; and 0.6.x before 0.6.0rc4 on Windows does not use MinGW multithread-safe exception handling, which allows remote attackers to cause a denial of service (application crash) or possibly execute arbitrary code via crafted Bitcoin protocol messages.

6 Aug 2012
7.5
CVSS
CVE-2012-1909MEDIUM

The Bitcoin protocol, as used in bitcoind before 0.4.4, wxBitcoin, Bitcoin-Qt, and other programs, does not properly handle multiple transactions with the same identifier, which allows remote attackers to cause a denial of service (unspendable transaction) by leveraging the ability to create a duplicate coinbase transaction.

6 Aug 2012
5.0
CVSS
CVE-2011-4447MEDIUM

The "encrypt wallet" feature in wxBitcoin and bitcoind 0.4.x before 0.4.1, and 0.5.0rc, does not properly interact with the deletion functionality of BSDDB, which allows context-dependent attackers to obtain unencrypted private keys from Bitcoin wallet files by bypassing the BSDDB interface and reading entries that are marked for deletion.

6 Aug 2012
4.3
CVSS
CVE-2010-5141HIGH

wxBitcoin and bitcoind before 0.3.5 do not properly handle script opcodes in Bitcoin transactions, which allows remote attackers to spend bitcoins owned by other users via unspecified vectors.

6 Aug 2012
7.5
CVSS
CVE-2010-5140MEDIUM

wxBitcoin and bitcoind before 0.3.13 do not properly handle bitcoins associated with Bitcoin transactions that have zero confirmations, which allows remote attackers to cause a denial of service (invalid-transaction flood) by sending low-valued transactions without transaction fees.

6 Aug 2012
5.0
CVSS
CVE-2010-5139HIGH

Integer overflow in wxBitcoin and bitcoind before 0.3.11 allows remote attackers to bypass intended economic restrictions and create many bitcoins via a crafted Bitcoin transaction.

6 Aug 2012
7.5
CVSS
CVE-2010-5138MEDIUM

wxBitcoin and bitcoind 0.3.x allow remote attackers to cause a denial of service (electricity consumption) via a Bitcoin transaction containing multiple OP_CHECKSIG script opcodes.

6 Aug 2012
5.0
CVSS
CVE-2010-5137MEDIUM

wxBitcoin and bitcoind before 0.3.5 allow remote attackers to cause a denial of service (daemon crash) via a Bitcoin transaction containing an OP_LSHIFT script opcode.

6 Aug 2012
5.0
CVSS
← PrevPage 2 / 2Next →
Bitcoin CVEs & Vulnerabilities — 57 Tracked — Page 2