CVE-2024-52913
- EPSS 0.14%
- Veröffentlicht 18.11.2024 04:15:04
- Zuletzt bearbeitet 30.04.2025 16:15:34
In Bitcoin Core before 0.21.0, an attacker could prevent a node from seeing a specific unconfirmed transaction, because transaction re-requests are mishandled.
CVE-2024-52915
- EPSS 1.02%
- Veröffentlicht 18.11.2024 04:15:04
- Zuletzt bearbeitet 30.04.2025 16:16:08
Bitcoin Core before 0.20.0 allows remote attackers to cause a denial of service (memory consumption) via a crafted INV message.
CVE-2024-52916
- EPSS 0.16%
- Veröffentlicht 18.11.2024 04:15:04
- Zuletzt bearbeitet 30.04.2025 16:16:30
Bitcoin Core before 0.15.0 allows a denial of service (OOM kill of a daemon process) via a flood of minimum difficulty headers.
CVE-2024-52917
- EPSS 0.09%
- Veröffentlicht 18.11.2024 04:15:04
- Zuletzt bearbeitet 30.04.2025 16:16:39
Bitcoin Core before 22.0 has a miniupnp infinite loop in which it allocates memory on the basis of random data received over the network, e.g., large M-SEARCH replies from a fake UPnP device.
CVE-2024-52918
- EPSS 0.42%
- Veröffentlicht 18.11.2024 04:15:04
- Zuletzt bearbeitet 15.04.2026 00:35:42
Bitcoin-Qt in Bitcoin Core before 0.20.0 allows remote attackers to cause a denial of service (memory consumption and application crash) via a BIP21 r parameter for a URL that has a large file.
CVE-2024-52919
- EPSS 0.06%
- Veröffentlicht 18.11.2024 04:15:04
- Zuletzt bearbeitet 30.04.2025 16:17:33
Bitcoin Core before 22.0 has a CAddrMan nIdCount integer overflow and resultant assertion failure (and daemon exit) via a flood of addr messages.
CVE-2024-52920
- EPSS 0.85%
- Veröffentlicht 18.11.2024 04:15:04
- Zuletzt bearbeitet 30.04.2025 16:18:12
Bitcoin Core before 0.20.0 allows remote attackers to cause a denial of service (infinite loop) via a malformed GETDATA message.
CVE-2015-20111
- EPSS 3.99%
- Veröffentlicht 18.11.2024 04:15:03
- Zuletzt bearbeitet 15.04.2026 00:35:42
miniupnp before 4c90b87, as used in Bitcoin Core before 0.12 and other products, lacks checks for snprintf return values, leading to a buffer overflow and significant data leak, a different vulnerability than CVE-2019-12107. In Bitcoin Core before 0....
CVE-2024-35202
- EPSS 1.42%
- Veröffentlicht 10.10.2024 13:15:14
- Zuletzt bearbeitet 22.05.2025 16:51:01
Bitcoin Core before 25.0 allows remote attackers to cause a denial of service (blocktxn message-handling assertion and node exit) by including transactions in a blocktxn message that are not committed to in a block's merkle root. FillBlock can be cal...
CVE-2023-50428
- EPSS 0.03%
- Veröffentlicht 09.12.2023 19:15:07
- Zuletzt bearbeitet 21.11.2024 08:36:57
In Bitcoin Core through 26.0 and Bitcoin Knots before 25.1.knots20231115, datacarrier size limits can be bypassed by obfuscating data as code (e.g., with OP_FALSE OP_IF), as exploited in the wild by Inscriptions in 2022 and 2023. NOTE: although this ...