CVE-2024-52912
- EPSS 0.52%
- Veröffentlicht 18.11.2024 04:15:04
- Zuletzt bearbeitet 30.04.2025 16:14:24
Bitcoin Core before 0.21.0 allows a network split that is resultant from an integer overflow (calculating the time offset for newly connecting peers) and an abs64 logic bug.
CVE-2024-52913
- EPSS 0.37%
- Veröffentlicht 18.11.2024 04:15:04
- Zuletzt bearbeitet 30.04.2025 16:15:34
In Bitcoin Core before 0.21.0, an attacker could prevent a node from seeing a specific unconfirmed transaction, because transaction re-requests are mishandled.
CVE-2024-52914
- EPSS 0.51%
- Veröffentlicht 18.11.2024 04:15:04
- Zuletzt bearbeitet 30.04.2025 16:15:51
In Bitcoin Core before 0.18.0, a node could be stalled for hours when processing the orphans of a crafted unconfirmed transaction.
CVE-2024-52916
- EPSS 0.51%
- Veröffentlicht 18.11.2024 04:15:04
- Zuletzt bearbeitet 30.04.2025 16:16:30
Bitcoin Core before 0.15.0 allows a denial of service (OOM kill of a daemon process) via a flood of minimum difficulty headers.
CVE-2024-52917
- EPSS 0.27%
- Veröffentlicht 18.11.2024 04:15:04
- Zuletzt bearbeitet 30.04.2025 16:16:39
Bitcoin Core before 22.0 has a miniupnp infinite loop in which it allocates memory on the basis of random data received over the network, e.g., large M-SEARCH replies from a fake UPnP device.
CVE-2024-52918
- EPSS 0.47%
- Veröffentlicht 18.11.2024 04:15:04
- Zuletzt bearbeitet 15.04.2026 00:35:42
Bitcoin-Qt in Bitcoin Core before 0.20.0 allows remote attackers to cause a denial of service (memory consumption and application crash) via a BIP21 r parameter for a URL that has a large file.
CVE-2024-52919
- EPSS 0.27%
- Veröffentlicht 18.11.2024 04:15:04
- Zuletzt bearbeitet 30.04.2025 16:17:33
Bitcoin Core before 22.0 has a CAddrMan nIdCount integer overflow and resultant assertion failure (and daemon exit) via a flood of addr messages.
CVE-2024-52920
- EPSS 0.61%
- Veröffentlicht 18.11.2024 04:15:04
- Zuletzt bearbeitet 30.04.2025 16:18:12
Bitcoin Core before 0.20.0 allows remote attackers to cause a denial of service (infinite loop) via a malformed GETDATA message.
CVE-2015-20111
- EPSS 1.27%
- Veröffentlicht 18.11.2024 04:15:03
- Zuletzt bearbeitet 15.04.2026 00:35:42
miniupnp before 4c90b87, as used in Bitcoin Core before 0.12 and other products, lacks checks for snprintf return values, leading to a buffer overflow and significant data leak, a different vulnerability than CVE-2019-12107. In Bitcoin Core before 0....
CVE-2024-35202
- EPSS 0.9%
- Veröffentlicht 10.10.2024 13:15:14
- Zuletzt bearbeitet 22.05.2025 16:51:01
Bitcoin Core before 25.0 allows remote attackers to cause a denial of service (blocktxn message-handling assertion and node exit) by including transactions in a blocktxn message that are not committed to in a block's merkle root. FillBlock can be cal...