Vulnerabilities > Bitcoin > Bitcoin Core

DATE CVE VULNERABILITY TITLE RISK
2023-12-09 CVE-2023-50428 In Bitcoin Core through 26.0 and Bitcoin Knots before 25.1.knots20231115, datacarrier size limits can be bypassed by obfuscating data as code (e.g., with OP_FALSE OP_IF), as exploited in the wild by Inscriptions in 2022 and 2023.
network
low complexity
bitcoin bitcoinknots
5.3
2023-07-07 CVE-2023-37192 Missing Encryption of Sensitive Data vulnerability in Bitcoin Core 22.0
Memory management and protection issues in Bitcoin Core v22 allows attackers to modify the stored sending address within the app's memory, potentially allowing them to redirect Bitcoin transactions to wallets of their own choosing.
network
low complexity
bitcoin CWE-311
7.5
2023-05-22 CVE-2023-33297 Resource Exhaustion vulnerability in Bitcoin Core
Bitcoin Core before 24.1, when debug mode is not used, allows attackers to cause a denial of service (e.g., CPU consumption) because draining the inventory-to-send queue is inefficient, as exploited in the wild in May 2023.
network
low complexity
bitcoin CWE-400
7.5
2021-01-26 CVE-2021-3195 Improper Input Validation vulnerability in Bitcoin Core
bitcoind in Bitcoin Core through 0.21.0 can create a new file in an arbitrary directory (e.g., outside the ~/.bitcoin directory) via a dumpwallet RPC call.
network
low complexity
bitcoin CWE-20
7.5
2020-09-10 CVE-2020-14198 Unspecified vulnerability in Bitcoin Core 0.20.0
Bitcoin Core 0.20.0 allows remote denial of service.
network
low complexity
bitcoin
7.5
2020-09-10 CVE-2018-17145 Resource Exhaustion vulnerability in multiple products
Bitcoin Core 0.16.x before 0.16.2 and Bitcoin Knots 0.16.x before 0.16.2 allow remote denial of service via a flood of multiple transaction inv messages with random hashes, aka INVDoS.
5.0
2020-03-16 CVE-2017-12842 Improper Input Validation vulnerability in Bitcoin Core
Bitcoin Core before 0.14 allows an attacker to create an ostensibly valid SPV proof for a payment to a victim who uses an SPV wallet, even if that payment did not actually occur.
network
low complexity
bitcoin CWE-20
5.0
2020-03-12 CVE-2018-20586 Improper Encoding or Escaping of Output vulnerability in Bitcoin Core
bitcoind and Bitcoin-Qt prior to 0.17.1 allow injection of arbitrary data into the debug log via an RPC call.
network
bitcoin CWE-116
4.3
2020-03-12 CVE-2017-18350 Classic Buffer Overflow vulnerability in Bitcoin Core
bitcoind and Bitcoin-Qt prior to 0.15.1 have a stack-based buffer overflow if an attacker-controlled SOCKS proxy server is used.
network
high complexity
bitcoin CWE-120
5.9
2020-03-12 CVE-2015-3641 Unspecified vulnerability in Bitcoin Core
bitcoind and Bitcoin-Qt prior to 0.10.2 allow attackers to cause a denial of service (disabled functionality such as a client application crash) via an "Easy" attack.
network
low complexity
bitcoin
5.0