Vulnerabilities > Cgminer Project

DATE CVE VULNERABILITY TITLE RISK
2018-06-05 CVE-2018-10058 Out-of-bounds Write vulnerability in multiple products
The remote management interface of cgminer 4.10.0 and bfgminer 5.5.0 allows an authenticated remote attacker to execute arbitrary code due to a stack-based buffer overflow in the addpool, failover-only, poolquota, and save command handlers.
network
low complexity
cgminer-project bfgminer CWE-787
6.5
2018-06-05 CVE-2018-10057 Path Traversal vulnerability in multiple products
The remote management interface of cgminer 4.10.0 and bfgminer 5.5.0 allows an authenticated remote attacker to write the miner configuration file to arbitrary locations on the server due to missing basedir restrictions (absolute directory traversal).
network
low complexity
bfgminer cgminer-project CWE-22
4.0
2014-07-23 CVE-2014-4503 Improper Input Validation vulnerability in multiple products
The parse_notify function in util.c in sgminer before 4.2.2 and cgminer 3.3.0 through 4.0.1 allows man-in-the-middle attackers to cause a denial of service (application exit) via a crafted (1) bbversion, (2) prev_hash, (3) nbit, or (4) ntime parameter in a mining.notify action stratum message.
4.3
2014-07-23 CVE-2014-4501 Improper Restriction of Operations Within the Bounds of A Memory Buffer vulnerability in multiple products
Multiple stack-based buffer overflows in sgminer before 4.2.2, cgminer before 4.3.5, and BFGMiner before 3.3.0 allow remote pool servers to have unspecified impact via a long URL in a client.reconnect stratum message to the (1) extract_sockaddr or (2) parse_reconnect functions in util.c.
network
low complexity
sgminer-project cgminer-project bfgminer CWE-119
critical
10.0