Predictive Vulnerability Intelligence.

Product

  • Product
  • Pricing
  • Documentation

Company

  • About
  • Partnerships
  • Blog
  • Support

Legal

  • Terms
  • Privacy
  • Data Licensing

© 2026 FAUCET Technologies LLC. All rights reserved.

Bfgminer

First CVE: Jul 23, 2014Active for: 12 yearsTotal CVEs: 4

Bfgminer is a specialized cryptocurrency mining application with a narrow but historically significant footprint, where disclosed vulnerabilities have centered on memory-safety issues such as buffer overflows and out-of-bounds writes alongside path-traversal flaws in file handling. These weakness patterns reflect the low-level hardware interaction and file-system access demands inherent to mining software. Live severity, exploitation, and exposure counts are shown alongside this summary.

FAUCET AI Generated
4
Total CVEs
More Total CVEs than 79% of tracked vendors
2.0
Avg CVEs / Product / Year
More Avg CVEs / Product / Year than 80% of tracked vendors
8.8
Avg CVSS Score
Higher Avg CVSS Score than 87% of tracked vendors
0.0%
In CISA KEV
Bottom 1%

Trends Over Time

The number and severity of CVEs published that impact products developed by Bfgminer over time

Volume of CVEsAvg CVSS Base Score
First CVE
Jul 23, 2014
12 years ago
Most Recent CVE
Jun 5, 2018
2,971 days ago

Products(1 total)

Top CVEs

Signals from CVEs in this vendor scope (4 CVEs).

4 CVEs · Highest risk first

CVEPublishedCVSSRiskKEVExploit
CVE-2014-4502HIGH
Multiple heap-based buffer overflows in the parse_notify function in sgminer before 4.2.2, cgminer before 4.3.5, and BFGMiner before 4.1.0 allow remote pool servers to have unspeci
Jul 23, 201410.032NONO
CVE-2014-4501HIGH
Multiple stack-based buffer overflows in sgminer before 4.2.2, cgminer before 4.3.5, and BFGMiner before 3.3.0 allow remote pool servers to have unspecified impact via a long URL i
Jul 23, 201410.031NONO
CVE-2018-10058HIGH
The remote management interface of cgminer 4.10.0 and bfgminer 5.5.0 allows an authenticated remote attacker to execute arbitrary code due to a stack-based buffer overflow in the a
Jun 5, 20188.828NONO
CVE-2018-10057MEDIUM
The remote management interface of cgminer 4.10.0 and bfgminer 5.5.0 allows an authenticated remote attacker to write the miner configuration file to arbitrary locations on the ser
Jun 5, 20186.518NONO
View all 4 CVEs →

CVE Severity & Scoring

Severity distribution of CVEs that affect this vendor's products4 CVEs
25%
75%
Severity distribution among all CVEs352,294 CVEs
45%
40%
11%
MediumHigh
Attack Vector
Local0 (0.0%)
Network2 (50.0%)
Unknown2 (50.0%)
Physical0 (0.0%)
Adjacent Network0 (0.0%)
Attack Complexity
Low2 (50.0%)
High0 (0.0%)
Unknown2 (50.0%)
User Interaction
None2 (50.0%)
Unknown2 (50.0%)
Required0 (0.0%)
Privileges Required
Low2 (50.0%)
High0 (0.0%)
None0 (0.0%)
Unknown2 (50.0%)

Exploit Exposure

Signals from CVEs in this vendor scope (4 CVEs).

CISA KEV
0 CVEs
0.0% of CVEs· Bottom 1%
Metasploit
0 CVEs
0.0% of CVEs· Bottom 1%
Nuclei
0 CVEs
0.0% of CVEs· Bottom 1%
ExploitDB
0 CVEs
0.0% of CVEs· Bottom 1%

Social Chatter

An overview of all social media posts that mention a CVE ID that affects a product developed by Bfgminer.

Media Mentions

Media articles that mention a CVE ID that affects a product developed by Bfgminer — matched by CVE ID, not by vendor name.

Top CNAs Publishing CVEs For Bfgminer's Products

View all 1 CNAs →

Top CWEs