Bitcoind
Vendor:
First CVE: Mar 12, 2013 · Active for 13 years
8
Total CVEs
More Total CVEs than 85% of tracked products
4.0
Avg CVEs / Year
Higher CVE frequency than 83% of tracked products
6.5
Avg CVSS
Higher Avg CVSS than 29% of tracked products
0.0%
KEV Rate
Bottom 1%
Trends Over Time
The number and severity of CVEs published that impact Bitcoind over time
Volume of CVEsAvg CVSS Base Score
First CVE
Mar 12, 2013
13 years ago
Most Recent CVE
Jul 5, 2018
2,941 days ago
CVE Severity & Scoring
Bitcoind8 CVEs
50%
50%
All CVEs352,294 CVEs
45%
40%
11%
MediumHigh
Attack Vector
Local0 (0.0%)
Network2 (25.0%)
Unknown6 (75.0%)
Physical0 (0.0%)
Adjacent Network0 (0.0%)
Attack Complexity
Low2 (25.0%)
High0 (0.0%)
Unknown6 (75.0%)
User Interaction
None2 (25.0%)
Unknown6 (75.0%)
Required0 (0.0%)
Privileges Required
Low0 (0.0%)
High0 (0.0%)
None2 (25.0%)
Unknown6 (75.0%)
Top CVEs
Signals from CVEs in this product scope (8 CVEs).
8 CVEs · Highest risk first
| CVE | Published | CVSS | Risk | KEV | Exploit |
|---|---|---|---|---|---|
CVE-2013-3220MEDIUM bitcoind and Bitcoin-Qt before 0.4.9rc2, 0.5.x before 0.5.8rc2, 0.6.x before 0.6.5rc2, and 0.7.x before 0.7.3rc2, and wxBitcoin, do not properly consider whether a block's size cou | Aug 2, 2013 | 6.4 | 27 | NO | NO |
CVE-2013-2292HIGH bitcoind and Bitcoin-Qt 0.8.0 and earlier allow remote attackers to cause a denial of service (electricity consumption) by mining a block to create a nonstandard Bitcoin transactio | Mar 12, 2013 | 7.8 | 26 | NO | NO |
CVE-2016-10724HIGH Bitcoin Core before v0.13.0 allows denial of service (memory exhaustion) triggered by the remote network alert system (deprecated since Q1 2016) if an attacker can sign a message w | Jul 5, 2018 | 7.5 | 24 | NO | NO |
CVE-2012-4684HIGH The alert functionality in bitcoind and Bitcoin-Qt before 0.7.0 supports different character representations of the same signature data, but relies on a hash of this signature, whi | Mar 12, 2013 | 7.8 | 24 | NO | NO |
CVE-2016-10725HIGH In Bitcoin Core before v0.13.0, a non-final alert is able to block the special "final alert" (which is supposed to override all other alerts) because operations occur in the wrong | Jul 5, 2018 | 7.5 | 23 | NO | NO |
CVE-2013-2272MEDIUM The penny-flooding protection mechanism in the CTxMemPool::accept method in bitcoind and Bitcoin-Qt before 0.4.9rc1, 0.5.x before 0.5.8rc1, 0.6.0 before 0.6.0.11rc1, 0.6.1 through | Mar 12, 2013 | 5.0 | 17 | NO | NO |
CVE-2013-2293MEDIUM The CTransaction::FetchInputs method in bitcoind and Bitcoin-Qt before 0.8.0rc1 copies transactions from disk to memory without incrementally checking for spent prevouts, which all | Mar 12, 2013 | 5.0 | 15 | NO | NO |
CVE-2013-2273MEDIUM bitcoind and Bitcoin-Qt before 0.4.9rc1, 0.5.x before 0.5.8rc1, 0.6.0 before 0.6.0.11rc1, 0.6.1 through 0.6.5 before 0.6.5rc1, and 0.7.x before 0.7.3rc1 make it easier for remote a | Mar 12, 2013 | 5.0 | 15 | NO | NO |
Exploit Exposure
Signals from CVEs in this product scope (8 CVEs).
CISA KEV
0 CVEs
0.0% of CVEs· Bottom 1%
Metasploit
0 CVEs
0.0% of CVEs· Bottom 1%
Nuclei
0 CVEs
0.0% of CVEs· Bottom 1%
ExploitDB
0 CVEs
0.0% of CVEs· Bottom 1%
Social Chatter
Signals from CVEs in this product scope (8 CVEs).
Media Mentions
Signals from CVEs in this product scope (8 CVEs).
Top CNAs Publishing CVEs For Bitcoind
Top CWEs
Versions
| Version | CVE Count | Avg CVSS | Avg EPSS | KEV | Exploits |
|---|---|---|---|---|---|
| 0.7.3 | 1 | 6.4 | 2.4% | 0 | 0 |
| 0.7.2 | 4 | 6.0 | 2.2% | 0 | 0 |
| 0.7.1 | 5 | 5.8 | 2.3% | 0 | 0 |
| 0.7.0 | 5 | 5.8 | 2.3% | 0 | 0 |
| 0.6.5 | 1 | 6.4 | 2.4% | 0 | 0 |
| 0.6.4 | 5 | 5.8 | 2.3% | 0 | 0 |
| 0.6.3 | 6 | 6.2 | 2.4% | 0 | 0 |
| 0.6.0.10 | 5 | 5.8 | 2.3% | 0 | 0 |
| 0.6.0.0 | 5 | 5.8 | 2.3% | 0 | 0 |
| 0.5.8 | 1 | 6.4 | 2.4% | 0 | 0 |
| 0.5.7 | 5 | 5.8 | 2.3% | 0 | 0 |
| 0.4.4 | 3 | 6.4 | 2.5% | 0 | 0 |