Vulnerabilities (CVE)

Join the Common Vulnerabilities and Exposures (CVE) community and start to get notified about new vulnerabilities.

Filtered by vendor Cgminer Project Subscribe
Total 4 CVE
CVE Vendors Products Updated CVSS v2 CVSS v3
CVE-2018-10058 2 Bfgminer, Cgminer Project 2 Bfgminer, Cgminer 2020-08-24 6.5 MEDIUM 8.8 HIGH
The remote management interface of cgminer 4.10.0 and bfgminer 5.5.0 allows an authenticated remote attacker to execute arbitrary code due to a stack-based buffer overflow in the addpool, failover-only, poolquota, and save command handlers.
CVE-2018-10057 2 Bfgminer, Cgminer Project 2 Bfgminer, Cgminer 2018-07-27 4.0 MEDIUM 6.5 MEDIUM
The remote management interface of cgminer 4.10.0 and bfgminer 5.5.0 allows an authenticated remote attacker to write the miner configuration file to arbitrary locations on the server due to missing basedir restrictions (absolute directory traversal).
CVE-2014-4503 2 Cgminer Project, Sgminer Project 2 Cgminer, Sgminer 2014-07-23 4.3 MEDIUM N/A
The parse_notify function in util.c in sgminer before 4.2.2 and cgminer 3.3.0 through 4.0.1 allows man-in-the-middle attackers to cause a denial of service (application exit) via a crafted (1) bbversion, (2) prev_hash, (3) nbit, or (4) ntime parameter in a mining.notify action stratum message.
CVE-2014-4501 3 Bfgminer, Cgminer Project, Sgminer Project 3 Bfgminer, Cgminer, Sgminer 2014-07-23 10.0 HIGH N/A
Multiple stack-based buffer overflows in sgminer before 4.2.2, cgminer before 4.3.5, and BFGMiner before 3.3.0 allow remote pool servers to have unspecified impact via a long URL in a client.reconnect stratum message to the (1) extract_sockaddr or (2) parse_reconnect functions in util.c.