VYPR

Bfgminer

by Luke Jr

Source repositories

CVEs (3)

  • CVE-2018-10057Jun 5, 2018
    risk 0.00cvss epss 0.01

    The remote management interface of cgminer 4.10.0 and bfgminer 5.5.0 allows an authenticated remote attacker to write the miner configuration file to arbitrary locations on the server due to missing basedir restrictions (absolute directory traversal).

  • CVE-2014-4502Jul 23, 2014
    risk 0.00cvss epss 0.01

    Multiple heap-based buffer overflows in the parse_notify function in sgminer before 4.2.2, cgminer before 4.3.5, and BFGMiner before 4.1.0 allow remote pool servers to have unspecified impact via a (1) large or (2) negative value in the Extranonc2_size parameter in a…

  • CVE-2014-4501Jul 23, 2014
    risk 0.00cvss epss 0.00

    Multiple stack-based buffer overflows in sgminer before 4.2.2, cgminer before 4.3.5, and BFGMiner before 3.3.0 allow remote pool servers to have unspecified impact via a long URL in a client.reconnect stratum message to the (1) extract_sockaddr or (2) parse_reconnect functions…