CVE-2018-17145

Bitcoin Core 0.16.x before 0.16.2 and Bitcoin Knots 0.16.x before 0.16.2 allow remote denial of service via a flood of multiple transaction inv messages with random hashes, aka INVDoS. NOTE: this can also affect other cryptocurrencies, e.g., if they were forked from Bitcoin Core after 2017-11-15.
ProviderTypeBase ScoreAtk. VectorAtk. ComplexityPriv. RequiredVector
NISTNIST
7.5 HIGH
NETWORK
LOW
NONE
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H
mitreCNA
---
---
CVEADP
---
---
Base Score
CVSS 3.x
EPSS Score
Percentile: 77%
VendorProductVersion
bcoinbcoin
𝑥
< 1.0.2
bitcoinbitcoin_core
0.16.0 ≤
𝑥
< 0.16.2
bitcoinknotsbitcoin_knots
0.16.0 ≤
𝑥
< 0.16.2
btcd_projectbtcd
0.3.0:alpha
btcd_projectbtcd
0.3.1:alpha
btcd_projectbtcd
0.3.2:alpha
btcd_projectbtcd
0.3.3:alpha
btcd_projectbtcd
0.4.0:alpha
btcd_projectbtcd
0.5.0:alpha
btcd_projectbtcd
0.6.0:alpha
btcd_projectbtcd
0.7.0:alpha
btcd_projectbtcd
0.8.0:beta
btcd_projectbtcd
0.9.0:beta
btcd_projectbtcd
0.10.0:beta
btcd_projectbtcd
0.11.0:beta
btcd_projectbtcd
0.11.1:beta
btcd_projectbtcd
0.12.0:beta
btcd_projectbtcd
0.13.0:beta
btcd_projectbtcd
0.13.0:beta2
btcd_projectbtcd
0.20.0:beta
btcd_projectbtcd
0.20.1:beta
decreddcrd
𝑥
< 1.5.2
litecoinlitecoin
0.16.0 ≤
𝑥
< 0.16.2
namecoinnamecoin_core
0.16.0 ≤
𝑥
< 0.16.2
𝑥
= Vulnerable software versions