Vulnerabilities (CVE)

Filtered by vendor Nicehash Subscribe
CVE Vendors Products Updated CVSS v2 CVSS v3
CVE-2019-6122 1 Nicehash 1 Miner 2020-08-24 4.3 MEDIUM 3.1 LOW
A Username Enumeration via Error Message issue was discovered in NiceHash Miner before 2.0.3.0 because an "EMAIL DOES NOT EXIST" error message occurs whenever a submitted email address is incorrect, but there is a different error message for invalid credentials with a correct email address.
CVE-2019-6121 1 Nicehash 1 Miner 2019-11-08 4.3 MEDIUM 3.7 LOW
An issue was discovered in NiceHash Miner before 2.0.3.0. Missing Authorization allows an adversary to can gain access to a miner's information about such as his recent payments, unclaimed Balance, Old Balance (at the time of December 2017 breach) , Projected payout, Mining stats like profitability, Efficiency, Number of workers, etc.. A valid Email address is required in order to retrieve this Information.