CVE Feed

    Dashboard / CVE

    7.5
    High

    CVE-2018-13216

    Last Modified: 21 Nov 2024

    The sell function of a smart contract implementation for GreenMed (GRMD), an Ethereum token, has an integer overflow in which "amount * sellPrice" can be zero, consequently reducing a seller's assets.

    Published: 5 Jul 2018
    7.5
    High

    CVE-2018-13217

    Last Modified: 21 Nov 2024

    The sell function of a smart contract implementation for CoinToken, an Ethereum token, has an integer overflow in which "amount * sellPrice" can be zero, consequently reducing a seller's assets.

    Published: 5 Jul 2018
    7.5
    High

    CVE-2018-13218

    Last Modified: 21 Nov 2024

    The sell function of a smart contract implementation for ICO Dollar (ICOD), an Ethereum token, has an integer overflow in which "amount * sellPrice" can be zero, consequently reducing a seller's assets.

    Published: 5 Jul 2018
    7.5
    High

    CVE-2018-13219

    Last Modified: 21 Nov 2024

    The sell function of a smart contract implementation for YourCoin (ICO) (Contract Name: ETH033), an Ethereum token, has an integer overflow in which "amount * sellPrice" can be zero, consequently reducing a seller's assets.

    Published: 5 Jul 2018
    7.5
    High

    CVE-2018-13221

    Last Modified: 21 Nov 2024

    The sell function of a smart contract implementation for Extreme Coin (XT) (Contract Name: ExtremeToken), an Ethereum token, has an integer overflow in which "amount * sellPrice" can be zero, consequently reducing a seller's assets.

    Published: 5 Jul 2018
    7.5
    High

    CVE-2018-13222

    Last Modified: 21 Nov 2024

    The sell function of a smart contract implementation for ObjectToken (OBJ), an Ethereum token, has an integer overflow in which "amount * sellPrice" can be zero, consequently reducing a seller's assets.

    Published: 5 Jul 2018
    7.5
    High

    CVE-2018-13223

    Last Modified: 21 Nov 2024

    The sell function of a smart contract implementation for R Time Token v3 (RS) (Contract Name: RTokenMain), an Ethereum token, has an integer overflow in which "amount * sellPrice" can be zero, consequently reducing a seller's assets.

    Published: 5 Jul 2018
    7.5
    High

    CVE-2018-13224

    Last Modified: 21 Nov 2024

    The sell function of a smart contract implementation for Virtual Energy Units (VEU) (Contract Name: VEU_TokenERC20), an Ethereum token, has an integer overflow in which "amount * sellPrice" can be zero, consequently reducing a seller's assets.

    Published: 5 Jul 2018
    7.5
    High

    CVE-2018-13225

    Last Modified: 21 Nov 2024

    The sell function of a smart contract implementation for MyYLC, an Ethereum token, has an integer overflow in which "amount * sellPrice" can be zero, consequently reducing a seller's assets.

    Published: 5 Jul 2018
    7.5
    High

    CVE-2018-13226

    Last Modified: 21 Nov 2024

    The sell function of a smart contract implementation for YLCToken, an Ethereum token, has an integer overflow in which "amount * sellPrice" can be zero, consequently reducing a seller's assets.

    Published: 5 Jul 2018
    7.5
    High

    CVE-2018-13229

    Last Modified: 21 Nov 2024

    The sell function of a smart contract implementation for RiptideCoin (RIPT), an Ethereum token, has an integer overflow in which "amount * sellPrice" can be zero, consequently reducing a seller's assets.

    Published: 5 Jul 2018
    7.5
    High

    CVE-2018-13230

    Last Modified: 21 Nov 2024

    The sell function of a smart contract implementation for DestiNeed (DSN), an Ethereum token, has an integer overflow in which "amount * sellPrice" can be zero, consequently reducing a seller's assets.

    Published: 5 Jul 2018
    7.5
    High

    CVE-2018-13231

    Last Modified: 21 Nov 2024

    The sell function of a smart contract implementation for ENTER (ENTR) (Contract Name: EnterToken), an Ethereum token, has an integer overflow in which "amount * sellPrice" can be zero, consequently reducing a seller's assets.

    Published: 5 Jul 2018
    7.5
    High

    CVE-2018-13232

    Last Modified: 21 Nov 2024

    The sell function of a smart contract implementation for ENTER (ENTR) (Contract Name: EnterCoin), an Ethereum token, has an integer overflow in which "amount * sellPrice" can be zero, consequently reducing a seller's assets.

    Published: 5 Jul 2018
    7.5
    High

    CVE-2018-13156

    Last Modified: 21 Nov 2024

    The mintToken function of a smart contract implementation for bonusToken (BNS), an Ethereum token, has an integer overflow that allows the owner of the contract to set the balance of an arbitrary user to any value.

    Published: 5 Jul 2018
    7.5
    High

    CVE-2018-13158

    Last Modified: 21 Nov 2024

    The mintToken function of a smart contract implementation for AssetToken, an Ethereum token, has an integer overflow that allows the owner of the contract to set the balance of an arbitrary user to any value.

    Published: 5 Jul 2018
    7.5
    High

    CVE-2018-13160

    Last Modified: 21 Nov 2024

    The mintToken function of a smart contract implementation for etktokens (ETK), an Ethereum token, has an integer overflow that allows the owner of the contract to set the balance of an arbitrary user to any value.

    Published: 5 Jul 2018
    7.5
    High

    CVE-2018-13176

    Last Modified: 21 Nov 2024

    The mintToken function of a smart contract implementation for Trust Zen Token (ZEN), an Ethereum token, has an integer overflow that allows the owner of the contract to set the balance of an arbitrary user to any value.

    Published: 5 Jul 2018
    7.5
    High

    CVE-2018-13178

    Last Modified: 21 Nov 2024

    The mintToken function of a smart contract implementation for ECToints (ECT) (Contract Name: ECPoints), an Ethereum token, has an integer overflow that allows the owner of the contract to set the balance of an arbitrary user to any value.

    Published: 5 Jul 2018
    7.5
    High

    CVE-2018-13188

    Last Modified: 21 Nov 2024

    The mintToken function of a smart contract implementation for MyBO, an Ethereum token, has an integer overflow that allows the owner of the contract to set the balance of an arbitrary user to any value.

    Published: 5 Jul 2018
    7.5
    High

    CVE-2018-13206

    Last Modified: 21 Nov 2024

    The sell function of a smart contract implementation for ProvidenceCasino (PVE), an Ethereum token, has an integer overflow in which "amount * sellPrice" can be zero, consequently reducing a seller's assets.

    Published: 5 Jul 2018
    7.5
    High

    CVE-2018-13208

    Last Modified: 21 Nov 2024

    The sell function of a smart contract implementation for MoneyTree (TREE), an Ethereum token, has an integer overflow in which "amount * sellPrice" can be zero, consequently reducing a seller's assets.

    Published: 5 Jul 2018
    7.5
    High

    CVE-2018-13209

    Last Modified: 21 Nov 2024

    The sell function of a smart contract implementation for Nectar (NCTR), an Ethereum token, has an integer overflow in which "amount * sellPrice" can be zero, consequently reducing a seller's assets.

    Published: 5 Jul 2018
    7.5
    High

    CVE-2018-13227

    Last Modified: 21 Nov 2024

    The sell function of a smart contract implementation for MoneyChainNet (MCN), an Ethereum token, has an integer overflow in which "amount * sellPrice" can be zero, consequently reducing a seller's assets.

    Published: 5 Jul 2018
    7.5
    High

    CVE-2018-13233

    Last Modified: 21 Nov 2024

    The sell function of a smart contract implementation for GSI, an Ethereum token, has an integer overflow in which "amount * sellPrice" can be zero, consequently reducing a seller's assets.

    Published: 5 Jul 2018
    7.5
    High

    CVE-2018-13181

    Last Modified: 21 Nov 2024

    The mintToken function of a smart contract implementation for Troo, an Ethereum token, has an integer overflow that allows the owner of the contract to set the balance of an arbitrary user to any value.

    Published: 5 Jul 2018
    7.5
    High

    CVE-2018-13189

    Last Modified: 21 Nov 2024

    The mint function of a smart contract implementation for Unolabo (UNLB), an Ethereum token, has an integer overflow that allows the owner of the contract to set the balance of an arbitrary user to any value.

    Published: 5 Jul 2018
    7.5
    High

    CVE-2018-13195

    Last Modified: 21 Nov 2024

    The mintToken function of a smart contract implementation for Cranoo (CRN), an Ethereum token, has an integer overflow that allows the owner of the contract to set the balance of an arbitrary user to any value.

    Published: 5 Jul 2018
    7.5
    High

    CVE-2018-13196

    Last Modified: 21 Nov 2024

    The sell function of a smart contract implementation for T-Swap-Token (T-S-T), an Ethereum token, has an integer overflow in which "amount * sellPrice" can be zero, consequently reducing a seller's assets.

    Published: 5 Jul 2018
    7.5
    High

    CVE-2018-13198

    Last Modified: 21 Nov 2024

    The sell function of a smart contract implementation for STeX Exchange ICO (STE), an Ethereum token, has an integer overflow in which "amount * sellPrice" can be zero, consequently reducing a seller's assets.

    Published: 5 Jul 2018
    5.4
    Medium

    CVE-2015-9260

    Last Modified: 21 Nov 2024

    An issue was discovered in BEdita before 3.7.0. A cross-site scripting (XSS) attack occurs via a crafted pages/showObjects URI, as demonstrated by appending a payload to a pages/showObjects/2/0/0/leafs URI.

    Published: 5 Jul 2018
    7.5
    High

    CVE-2018-13168

    Last Modified: 21 Nov 2024

    The mintToken function of a smart contract implementation for Yu Gi Oh (YGO) (Contract Name: NetkillerBatchToken), an Ethereum token, has an integer overflow that allows the owner of the contract to set the balance of an arbitrary user to any value.

    Published: 5 Jul 2018
    7.5
    High

    CVE-2018-13169

    Last Modified: 21 Nov 2024

    The mintToken function of a smart contract implementation for Ethereum Cash Pro (ECP), an Ethereum token, has an integer overflow that allows the owner of the contract to set the balance of an arbitrary user to any value.

    Published: 5 Jul 2018
    7.5
    High

    CVE-2018-13175

    Last Modified: 21 Nov 2024

    The mintToken function of a smart contract implementation for AIChain, an Ethereum token, has an integer overflow that allows the owner of the contract to set the balance of an arbitrary user to any value.

    Published: 5 Jul 2018
    7.5
    High

    CVE-2018-13155

    Last Modified: 21 Nov 2024

    The mintToken function of a smart contract implementation for GEMCHAIN (GEM), an Ethereum token, has an integer overflow that allows the owner of the contract to set the balance of an arbitrary user to any value.

    Published: 5 Jul 2018
    7.5
    High

    CVE-2018-13161

    Last Modified: 21 Nov 2024

    The mintToken function of a smart contract implementation for MultiGames (MLT), an Ethereum token, has an integer overflow that allows the owner of the contract to set the balance of an arbitrary user to any value.

    Published: 5 Jul 2018
    7.5
    High

    CVE-2018-13213

    Last Modified: 21 Nov 2024

    The sell function of a smart contract implementation for TravelCoin (TRV), an Ethereum token, has an integer overflow in which "amount * sellPrice" can be zero, consequently reducing a seller's assets.

    Published: 5 Jul 2018
    7.5
    High

    CVE-2018-13220

    Last Modified: 21 Nov 2024

    The sell function of a smart contract implementation for MAVCash, an Ethereum token, has an integer overflow in which "amount * sellPrice" can be zero, consequently reducing a seller's assets.

    Published: 5 Jul 2018
    7.5
    High

    CVE-2018-13228

    Last Modified: 21 Nov 2024

    The sell function of a smart contract implementation for Crowdnext (CNX), an Ethereum token, has an integer overflow in which "amount * sellPrice" can be zero, consequently reducing a seller's assets.

    Published: 5 Jul 2018
    7.5
    High

    CVE-2018-13327

    Last Modified: 21 Nov 2024

    The transfer and transferFrom functions of a smart contract implementation for ChuCunLingAIGO (CCLAG), an Ethereum token, have an integer overflow. NOTE: this has been disputed by a third party.

    Published: 5 Jul 2018
    6.5
    Medium

    CVE-2018-13419

    Last Modified: 21 Nov 2024

    An issue has been found in libsndfile 1.0.28. There is a memory leak in psf_allocate in common.c, as demonstrated by sndfile-convert. NOTE: The maintainer and third parties were unable to reproduce and closed the issue

    Published: 5 Jul 2018
    7.8
    High

    CVE-2018-13405

    Last Modified: 21 Nov 2024

    The inode_init_owner function in fs/inode.c in the Linux kernel through 3.16 allows local users to create files with an unintended group ownership, in a scenario where a directory is SGID to a certain group and is writable by a user who is not a member of that group. Here, the non-member can trigger creation of a plain file whose group ownership is that group. The intended behavior was that the non-member can trigger creation of a directory (but not a plain file) whose group ownership is that group. The non-member can escalate privileges by making the plain file executable and SGID.

    Published: 5 Jul 2018
    7.5
    High

    CVE-2018-13326

    Last Modified: 21 Nov 2024

    The transfer and transferFrom functions of a smart contract implementation for Bittelux (BTX), an Ethereum token, have an integer overflow. NOTE: this has been disputed by a third party.

    Published: 5 Jul 2018
    5.3
    Medium

    CVE-2018-10892

    Last Modified: 21 Nov 2024

    The default OCI linux spec in oci/defaults{_linux}.go in Docker/Moby from 1.11 to current does not block /proc/acpi pathnames. The flaw allows an attacker to modify host's hardware like enabling/disabling bluetooth or turning up/down keyboard brightness.

    Published: 5 Jul 2018
    5.5
    Medium

    CVE-2018-14615

    Last Modified: 21 Nov 2024

    An issue was discovered in the Linux kernel through 4.17.10. There is a buffer overflow in truncate_inline_inode() in fs/f2fs/inline.c when umounting an f2fs image, because a length value may be negative.

    Published: 5 Jul 2018
    6.5
    Medium

    CVE-2018-16643

    Last Modified: 21 Nov 2024

    The functions ReadDCMImage in coders/dcm.c, ReadPWPImage in coders/pwp.c, ReadCALSImage in coders/cals.c, and ReadPICTImage in coders/pict.c in ImageMagick 7.0.8-4 do not check the return value of the fputc function, which allows remote attackers to cause a denial of service via a crafted image file.

    Published: 5 Jul 2018
    7.5
    High

    CVE-2018-13145

    Last Modified: 21 Nov 2024

    The mintToken function of a smart contract implementation for JavaSwapTest (JST), an Ethereum token, has an integer overflow.

    Published: 4 Jul 2018
    7.5
    High

    CVE-2018-13146

    Last Modified: 21 Nov 2024

    The mintToken, buy, and sell functions of a smart contract implementation for LEF, an Ethereum token, have an integer overflow.

    Published: 4 Jul 2018
    7.8
    High

    CVE-2018-13133

    Last Modified: 21 Nov 2024

    Golden Frog VyprVPN before 2018-06-21 has a vulnerability associated with the installation process on Windows.

    Published: 4 Jul 2018
    6.1
    Medium

    CVE-2018-13136

    Last Modified: 21 Nov 2024

    The Ultimate Member (aka ultimatemember) plugin before 2.0.18 for WordPress has XSS via the wp-admin settings screen.

    Published: 4 Jul 2018