Vulmon
Recent Vulnerabilities
Research Posts
Trends
Blog
About
Contact
Vulmon Alerts
By Relevance
By Risk Score
By Publish Date
ethereum vulnerabilities and exploits
(subscribe to this query)
7.5
CVSSv3
CVE-2018-16733
In Go Ethereum (aka geth) prior to 1.8.14, TraceChain in eth/api_tracer.go does not verify that the end block is after the start block.
Ethereum Go Ethereum
8.1
CVSSv3
CVE-2017-12113
An exploitable improper authorization vulnerability exists in admin_nodeInfo API of cpp-ethereum's JSON-RPC (commit 4e1015743b95821849d001618a7ce82c7c073768). A JSON request can cause an access to the restricted functionality resulting in authorization bypass. An attacker ca...
Ethereum Cpp-ethereum -
7.5
CVSSv3
CVE-2021-39137
go-ethereum is the official Go implementation of the Ethereum protocol. In affected versions a consensus-vulnerability in go-ethereum (Geth) could cause a chain split, where vulnerable versions refuse to accept the canonical chain. Further details about the vulnerability will be ...
Ethereum Go Ethereum
2 Github repositories
5.5
CVSSv3
CVE-2021-43668
Go-Ethereum 1.10.9 nodes crash (denial of service) after receiving a serial of messages and cannot be recovered. They will crash with "runtime error: invalid memory address or nil pointer dereference" and arise a SEGV signal.
Ethereum Go Ethereum 1.10.9
7.5
CVSSv3
CVE-2018-20421
Go Ethereum (aka geth) 1.8.19 allows malicious users to cause a denial of service (memory consumption) by rewriting the length of a dynamic array in memory, and then writing data to a single memory location with a large index number, as demonstrated by use of "assembly { mst...
Ethereum Go Ethereum 1.8.19
7.5
CVSSv3
CVE-2018-19184
cmd/evm/runner.go in Go Ethereum (aka geth) 1.8.17 allows malicious users to cause a denial of service (SEGV) via crafted bytecode.
Ethereum Go Ethereum 1.8.17
7.5
CVSSv3
CVE-2021-42219
Go-Ethereum v1.10.9 exists to contain an issue which allows malicious users to cause a denial of service (DoS) via sending an excessive amount of messages to a node. This is caused by missing memory in the component /ethash/algorithm.go.
Ethereum Go Ethereum 1.10.9
8.2
CVSSv3
CVE-2017-14457
An exploitable information leak/denial of service vulnerability exists in the libevm (Ethereum Virtual Machine) `create2` opcode handler of CPP-Ethereum. A specially crafted smart contract code can cause an out-of-bounds read leading to memory disclosure or denial of service. An ...
Ethereum Ethereum Virtual Machine -
7.5
CVSSv3
CVE-2021-42765
The Proof-of-Stake (PoS) Ethereum consensus protocol through 2021-10-19 allows an adversary to leverage network delay to cause a denial of service (indefinite stalling of consensus decisions).
Proof-of-stake Ethereum Project Proof-of-stake Ethereum
7.5
CVSSv3
CVE-2018-13169
The mintToken function of a smart contract implementation for Ethereum Cash Pro (ECP), an Ethereum token, has an integer overflow that allows the owner of the contract to set the balance of an arbitrary user to any value.
Ethereum Cash Pro Coin Project Ethereum Cash Pro Coin -
CVSSv3
CVSSv2
CVSSv3
VMScore
Recommendations:
inject
CVE-2024-34001
CVE-2024-37018
LFI
CVE-2024-1275
CVE-2024-1086
CSRF
CVE-2024-31030
CVE-2024-24919
Vulnerability Notification Service
You don’t have to wait for vulnerability scanning results
Get Started
« PREV
1
2
3
4
5
6
7
8
NEXT »