7.5
CVSSv2

CVE-2017-14451

Published: 02/12/2020 Updated: 09/12/2020
CVSS v2 Base Score: 7.5 | Impact Score: 6.4 | Exploitability Score: 10
CVSS v3 Base Score: 10 | Impact Score: 6 | Exploitability Score: 3.9
VMScore: 668
Vector: AV:N/AC:L/Au:N/C:P/I:P/A:P

Vulnerability Summary

An exploitable out-of-bounds read vulnerability exists in libevm (Ethereum Virtual Machine) of CPP-Ethereum. A specially crafted smart contract code can cause an out-of-bounds read which can subsequently trigger an out-of-bounds write resulting in remote code execution. An attacker can create/send malicious smart contract to trigger this vulnerability.

Vulnerability Trend

Vulnerable Product Search on Vulmon Subscribe to Product

ethereum ethereum -

Github Repositories

For testing only, includes vulnerable dependencies on pupose

vulnerable_crate This crate is intended for testing purposes only, and uses vulnerable dependencies on purpose Its goal is to allow checking and comparing outputs of various auditing tools able to work on Rust sources or binaries Vulnerabilities This crate includes different cases in its dependencies: An informational = "notice" advisory An informational = "un