7.5
CVSSv3

CVE-2018-19183

Published: 12/11/2018 Updated: 17/05/2024
CVSS v2 Base Score: 5 | Impact Score: 2.9 | Exploitability Score: 10
CVSS v3 Base Score: 7.5 | Impact Score: 3.6 | Exploitability Score: 3.9
VMScore: 445
Vector: AV:N/AC:L/Au:N/C:N/I:N/A:P

Vulnerability Summary

ethereumjs-vm 2.4.0 allows malicious users to cause a denial of service (vm.runCode failure and REVERT) via a "code: Buffer.from(my_code, 'hex')" attribute. NOTE: the vendor disputes this because REVERT is a normal bytecode that can be triggered from high-level source code, leading to a normal programmatic execution result.

Vulnerability Trend

Vulnerable Product Search on Vulmon Subscribe to Product

ethereumjs-vm project ethereumjs-vm 2.4.0