CVE-2018-10376

HIGH EXPLOITED IN THE WILD

SmartMesh - Integer Overflow in transferProxy

Title source: llm
STIX 2.1

Exploitation Summary

CVE-2018-10376 has been observed exploited in the wild (reported by VulnCheck KEV, InTheWild.io).

Description

An integer overflow in the transferProxy function of a smart contract implementation for SmartMesh (aka SMT), an Ethereum ERC20 token, allows attackers to accomplish an unauthorized increase of digital assets via crafted _fee and _value parameters, as exploited in the wild in April 2018, aka the "proxyOverflow" issue.

References (3)

Core 3
Core References
Exploit, Third Party Advisory x_refsource_misc
https://peckshield.com/2018/04/25/proxyOverflow/
Exploit, Third Party Advisory x_refsource_misc
https://www.reddit.com/r/ethereum/comments/8esyg9/okex_erc20_bug/
Not Applicable x_refsource_misc
https://dasp.co/#item-3

Scores

CVSS v3 7.5
EPSS 0.0182
EPSS Percentile 76.1%
Attack Vector NETWORK
CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:H/A:N

Details

VulnCheck KEV 2018-04-25
InTheWild.io 2018-06-13
CWE
CWE-190
Status published
Products (1)
smartmesh/smartmesh
Published Apr 25, 2018
Tracked Since Feb 18, 2026