dasp.co
https://dasp.co/ CVE-2018-10376
HIGH
smartmesh smartmesh Integer Overflow or Wraparound
Record summary
CVE-2018-10376 has a selected CVSS score of 7.5 (high).
Description
An integer overflow in the transferProxy function of a smart contract implementation for SmartMesh (aka SMT), an Ethereum ERC20 token, allows attackers to accomplish an unauthorized increase of digital assets via crafted _fee and _value parameters, as exploited in the wild in April 2018, aka the "proxyOverflow" issue.
Description source: CVE List
Exploitation context
Known exploitation
- VulnCheck KEV
- Listed · Apr 25, 2018 · VulnCheck
- Reported exploitation
- Observed · VulnCheck
Affected products and versions
1| Product | Source | Version range | Status |
|---|---|---|---|
smartmeshBrowse smartmesh / smartmesh | VulnCheck | Version data not supplied | |
References
4nvd.nist.gov
https://nvd.nist.gov/vuln/detail/CVE-2018-10376 peckshield.com
https://peckshield.com/2018/04/25/proxyOverflow reddit.com
https://www.reddit.com/r/ethereum/comments/8esyg9/okex_erc20_bug