Record summary

CVE-2018-10376 has a selected CVSS score of 7.5 (high).

Description

An integer overflow in the transferProxy function of a smart contract implementation for SmartMesh (aka SMT), an Ethereum ERC20 token, allows attackers to accomplish an unauthorized increase of digital assets via crafted _fee and _value parameters, as exploited in the wild in April 2018, aka the "proxyOverflow" issue.

Description source: CVE List

Exploitation context

Known exploitation

VulnCheck KEV
Listed · Apr 25, 2018 · VulnCheck
Reported exploitation
Observed · VulnCheck

Affected products and versions

1
ProductSourceVersion rangeStatus
VulnCheckVersion data not supplied

References

4