CVE-2018-14439

HIGH

espritblock eos4j - Info Disclosure

Title source: llm
STIX 2.1

Description

espritblock eos4j, an unofficial SDK for EOS, through 2018-07-12 mishandles floating-point numbers with more than four digits after the decimal point, which might allow attackers to trigger currency transfers of unintended amounts.

Scores

CVSS v3 7.5
EPSS 0.0024
EPSS Percentile 46.7%
Attack Vector NETWORK
CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:H/A:N

Details

CWE
CWE-682
Status published
Products (1)
eblock/eos4j < 2018-07-12
Published Jul 20, 2018
Tracked Since Feb 18, 2026