CVE-2018-14439

HIGH

espritblock eos4j - Info Disclosure

Title source: llm

Description

espritblock eos4j, an unofficial SDK for EOS, through 2018-07-12 mishandles floating-point numbers with more than four digits after the decimal point, which might allow attackers to trigger currency transfers of unintended amounts.

Scores

CVSS v3 7.5
EPSS 0.0024
EPSS Percentile 46.5%
Attack Vector NETWORK
CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:H/A:N

Classification

CWE
CWE-682
Status published

Affected Products (1)

eblock/eos4j < 2018-07-12

Timeline

Published Jul 20, 2018
Tracked Since Feb 18, 2026