Vulnerability index

Browse CVEs

14 matching
Filters 1 Clear all
Severity

Filters apply as you choose them.

Frontier HIGH 7.5
CVE-2023-45130

Frontier is Substrate's Ethereum compatibility layer. Prior to commit aea528198b3b226e0d20cce878551fd4c0e3d5d0, at the end of a contract execution, w…

Fix: after 0.1.0
Fix from $1,950 2023-10-13
Ink\! MEDIUM 5.3
CVE-2023-34449

ink! is an embedded domain specific language to write smart contracts in Rust for blockchains built on the Substrate framework. Starting in version 4…

Fix: 4.2.1+
Fix from $1,600 2023-06-14
Frontier HIGH 7.5
CVE-2023-28431

Frontier is an Ethereum compatibility layer for Substrate. Frontier's `modexp` precompile uses `num-bigint` crate under the hood. In the implementati…

Fix: 2023-03-15+
Fix from $1,950 2023-03-22
Frontier MEDIUM 5.3
CVE-2022-39242

Frontier is an Ethereum compatibility layer for Substrate. Prior to commit d3beddc6911a559a3ecc9b3f08e153dbe37a8658, the worst case weight was always…

Fix: 2022-09-12+
Fix from $1,600 2022-09-24
Frontier MEDIUM 6.5
CVE-2022-36008

Frontier is Substrate's Ethereum compatibility layer. A security issue was discovered affecting parsing of the RPC result of the exit reason in case …

Patch available
Fix from $1,600 2022-08-19
Frontier MEDIUM 5.3
CVE-2022-31111

Frontier is Substrate's Ethereum compatibility layer. In affected versions the truncation done when converting between EVM balance type and Substrate…

Patch available
Fix from $1,600 2022-07-06
Frontier MEDIUM 6.5
CVE-2022-21685

Frontier is Substrate's Ethereum compatibility layer. Prior to commit number `8a93fdc6c9f4eb1d2f2a11b7ff1d12d70bf5a664`, a bug in Frontier's MODEXP p…

Fix: after 2022-01-13
Fix from $1,600 2022-01-14
Frontier MEDIUM 5.3
CVE-2021-41138

Frontier is Substrate's Ethereum compatibility layer. In the newly introduced signed Frontier-specific extrinsic for `pallet-ethereum`, a large part …

Fix: 2021-10-13+
Fix from $1,600 2021-10-13
Frontier MEDIUM 5.3
CVE-2021-39193

Frontier is Substrate's Ethereum compatibility layer. Prior to commit number 0b962f218f0cdd796dadfe26c3f09e68f7861b26, a bug in `pallet-ethereum` can…

Fix: 2021-09-03+
Fix from $1,600 2021-09-03
Libsecp256k1 CRITICAL 9.8
CVE-2021-38195

An issue was discovered in the libsecp256k1 crate before 0.5.0 for Rust. It can verify an invalid signature because it allows the R or S parameter to…

Fix: 0.5.0+
Fix from $2,300 2021-08-08
Libsecp256k1 HIGH 7.5
CVE-2019-25003

An issue was discovered in the libsecp256k1 crate before 0.3.1 for Rust. Scalar::check_overflow allows a timing side-channel attack; consequently, at…

Fix: 0.3.1+
Fix from $1,950 2020-12-31
Libsecp256k1 MEDIUM 5.9
CVE-2019-20399

A timing vulnerability in the Scalar::check_overflow function in Parity libsecp256k1-rs before 0.3.1 potentially allows an attacker to leak informati…

Fix: 0.3.1+
Fix from $1,600 2020-01-23
Ethereum Client HIGH 7.5
CVE-2017-14460

An exploitable overly permissive cross-domain (CORS) whitelist vulnerability exists in JSON-RPC of Parity Ethereum client version 1.7.8. An automatic…

No fix yet
Fix from $1,950 2018-01-19
Browser MEDIUM 5.3
CVE-2017-18016EPSS 5%

Parity Browser 1.6.10 and earlier allows remote attackers to bypass the Same Origin Policy and obtain sensitive information by requesting other websi…

Patch available
Fix from $1,600 2018-01-11