We found results for “”
CVE-2023-42460
Good to know:
Date: September 26, 2023
Vyper is a Pythonic Smart Contract Language for the EVM. The "_abi_decode()" function does not validate input when it is nested in an expression. Uses of "_abi_decode()" can be constructed which allow for bounds checking to be bypassed resulting in incorrect results. This issue has not yet been fixed, but a fix is expected in release "0.3.10". Users are advised to reference pull request #3626.
Language: Python
Severity Score
Related Resources (6)
Severity Score
Weakness Type (CWE)
Incorrect Calculation
CWE-682Top Fix
CVSS v3.1
| Base Score: |
|
|---|---|
| Attack Vector (AV): | NETWORK |
| Attack Complexity (AC): | HIGH |
| Privileges Required (PR): | LOW |
| User Interaction (UI): | NONE |
| Scope (S): | UNCHANGED |
| Confidentiality (C): | NONE |
| Integrity (I): | HIGH |
| Availability (A): | NONE |
Vulnerabilities
Projects
Contact Us


