Lucene search

K

Parity Security Vulnerabilities

cve
cve

CVE-2023-28431

Frontier is an Ethereum compatibility layer for Substrate. Frontier's modexp precompile uses num-bigint crate under the hood. In the implementation prior to pull request 1017, the cases for modulus being even and modulus being odd are treated separately. Odd modulus uses the fast Montgomery...

7.5CVSS

7.3AI Score

0.001EPSS

2023-03-22 09:15 PM
29
cve
cve

CVE-2023-45130

Frontier is Substrate's Ethereum compatibility layer. Prior to commit aea528198b3b226e0d20cce878551fd4c0e3d5d0, at the end of a contract execution, when opcode SUICIDE marks a contract to be deleted, the software uses storage::remove_prefix (now renamed to storage::clear_prefix) to remove all...

7.5CVSS

7.4AI Score

0.001EPSS

2023-10-13 01:15 PM
19
cve
cve

CVE-2021-39193

Frontier is Substrate's Ethereum compatibility layer. Prior to commit number 0b962f218f0cdd796dadfe26c3f09e68f7861b26, a bug in pallet-ethereum can cause invalid transactions to be included in the Ethereum block state in pallet-ethereum due to not validating the input data size. Any invalid...

5.3CVSS

5.2AI Score

0.001EPSS

2021-09-03 06:15 PM
33
cve
cve

CVE-2023-34449

ink! is an embedded domain specific language to write smart contracts in Rust for blockchains built on the Substrate framework. Starting in version 4.0.0 and prior to version 4.2.1, the return value when using delegate call mechanics, either through CallBuilder::delegate or...

5.3CVSS

5.2AI Score

0.001EPSS

2023-06-14 09:15 PM
24
cve
cve

CVE-2022-39242

Frontier is an Ethereum compatibility layer for Substrate. Prior to commit d3beddc6911a559a3ecc9b3f08e153dbe37a8658, the worst case weight was always accounted as the block weight for all cases. In case of large EVM gas refunds, this can lead to block spamming attacks -- the adversary can...

5.3CVSS

5.1AI Score

0.001EPSS

2022-09-24 02:15 AM
36
3
cve
cve

CVE-2022-36008

Frontier is Substrate's Ethereum compatibility layer. A security issue was discovered affecting parsing of the RPC result of the exit reason in case of EVM reversion. In release build, this would cause the exit reason being incorrectly parsed and returned by RPC. In debug build, this would cause...

7.1CVSS

6.5AI Score

0.001EPSS

2022-08-19 09:15 PM
54
5
cve
cve

CVE-2022-31111

Frontier is Substrate's Ethereum compatibility layer. In affected versions the truncation done when converting between EVM balance type and Substrate balance type was incorrectly implemented. This leads to possible discrepancy between appeared EVM transfer value and actual Substrate value...

5.3CVSS

5.1AI Score

0.001EPSS

2022-07-06 06:15 PM
26
6
cve
cve

CVE-2022-21685

Frontier is Substrate's Ethereum compatibility layer. Prior to commit number 8a93fdc6c9f4eb1d2f2a11b7ff1d12d70bf5a664, a bug in Frontier's MODEXP precompile implementation can cause an integer underflow in certain conditions. This will cause a node crash for debug builds. For release builds (and...

6.5CVSS

6.3AI Score

0.001EPSS

2022-01-14 05:15 PM
44
cve
cve

CVE-2021-41138

Frontier is Substrate's Ethereum compatibility layer. In the newly introduced signed Frontier-specific extrinsic for pallet-ethereum, a large part of transaction validation logic was only called in transaction pool validation, but not in block execution. Malicious validators can take advantage of.....

5.3CVSS

5.2AI Score

0.001EPSS

2021-10-13 04:15 PM
23
cve
cve

CVE-2021-38195

An issue was discovered in the libsecp256k1 crate before 0.5.0 for Rust. It can verify an invalid signature because it allows the R or S parameter to be larger than the curve order, aka an...

9.8CVSS

9.3AI Score

0.003EPSS

2021-08-08 06:15 AM
83
5
cve
cve

CVE-2019-25003

An issue was discovered in the libsecp256k1 crate before 0.3.1 for Rust. Scalar::check_overflow allows a timing side-channel attack; consequently, attackers can obtain sensitive...

7.5CVSS

7.3AI Score

0.002EPSS

2020-12-31 10:15 AM
33
cve
cve

CVE-2019-20399

A timing vulnerability in the Scalar::check_overflow function in Parity libsecp256k1-rs before 0.3.1 potentially allows an attacker to leak information via a side-channel...

5.9CVSS

5.2AI Score

0.002EPSS

2020-01-23 12:15 AM
65
cve
cve

CVE-2017-14460

An exploitable overly permissive cross-domain (CORS) whitelist vulnerability exists in JSON-RPC of Parity Ethereum client version 1.7.8. An automatically sent JSON object to JSON-RPC endpoint can trigger this vulnerability. A victim needs to visit a malicious website to trigger this...

7.5CVSS

7.4AI Score

0.003EPSS

2018-01-19 11:29 PM
46
cve
cve

CVE-2017-18016

Parity Browser 1.6.10 and earlier allows remote attackers to bypass the Same Origin Policy and obtain sensitive information by requesting other websites via the Parity web proxy engine (reusing the current website's token, which is not bound to an...

5.3CVSS

5.2AI Score

0.025EPSS

2018-01-11 04:29 PM
35