
We found results for “”
CVE-2023-42460
Good to know:


Date: September 26, 2023
Vyper is a Pythonic Smart Contract Language for the EVM. The "_abi_decode()" function does not validate input when it is nested in an expression. Uses of "_abi_decode()" can be constructed which allow for bounds checking to be bypassed resulting in incorrect results. This issue has not yet been fixed, but a fix is expected in release "0.3.10". Users are advised to reference pull request #3626.
Language: Python
Severity Score
Related Resources (6)
Severity Score
Weakness Type (CWE)
Incorrect Calculation
CWE-682Top Fix

CVSS v3.1
Base Score: |
|
---|---|
Attack Vector (AV): | NETWORK |
Attack Complexity (AC): | HIGH |
Privileges Required (PR): | LOW |
User Interaction (UI): | NONE |
Scope (S): | UNCHANGED |
Confidentiality (C): | NONE |
Integrity (I): | HIGH |
Availability (A): | NONE |