CVE-2024-58131
- EPSS 0.22%
- Veröffentlicht 06.04.2025 03:15:13
- Zuletzt bearbeitet 08.04.2025 16:45:17
FISCO BCOS 3.11.0 has an issue with synchronization of the transaction pool that can, for example, be observed when a malicious node (that has modified the codebase to allow a large min_seal_time value) joins a blockchain network.
CVE-2022-28936
- EPSS 0.28%
- Veröffentlicht 15.05.2022 16:15:07
- Zuletzt bearbeitet 21.11.2024 06:58:13
FISCO-BCOS release-3.0.0-rc2 was discovered to contain an issue where a malicious node can trigger an integer overflow and cause a Denial of Service (DoS) via an unusually large viewchange message packet.
CVE-2022-28937
- EPSS 0.33%
- Veröffentlicht 15.05.2022 16:15:07
- Zuletzt bearbeitet 21.11.2024 06:58:13
FISCO-BCOS release-3.0.0-rc2 was discovered to contain an issue where a malicious node, via an invalid proposal with an invalid header, will cause normal nodes to stop producing new blocks and processing new clients' requests.
CVE-2022-26534
- EPSS 0.28%
- Veröffentlicht 17.03.2022 00:15:07
- Zuletzt bearbeitet 21.11.2024 06:54:07
FISCO-BCOS release-3.0.0-rc2 was discovered to contain an issue where a malicious node, via a malicious viewchange packet, will cause normal nodes to change view excessively and stop generating blocks.
CVE-2021-46359
- EPSS 0.33%
- Veröffentlicht 07.02.2022 13:15:07
- Zuletzt bearbeitet 21.11.2024 06:33:57
FISCO-BCOS release-3.0.0-rc2 contains a denial of service vulnerability. Some transactions may not be committed successfully, and malicious users may use this to achieve double-spending attacks.
CVE-2021-35041
- EPSS 0.33%
- Veröffentlicht 24.06.2021 00:15:08
- Zuletzt bearbeitet 21.11.2024 06:11:43
The blockchain node in FISCO-BCOS V2.7.2 may have a bug when dealing with unformatted packet and lead to a crash. A malicious node can send a packet continuously. The packet is in an incorrect format and cannot be decoded by the node correctly. As a ...