Openzeppelin

Contracts

21 Schwachstellen gefunden.

Hinweis: Diese Liste kann unvollständig sein. Daten werden ohne Gewähr im Ursprungsformat bereitgestellt.
  • EPSS 0.56%
  • Veröffentlicht 04.11.2022 22:15:12
  • Zuletzt bearbeitet 21.11.2024 07:18:11

OpenZeppelin Contracts is a library for secure smart contract development. Before version 4.4.1 but after 3.2.0, initializer functions that are invoked separate from contract creation (the most prominent example being minimal proxies) may be reentere...

  • EPSS 0.16%
  • Veröffentlicht 15.08.2022 11:21:39
  • Zuletzt bearbeitet 21.11.2024 07:12:03

OpenZeppelin Contracts is a library for secure smart contract development. The functions `ECDSA.recover` and `ECDSA.tryRecover` are vulnerable to a kind of signature malleability due to accepting EIP-2098 compact signatures in addition to the traditi...

  • EPSS 0.24%
  • Veröffentlicht 01.08.2022 21:15:13
  • Zuletzt bearbeitet 21.11.2024 07:11:57

OpenZeppelin Contracts is a library for secure smart contract development. Contracts using the cross chain utilities for Arbitrum L2, `CrossChainEnabledArbitrumL2` or `LibArbitrumL2`, will classify direct interactions of externally owned accounts (EO...

  • EPSS 0.31%
  • Veröffentlicht 01.08.2022 21:15:13
  • Zuletzt bearbeitet 21.11.2024 07:11:57

OpenZeppelin Contracts is a library for secure smart contract development. The target contract of an EIP-165 `supportsInterface` query can cause unbounded gas consumption by returning a lot of data, while it is generally assumed that this operation h...

  • EPSS 0.27%
  • Veröffentlicht 01.08.2022 21:15:13
  • Zuletzt bearbeitet 21.11.2024 07:04:06

OpenZeppelin Contracts is a library for secure smart contract development. This issue concerns instances of Governor that use the module `GovernorVotesQuorumFraction`, a mechanism that determines quorum requirements as a percentage of the voting toke...

  • EPSS 0.11%
  • Veröffentlicht 22.07.2022 04:15:14
  • Zuletzt bearbeitet 21.11.2024 07:04:03

OpenZeppelin Contracts is a library for smart contract development. Versions 4.1.0 until 4.7.1 are vulnerable to the SignatureChecker reverting. `SignatureChecker.isValidSignatureNow` is not expected to revert. However, an incorrect assumption about ...

  • EPSS 0.31%
  • Veröffentlicht 22.07.2022 04:15:14
  • Zuletzt bearbeitet 21.11.2024 07:04:02

OpenZeppelin Contracts is a library for smart contract development. Versions 4.0.0 until 4.7.1 are vulnerable to ERC165Checker reverting instead of returning `false`. `ERC165Checker.supportsInterface` is designed to always successfully return a boole...

Exploit
  • EPSS 1.11%
  • Veröffentlicht 15.07.2022 18:15:08
  • Zuletzt bearbeitet 21.11.2024 07:04:00

OpenZeppelin Contracts for Cairo is a library for contract development written in Cairo for StarkNet, a decentralized ZK Rollup. Version 0.2.0 is vulnerable to an error that renders account contracts unusable on live networks. This issue affects all ...

  • EPSS 0.64%
  • Veröffentlicht 12.11.2021 18:15:07
  • Zuletzt bearbeitet 21.11.2024 06:25:55

OpenZeppelin Contracts is a library for smart contract development. In affected versions upgradeable contracts using `UUPSUpgradeable` may be vulnerable to an attack affecting uninitialized implementation contracts. A fix is included in version 4.3.2...

  • EPSS 0.44%
  • Veröffentlicht 27.08.2021 00:15:07
  • Zuletzt bearbeitet 21.11.2024 06:18:46

OpenZepplin is a library for smart contract development. In affected versions a vulnerability in TimelockController allowed an actor with the executor role to escalate privileges. Further details about the vulnerability will be disclosed at a later d...