CVE-2023-27892
- EPSS 0.05%
- Veröffentlicht 02.05.2023 21:15:09
- Zuletzt bearbeitet 30.01.2025 17:15:13
Insufficient length checks in the ShapeShift KeepKey hardware wallet firmware before 7.7.0 allow a global buffer overflow via crafted messages. Flaws in cf_confirmExecTx() in ethereum_contracts.c can be used to reveal arbitrary microcontroller memory...
CVE-2021-31616
- EPSS 2.2%
- Veröffentlicht 06.05.2021 13:15:12
- Zuletzt bearbeitet 21.11.2024 06:06:02
Insufficient length checks in the ShapeShift KeepKey hardware wallet firmware before 7.1.0 allow a stack buffer overflow via crafted messages. The overflow in ethereum_extractThorchainSwapData() in ethereum.c can circumvent stack protections and lead...
CVE-2019-18672
- EPSS 0.48%
- Veröffentlicht 06.12.2019 18:15:12
- Zuletzt bearbeitet 21.11.2024 04:33:30
Insufficient checks in the finite state machine of the ShapeShift KeepKey hardware wallet before firmware 6.2.2 allow a partial reset of cryptographic secrets to known values via crafted messages. Notably, this breaks the security of U2F for new serv...
CVE-2019-14355
- EPSS 0.06%
- Veröffentlicht 10.08.2019 16:15:11
- Zuletzt bearbeitet 21.11.2024 04:26:34
On ShapeShift KeepKey devices, a side channel for the row-based OLED display was found. The power consumption of each row-based display cycle depends on the number of illuminated pixels, allowing a partial recovery of display contents. For example, a...
CVE-2018-6875
- EPSS 0.31%
- Veröffentlicht 14.03.2018 13:29:00
- Zuletzt bearbeitet 21.11.2024 04:11:20
Format String vulnerability in KeepKey version 4.0.0 allows attackers to trigger information display (of information that should not be accessible), related to text containing characters that the device's font lacks.