Vyper是EVM 的 Pythonic 智能合约语言。 Vyper 0.3.10 及之前版本存在安全漏洞,该漏洞源于当缓冲区参数为 msg.data、self.code、<address>.code、start、length时,可能会导致安全问题。
Although we use advanced large model technology, its output may still contain inaccurate or outdated information.Shenlong tries to ensure data accuracy, but please verify and judge based on the actual situation.
| # | POC Description | Source Link | Shenlong Link |
|---|
No public POC found.
Login to generate AI POC| CVE-2024-32649 | 5.3 MEDIUM | vyper performs double eval of the argument of sqrt |
| CVE-2024-32481 | 5.3 MEDIUM | vyper's range(start, start + N) reverts for negative numbers |
| CVE-2024-32648 | 5.3 MEDIUM | vyper default functions don't respect nonreentrancy keys |
| CVE-2024-32647 | 5.3 MEDIUM | vyper performs double eval of raw_args in create_from_blueprint |
| CVE-2024-32645 | 5.3 MEDIUM | vyper performs incorrect topic logging in raw_log |
No comments yet