Skip to main content

Vendor/product archive

openzeppelin / contracts CVEs

Beta · best-effort

20 CVEs tagged to openzeppelin / contracts3 Critical, 4 High, 13 Medium, 0 Low, 0 Unrated.

CVE-2024-45304

Published Aug 31, 2024

Cairo-Contracts are OpenZeppelin Contracts written in Cairo for Starknet, a decentralized ZK Rollup. This vulnerability can lead to unauthorized ownership transfer, contrary to th…

CVSS 5.3 · Medium
Vendor/product tagsBeta · best-effort

CVE-2023-23940

Published Feb 3, 2023

OpenZeppelin Contracts for Cairo is a library for secure smart contract development written in Cairo for StarkNet, a decentralized ZK Rollup. `is_valid_eth_signature` is missing a…

CVSS 6.4 · Medium
Vendor/product tagsBeta · best-effort

CVE-2022-31172

Published Jul 22, 2022

OpenZeppelin Contracts is a library for smart contract development. Versions 4.1.0 until 4.7.1 are vulnerable to the SignatureChecker reverting. `SignatureChecker.isValidSignature…

CVSS 7.5 · High
Vendor/product tagsBeta · best-effort

CVE-2022-31170

Published Jul 22, 2022

OpenZeppelin Contracts is a library for smart contract development. Versions 4.0.0 until 4.7.1 are vulnerable to ERC165Checker reverting instead of returning `false`. `ERC165Check…

CVSS 7.5 · High
Vendor/product tagsBeta · best-effort

CVE-2022-31153

Published Jul 15, 2022

OpenZeppelin Contracts for Cairo is a library for contract development written in Cairo for StarkNet, a decentralized ZK Rollup. Version 0.2.0 is vulnerable to an error that rende…

CVSS 6.5 · Medium
Vendor/product tagsBeta · best-effort

CVE-2021-41264

Published Nov 12, 2021

OpenZeppelin Contracts is a library for smart contract development. In affected versions upgradeable contracts using `UUPSUpgradeable` may be vulnerable to an attack affecting uni…

CVSS 9.8 · Critical
Vendor/product tagsBeta · best-effort

CVE-2021-39168

Published Aug 27, 2021

OpenZepplin is a library for smart contract development. In affected versions a vulnerability in TimelockController allowed an actor with the executor role to escalate privileges.…

CVSS 10.0 · Critical
Vendor/product tagsBeta · best-effort

CVE-2021-39167

Published Aug 27, 2021

OpenZepplin is a library for smart contract development. In affected versions a vulnerability in TimelockController allowed an actor with the executor role to escalate privileges.…

CVSS 10.0 · Critical
Vendor/product tagsBeta · best-effort
Showing 1-20 of 20 CVEsPage 1 of 1