Skip to main content

Vendor archive

parity CVEs

Beta · best-effort

14 CVEs tagged to vendor parity1 Critical, 5 High, 8 Medium, 0 Low, 0 Unrated.

CVE-2023-45130

Published Oct 13, 2023

Frontier is Substrate's Ethereum compatibility layer. Prior to commit aea528198b3b226e0d20cce878551fd4c0e3d5d0, at the end of a contract execution, when opcode SUICIDE marks a con…

CVSS 7.5 · High
Vendor/product tagsBeta · best-effort

CVE-2023-34449

Published Jun 14, 2023

ink! is an embedded domain specific language to write smart contracts in Rust for blockchains built on the Substrate framework. Starting in version 4.0.0 and prior to version 4.2.…

CVSS 5.3 · Medium
Vendor/product tagsBeta · best-effort

CVE-2023-28431

Published Mar 22, 2023

Frontier is an Ethereum compatibility layer for Substrate. Frontier's `modexp` precompile uses `num-bigint` crate under the hood. In the implementation prior to pull request 1017,…

CVSS 7.5 · High
Vendor/product tagsBeta · best-effort

CVE-2022-39242

Published Sep 24, 2022

Frontier is an Ethereum compatibility layer for Substrate. Prior to commit d3beddc6911a559a3ecc9b3f08e153dbe37a8658, the worst case weight was always accounted as the block weight…

CVSS 5.3 · Medium
Vendor/product tagsBeta · best-effort

CVE-2022-36008

Published Aug 19, 2022

Frontier is Substrate's Ethereum compatibility layer. A security issue was discovered affecting parsing of the RPC result of the exit reason in case of EVM reversion. In release b…

CVSS 7.1 · High
Vendor/product tagsBeta · best-effort

CVE-2022-31111

Published Jul 6, 2022

Frontier is Substrate's Ethereum compatibility layer. In affected versions the truncation done when converting between EVM balance type and Substrate balance type was incorrectly…

CVSS 5.3 · Medium
Vendor/product tagsBeta · best-effort

CVE-2022-21685

Published Jan 14, 2022

Frontier is Substrate's Ethereum compatibility layer. Prior to commit number `8a93fdc6c9f4eb1d2f2a11b7ff1d12d70bf5a664`, a bug in Frontier's MODEXP precompile implementation can c…

CVSS 6.5 · Medium
Vendor/product tagsBeta · best-effort

CVE-2021-41138

Published Oct 13, 2021

Frontier is Substrate's Ethereum compatibility layer. In the newly introduced signed Frontier-specific extrinsic for `pallet-ethereum`, a large part of transaction validation logi…

CVSS 5.3 · Medium
Vendor/product tagsBeta · best-effort

CVE-2021-39193

Published Sep 3, 2021

Frontier is Substrate's Ethereum compatibility layer. Prior to commit number 0b962f218f0cdd796dadfe26c3f09e68f7861b26, a bug in `pallet-ethereum` can cause invalid transactions to…

CVSS 5.3 · Medium
Vendor/product tagsBeta · best-effort

CVE-2021-38195

Published Aug 8, 2021

An issue was discovered in the libsecp256k1 crate before 0.5.0 for Rust. It can verify an invalid signature because it allows the R or S parameter to be larger than the curve orde…

CVSS 9.8 · Critical
Vendor/product tagsBeta · best-effort

CVE-2019-25003

Published Dec 31, 2020

An issue was discovered in the libsecp256k1 crate before 0.3.1 for Rust. Scalar::check_overflow allows a timing side-channel attack; consequently, attackers can obtain sensitive i…

CVSS 7.5 · High
Vendor/product tagsBeta · best-effort

CVE-2019-20399

Published Jan 23, 2020

A timing vulnerability in the Scalar::check_overflow function in Parity libsecp256k1-rs before 0.3.1 potentially allows an attacker to leak information via a side-channel attack.

CVSS 5.9 · Medium
Vendor/product tagsBeta · best-effort

CVE-2017-14460

Published Jan 19, 2018

An exploitable overly permissive cross-domain (CORS) whitelist vulnerability exists in JSON-RPC of Parity Ethereum client version 1.7.8. An automatically sent JSON object to JSON-…

CVSS 7.5 · High
Vendor/product tagsBeta · best-effort

CVE-2017-18016

Published Jan 11, 2018

Parity Browser 1.6.10 and earlier allows remote attackers to bypass the Same Origin Policy and obtain sensitive information by requesting other websites via the Parity web proxy e…

CVSS 5.3 · Medium
Vendor/product tagsBeta · best-effort
Showing 1-14 of 14 CVEsPage 1 of 1