Unrated severityNVD Advisory· Published Apr 28, 2018· Updated Aug 5, 2024
CVE-2018-10468
CVE-2018-10468
Description
The transferFrom function of a smart contract implementation for Useless Ethereum Token (UET), an Ethereum ERC20 token, allows attackers to steal assets (e.g., transfer all victims' balances into their account) because certain computations involving _value are incorrect, as exploited in the wild starting in December 2017, aka the "transferFlaw" issue.
Affected products
1Patches
Vulnerability mechanics
AI mechanics synthesis has not run for this CVE yet.
References
2- medium.com/%40jonghyk.song/uselessethereumtoken-uet-erc20-token-allows-attackers-to-steal-all-victims-balances-543d42ac808emitrex_refsource_MISC
- peckshield.com/2018/04/28/transferFlaw/mitrex_refsource_MISC
News mentions
0No linked articles in our index yet.