OpenZeppelin / Contracts
20 CVEs
| CVE ID | Description | Severity | CVSS | Published |
|---|---|---|---|---|
| CVE-2024-45304 | OwnableTwoStep allows a pending owner to accept ownership after the original owner has renounced ownership in cairo-contracts | MEDIUM | 6.5 | Aug 30, 2024 |
| CVE-2024-27094 | OpenZeppelin Contracts base64 encoding may read from potentially dirty memory | HIGH | 7.4 | Feb 29, 2024 |
| CVE-2023-49798 | Duplicated execution of subcalls in OpenZeppelin Contracts | HIGH | 7.5 | Dec 8, 2023 |
| CVE-2023-34459 | OpenZeppelin Contracts's MerkleProof multiproofs may allow proving arbitrary leaves for specific trees | MEDIUM | 5.9 | Jun 16, 2023 |
| CVE-2023-34234 | Governor proposal creation may be blocked by frontrunning in OpenZeppelin | MEDIUM | 5.3 | Jun 7, 2023 |
| CVE-2023-30541 | TransparentUpgradeableProxy clashing selector calls may not be delegated in @openzeppelin/contracts | MEDIUM | 5.3 | Apr 17, 2023 |
| CVE-2023-30542 | GovernorCompatibilityBravo may trim proposal calldata | HIGH | 8.8 | Apr 16, 2023 |
| CVE-2023-26488 | OpenZeppelin Contracts contains Incorrect Calculation | MEDIUM | 6.5 | Mar 3, 2023 |
| CVE-2023-23940 | OpenZeppelin Contracts for Cairo is vulnerable to signature validation bypass | MEDIUM | 6.0 | Feb 3, 2023 |
| CVE-2022-39384 | OpenZeppelin Contracts initializer reentrancy may lead to double initialization | MEDIUM | 5.6 | Nov 4, 2022 |
| CVE-2022-35961 | ECDSA signature malleability in OpenZeppelin Contracts | HIGH | 7.9 | Aug 14, 2022 |
| CVE-2022-35915 | Unbounded gas consumption in @openzeppelin/contracts | MEDIUM | 5.3 | Aug 1, 2022 |
| CVE-2022-35916 | Cross chain utilities for Arbitrum L2 see EOA calls as cross chain calls | MEDIUM | 5.3 | Aug 1, 2022 |
| CVE-2022-31198 | GovernorVotesQuorumFraction updates to quorum may affect past defeated proposals in @openzeppelin/contracts | HIGH | 7.5 | Aug 1, 2022 |
| CVE-2022-31170 | OpenZeppelin Contracts's ERC165Checker may revert instead of returning false | HIGH | 7.5 | Jul 21, 2022 |
| CVE-2022-31172 | OpenZeppelin Contracts's SignatureChecker may revert on invalid EIP-1271 signers | HIGH | 7.5 | Jul 21, 2022 |
| CVE-2022-31153 | OpenZeppelin Contracts for Cairo account cannot process transactions on Goerli | MEDIUM | 6.5 | Jul 15, 2022 |
| CVE-2021-41264 | UUPSUpgradeable vulnerability in OpenZeppelin Contracts | CRITICAL | 9.8 | Nov 12, 2021 |
| CVE-2021-39167 | TimelockController vulnerability in OpenZeppelin Contracts | CRITICAL | 10.0 | Aug 26, 2021 |
| CVE-2021-39168 | TimelockController vulnerability in OpenZeppelin Contracts | CRITICAL | 10.0 | Aug 26, 2021 |
Showing 1 to 20 of 20 CVEs