CVE-2017-14457 is a high-severity information leak and denial-of-service vulnerability affecting the libevm (Ethereum Virtual Machine) create2 opcode handler in CPP-Ethereum. An unauthenticated attacker can exploit this by deploying a specially crafted smart contract, leading to an out-of-bounds read that can disclose memory contents or cause a denial of service. While the CVSS score is 8.2 (HIGH), indicating a critical risk, there is currently no known active exploitation, public exploit code (Metasploit, Nuclei, ExploitDB), or significant community discussion or media coverage surrounding this vulnerability.
| Vendor | Product | Version(s) | CPE |
|---|---|---|---|
Range not provided by sourceCPE matchmatch criteria | cpe:2.3:a:ethereum:ethereum_virtual_machine:-:*:*:*:*:*:*:* |
CVSS version used by this source: 3.0
CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:H
The average CVE in this peer group has 0.0 Twitter, 0.0 Reddit, 0.1 Bluesky, 0.1 Mastodon, and 0.4 GitHub mentions.
No media coverage found for this CVE.
The average CVE in this peer group has 0.1 InfoSec Media, 0.0 Vendor Blog, and 0.0 Security Researcher mentions.
Remediation records are not available for this CVE.