CVE-2018-11239 describes an integer overflow in the _transfer function of the Hexagon (HXG) Ethereum ERC20 token smart contract. This vulnerability allows an attacker to illicitly increase their digital assets by manipulating the _to and _value arguments during a transfer. Rated 7.5 HIGH on CVSS, it is a network-exploitable vulnerability with low attack complexity and high impact on integrity, requiring no user interaction or privileges. While exploited in the wild in May 2018, there is no public exploit code available, nor significant community discussion or media coverage surrounding this issue.
| Vendor | Product | Version(s) | CPE |
|---|---|---|---|
Range not provided by sourceCPE matchmatch criteria | cpe:2.3:a:hexagontoken:hexagon:-:*:*:*:*:*:*:* |
CVSS version used by this source: 3.0
CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:H/A:N
The average CVE in this peer group has 0.0 Twitter, 0.0 Reddit, 0.1 Bluesky, 0.1 Mastodon, and 0.4 GitHub mentions.
No media coverage found for this CVE.
The average CVE in this peer group has 0.1 InfoSec Media, 0.0 Vendor Blog, and 0.0 Security Researcher mentions.
Remediation records are not available for this CVE.