CVE-2018-10376 describes an integer overflow vulnerability in the SmartMesh (SMT) ERC20 token's smart contract, specifically within the transferProxy function. This flaw allows an attacker to illicitly inflate their digital asset holdings by manipulating the _fee and _value parameters. With a CVSS score of 7.5 (HIGH), the vulnerability is network-exploitable with low attack complexity, leading to high integrity impact without requiring user interaction. This "proxyOverflow" issue was actively exploited in the wild in April 2018, though no public exploit code or significant community discussion is currently available.
| Vendor | Product | Version(s) | CPE |
|---|---|---|---|
Range not provided by sourceCPE matchmatch criteria | cpe:2.3:a:smartmesh:smartmesh:-:*:*:*:*:*:*:* |
CVSS version used by this source: 3.0
CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:H/A:N
The average CVE in this peer group has 0.0 Twitter, 0.0 Reddit, 0.1 Bluesky, 0.1 Mastodon, and 0.4 GitHub mentions.
No media coverage found for this CVE.
The average CVE in this peer group has 0.1 InfoSec Media, 0.0 Vendor Blog, and 0.0 Security Researcher mentions.
Remediation records are not available for this CVE.