Block maintains a narrowly scoped vulnerability footprint centered on its EOS and JIT-WASM products, where the durable signal reflects parser and memory-handling vulnerabilities such as improper input validation and out-of-bounds writes. Current severity, exploitation, and exposure counts are shown alongside this summary.
The number and severity of CVEs published that impact products developed by Block over time
Signals from CVEs in this vendor scope (2 CVEs).
2 CVEs · Highest risk first
| CVE | Published | CVSS | Risk | KEV | Exploit |
|---|---|---|---|---|---|
CVE-2018-13443HIGH EOS.IO jit-wasm 4.1 has a heap-based buffer overflow via a crafted wast file. | Apr 24, 2019 | 8.8 | 29 | NO | NO |
CVE-2018-11548HIGH An issue was discovered in EOS.IO DAWN 4.2. plugins/net_plugin/net_plugin.cpp does not limit the number of P2P connections from the same source IP address. | May 29, 2018 | 7.5 | 24 | NO | NO |
Signals from CVEs in this vendor scope (2 CVEs).
An overview of all social media posts that mention a CVE ID that affects a product developed by Block.
Media articles that mention a CVE ID that affects a product developed by Block — matched by CVE ID, not by vendor name.