CVE-2017-14457: Ethereum Virtual Machine
High severity, CVSS 8.2. EPSS: 1.7% chance of exploitation in the next 30 days.
An exploitable information leak/denial of service vulnerability exists in the libevm (Ethereum Virtual Machine) `create2` opcode handler of CPP-Ethereum. A specially crafted smart contract code can cause an out-of-bounds read leading to memory disclosure or denial of service. An attacker can create/send malicious a smart contract to trigger this vulnerability.
Affected products
- Ethereum Ethereum Virtual Machine: affected versions not specified
Published 2018-01-19. Last modified 2026-06-17.