CVE-2018-10376: Smartmesh
High severity, CVSS 7.5. EPSS: 1.8% chance of exploitation in the next 30 days.
An integer overflow in the transferProxy function of a smart contract implementation for SmartMesh (aka SMT), an Ethereum ERC20 token, allows attackers to accomplish an unauthorized increase of digital assets via crafted _fee and _value parameters, as exploited in the wild in April 2018, aka the "proxyOverflow" issue.
Affected products
- Smartmesh Smartmesh: affected versions not specified
Published 2018-04-25. Last modified 2026-06-17.