parity records
14 published records for vendor parity.
Researcher profile
- Entered KEV
- 0 · 0%
- Weaponized
- 0 · 0%
- Pre-auth RCE
- 0
- With a fix record
- 28.6%
- Median publish → KEV
- No record has entered KEV
Recurring classes
- CWE-682 Incorrect Calculation2
- CWE-20 Improper Input Validation2
- CWE-203 Observable Discrepancy1
- CWE-253 Incorrect Check of Function Return Value1
- CWE-346 Origin Validation Error1
- CWE-347 Improper Verification of Cryptographic Signature1
The weakness classes this vendor ships most often: where to look.
CWEAll records
14 records| Action | CVE | Vulnerability | Severity | KEV | EPSS | Published |
|---|---|---|---|---|---|---|
39Monitor | CVE-2021-38195No exploit | An issue was discovered in the libsecp256k1 crate before 0.5.0 for Rust.parity · libsecp256k1 · CWE-347 | Critical9.8 | — | 0.9% | Aug 8, 2021 |
30Monitor | CVE-2019-25003No exploit | An issue was discovered in the libsecp256k1 crate before 0.3.1 for Rust.parity · libsecp256k1 | High7.5 | — | 1.4% | Dec 31, 2020 |
30Monitor | CVE-2017-14460No exploit | An exploitable overly permissive cross-domain (CORS) whitelist vulnerability exists in JSON-RPC of Parity Ethereum client version 1.7.8.parity · ethereum client | High7.5 | — | 1.2% | Jan 19, 2018 |
30Monitor | CVE-2023-45130No exploit | Frontier opcode SUICIDE touches too many storage values on large contractsparity · frontier · CWE-770 | High7.5 | — | 0.9% | Oct 13, 2023 |
30Monitor | CVE-2023-28431No exploit | Frontier's modexp precompile is slow for even modulusparity · frontier · CWE-682 | High7.5 | — | 0.9% | Mar 22, 2023 |
26Monitor | CVE-2022-21685No exploit | Integer underflow in Frontierparity · frontier · CWE-191 | Medium6.5 | — | 1.3% | Jan 14, 2022 |
26Monitor | CVE-2022-36008No exploit | Message length overflow in frontierparity · frontier · CWE-190 | Medium6.5 | — | 1.2% | Aug 19, 2022 |
23Monitor | CVE-2017-18016Proof of concept | Parity Browser 1.6.10 and earlier allows remote attackers to bypass the Same Origin Policy and obtain sensitive information by requesting otparity · browser · CWE-346 | Medium5.3 | — | 5.5% | Jan 11, 2018 |
23Monitor | CVE-2019-20399No exploit | A timing vulnerability in the Scalar::check_overflow function in Parity libsecp256k1-rs before 0.3.1 potentially allows an attacker to leak parity · libsecp256k1 · CWE-203 | Medium5.9 | — | 0.9% | Jan 22, 2020 |
21Monitor | CVE-2021-41138No exploit | Validity check for signed Frontier-specific extrinsic not called in block executionparity · frontier · CWE-20 | Medium5.3 | — | 1.4% | Oct 13, 2021 |
21Monitor | CVE-2022-31111No exploit | Discrepency in transfer value and actual value due to incorrect truncation in Frontierparity · frontier · CWE-670 | Medium5.3 | — | 1.4% | Jul 6, 2022 |
21Monitor | CVE-2021-39193No exploit | Transaction validity oversight in pallet-ethereumparity · frontier · CWE-20 | Medium5.3 | — | 1.2% | Sep 3, 2021 |
21Monitor | CVE-2023-34449No exploit | ink! vulnerable to incorrect decoding of storage value when using `DelegateCall`parity · ink\! · CWE-253 | Medium5.3 | — | 1.0% | Jun 14, 2023 |
21Monitor | CVE-2022-39242No exploit | Incorrect Calculation in Frontier leads to inflated Ethereum chain gas pricesparity · frontier · CWE-682 | Medium5.3 | — | 0.7% | Sep 23, 2022 |
- CVE-2021-3819539Monitor
An issue was discovered in the libsecp256k1 crate before 0.5.0 for Rust.
CriticalCVSS 9.8No exploitEPSS 1%parity · libsecp256k1Aug 8, 2021
- CVE-2019-2500330Monitor
An issue was discovered in the libsecp256k1 crate before 0.3.1 for Rust.
HighCVSS 7.5No exploitEPSS 1%parity · libsecp256k1Dec 31, 2020
- CVE-2017-1446030Monitor
An exploitable overly permissive cross-domain (CORS) whitelist vulnerability exists in JSON-RPC of Parity Ethereum client version 1.7.8.
HighCVSS 7.5No exploitEPSS 1%parity · ethereum clientJan 19, 2018
- CVE-2023-4513030Monitor
Frontier opcode SUICIDE touches too many storage values on large contracts
HighCVSS 7.5No exploitEPSS 1%parity · frontierOct 13, 2023
- CVE-2023-2843130Monitor
Frontier's modexp precompile is slow for even modulus
HighCVSS 7.5No exploitEPSS 1%parity · frontierMar 22, 2023
- CVE-2022-2168526Monitor
Integer underflow in Frontier
MediumCVSS 6.5No exploitEPSS 1%parity · frontierJan 14, 2022
- CVE-2022-3600826Monitor
Message length overflow in frontier
MediumCVSS 6.5No exploitEPSS 1%parity · frontierAug 19, 2022
- CVE-2017-1801623Monitor
Parity Browser 1.6.10 and earlier allows remote attackers to bypass the Same Origin Policy and obtain sensitive information by requesting ot
MediumCVSS 5.3Proof of conceptEPSS 5%parity · browserJan 11, 2018
- CVE-2019-2039923Monitor
A timing vulnerability in the Scalar::check_overflow function in Parity libsecp256k1-rs before 0.3.1 potentially allows an attacker to leak
MediumCVSS 5.9No exploitEPSS 1%parity · libsecp256k1Jan 22, 2020
- CVE-2021-4113821Monitor
Validity check for signed Frontier-specific extrinsic not called in block execution
MediumCVSS 5.3No exploitEPSS 1%parity · frontierOct 13, 2021
- CVE-2022-3111121Monitor
Discrepency in transfer value and actual value due to incorrect truncation in Frontier
MediumCVSS 5.3No exploitEPSS 1%parity · frontierJul 6, 2022
- CVE-2021-3919321Monitor
Transaction validity oversight in pallet-ethereum
MediumCVSS 5.3No exploitEPSS 1%parity · frontierSep 3, 2021
- CVE-2023-3444921Monitor
ink! vulnerable to incorrect decoding of storage value when using `DelegateCall`
MediumCVSS 5.3No exploitEPSS 1%parity · ink\!Jun 14, 2023
- CVE-2022-3924221Monitor
Incorrect Calculation in Frontier leads to inflated Ethereum chain gas prices
MediumCVSS 5.3No exploitEPSS 1%parity · frontierSep 23, 2022