shapeshift records
5 published records for vendor shapeshift.
Researcher profile
- Entered KEV
- 0 · 0%
- Weaponized
- 0 · 0%
- Pre-auth RCE
- 0
- With a fix record
- 0%
- Median publish → KEV
- No record has entered KEV
Recurring classes
- CWE-125 Out-of-bounds Read1
- CWE-134 Use of Externally-Controlled Format String1
- CWE-203 Observable Discrepancy1
- CWE-354 Improper Validation of Integrity Check Value1
- CWE-787 Out-of-bounds Write1
The weakness classes this vendor ships most often: where to look.
CWEAttack profile
All records
5 records| Action | CVE | Vulnerability | Severity | KEV | EPSS | Published |
|---|---|---|---|---|---|---|
36Monitor | CVE-2021-31616No exploit | Insufficient length checks in the ShapeShift KeepKey hardware wallet firmware before 7.1.0 allow a stack buffer overflow via crafted messageshapeshift · keepkey firmware · CWE-787 | High8.8 | — | 2.5% | May 6, 2021 |
30Monitor | CVE-2018-6875No exploit | Format String vulnerability in KeepKey version 4.0.0 allows attackers to trigger information display (of information that should not be accekeepkey · keepkey · CWE-134 | High7.5 | — | 1.1% | Mar 14, 2018 |
30Monitor | CVE-2019-18672No exploit | Insufficient checks in the finite state machine of the ShapeShift KeepKey hardware wallet before firmware 6.2.2 allow a partial reset of cryshapeshift · keepkey firmware · CWE-354 | High7.5 | — | 0.8% | Dec 6, 2019 |
22Monitor | CVE-2023-27892No exploit | Insufficient length checks in the ShapeShift KeepKey hardware wallet firmware before 7.7.0 allow a global buffer overflow via crafted messagshapeshift · keepkey firmware · CWE-125 | Medium5.7 | — | 0.5% | May 2, 2023 |
9Monitor | CVE-2019-14355No exploit | On ShapeShift KeepKey devices, a side channel for the row-based OLED display was found.shapeshift · keepkey firmware · CWE-203 | Low2.4 | — | 0.3% | Aug 10, 2019 |
- CVE-2021-3161636Monitor
Insufficient length checks in the ShapeShift KeepKey hardware wallet firmware before 7.1.0 allow a stack buffer overflow via crafted message
HighCVSS 8.8No exploitEPSS 2%shapeshift · keepkey firmwareMay 6, 2021
- CVE-2018-687530Monitor
Format String vulnerability in KeepKey version 4.0.0 allows attackers to trigger information display (of information that should not be acce
HighCVSS 7.5No exploitEPSS 1%keepkey · keepkeyMar 14, 2018
- CVE-2019-1867230Monitor
Insufficient checks in the finite state machine of the ShapeShift KeepKey hardware wallet before firmware 6.2.2 allow a partial reset of cry
HighCVSS 7.5No exploitEPSS 1%shapeshift · keepkey firmwareDec 6, 2019
- CVE-2023-2789222Monitor
Insufficient length checks in the ShapeShift KeepKey hardware wallet firmware before 7.7.0 allow a global buffer overflow via crafted messag
MediumCVSS 5.7No exploitEPSS 0%shapeshift · keepkey firmwareMay 2, 2023
- CVE-2019-143559Monitor
On ShapeShift KeepKey devices, a side channel for the row-based OLED display was found.
LowCVSS 2.4No exploitEPSS 0%shapeshift · keepkey firmwareAug 10, 2019