Vulnerabilities (CVE)

Join the Common Vulnerabilities and Exposures (CVE) community and start to get notified about new vulnerabilities.

Filtered by vendor Mycryptochamp Subscribe
Filtered by product Mycryptochamp
Total 1 CVE
CVE Vendors Products Updated CVSS v2 CVSS v3
CVE-2018-12885 1 Mycryptochamp 1 Mycryptochamp 2018-10-18 4.3 MEDIUM 5.9 MEDIUM
The randMod() function of the smart contract implementation for MyCryptoChamp, an Ethereum game, generates a random value with publicly readable variables such as the current block information and a private variable, (which can be read with a getStorageAt call). Therefore, attackers can get powerful champs/items and get rewards.