CVE-2018-13877
Last modified
CVE-2018-13877 is a vulnerability of currently unknown severity. The doPayouts() function of the smart contract implementation for MegaCryptoPolis, an Ethereum game, has a Denial of Service vulnerability. If a smart contract that has a fallback function always causing exceptions buys a land, users cannot buy lands near that contract's land, because those purchase attempts will not be completed unless the doPayouts() function successfully sends Ether to certain neighbors.. EPSS estimates a 1.05% chance of exploitation in the next 30 days.
Description
The doPayouts() function of the smart contract implementation for MegaCryptoPolis, an Ethereum game, has a Denial of Service vulnerability. If a smart contract that has a fallback function always causing exceptions buys a land, users cannot buy lands near that contract's land, because those purchase attempts will not be completed unless the doPayouts() function successfully sends Ether to certain neighbors.
Metrics
Weakness Enumeration
Affected Software
| Vendor | Product | Versions |
|---|---|---|
| Megacryptopolis | Megacryptopolis | All versions |
References
Timeline
- Published
- Last Modified
- Status
- Modified
Frequently Asked Questions
What is CVE-2018-13877?
How severe is CVE-2018-13877?
How do I fix CVE-2018-13877?
How Strix Helps
- How Strix found a critical auth bypass in etcdStrix autonomously discovered a critical authentication bypass in etcd, later designated CVE-2026-33413.
- Autonomous PentestingAI agents that find and validate exploitable vulnerabilities like this one across your applications.
- PR ReviewsPentest every pull request so vulnerable code is caught before it ships to production.
- AI Penetration TestingHow AI-driven penetration testing continuously covers your attack surface.
Related CVEs from 2018
- CVE-2018-13871An issue was discovered in the HDF HDF5 1.8.20 library. Ther…
- CVE-2018-13872An issue was discovered in the HDF HDF5 1.8.20 library. Ther…
- CVE-2018-13873An issue was discovered in the HDF HDF5 1.8.20 library. Ther…9.8
- CVE-2018-13874An issue was discovered in the HDF HDF5 1.8.20 library. Ther…
- CVE-2018-13875An issue was discovered in the HDF HDF5 1.8.20 library. Ther…
- CVE-2018-13876An issue was discovered in the HDF HDF5 1.8.20 library. Ther…
- CVE-2018-13878An XSS issue was discovered in packages/rocketchat-mentions/…
- CVE-2018-13879A reflected XSS issue was discovered in the registration for…
- CVE-2018-1388GSKit V7 may disclose side channel information via discrepan…
- CVE-2018-13880Rejected reason: DO NOT USE THIS CANDIDATE NUMBER. ConsultID…
- CVE-2018-13881Rejected reason: DO NOT USE THIS CANDIDATE NUMBER. ConsultID…
- CVE-2018-13882Rejected reason: DO NOT USE THIS CANDIDATE NUMBER. ConsultID…
Are you affected by CVE-2018-13877?
Run a free Strix scan to check your systems for this vulnerability.
Scan your code nowSource: NVD / NIST
