Vulnerabilities > Shapeshift > High
DATE | CVE | VULNERABILITY TITLE | RISK |
---|---|---|---|
2021-05-06 | CVE-2021-31616 | Out-of-bounds Write vulnerability in Shapeshift Keepkey Firmware 7.0.3 Insufficient length checks in the ShapeShift KeepKey hardware wallet firmware before 7.1.0 allow a stack buffer overflow via crafted messages. | 8.8 |
2019-12-06 | CVE-2019-18672 | Improper Validation of Integrity Check Value vulnerability in Shapeshift Keepkey Firmware Insufficient checks in the finite state machine of the ShapeShift KeepKey hardware wallet before firmware 6.2.2 allow a partial reset of cryptographic secrets to known values via crafted messages. | 7.5 |
2018-03-14 | CVE-2018-6875 | Use of Externally-Controlled Format String vulnerability in Shapeshift Keepkey Firmware 4.0.0 Format String vulnerability in KeepKey version 4.0.0 allows attackers to trigger information display (of information that should not be accessible), related to text containing characters that the device's font lacks. | 7.5 |