{"api_version":"1","generated_at":"2026-07-23T09:18:49+00:00","cve":"CVE-2018-18665","urls":{"html":"https://cve.report/CVE-2018-18665","api":"https://cve.report/api/cve/CVE-2018-18665.json","docs":"https://cve.report/api","cve_org":"https://www.cve.org/CVERecord?id=CVE-2018-18665","nvd":"https://nvd.nist.gov/vuln/detail/CVE-2018-18665"},"summary":{"title":"CVE-2018-18665","description":"The mintToken function of Nexxus (NXX) aka NexxusToken, an Ethereum token, has an integer overflow that allows the owner of the contract to set the balance of an arbitrary user to any value.","state":"PUBLIC","assigner":"cve@mitre.org","published_at":"2018-12-28 17:29:00","updated_at":"2019-01-11 20:34:00"},"problem_types":["CWE-190"],"metrics":[],"references":[{"url":"https://github.com/NexxusUniversity/nexxuscoin/issues/2","name":"https://github.com/NexxusUniversity/nexxuscoin/issues/2","refsource":"MISC","tags":["Exploit","Third Party Advisory"],"title":"a overflow vulnerability in mintToken · Issue #2 · NexxusUniversity/nexxuscoin · GitHub","mime":"text/html","httpstatus":"200","archivestatus":"200"},{"url":"https://etherscan.io/address/0x7627de4b93263a6a7570b8dafa64bae812e5c394#code","name":"https://etherscan.io/address/0x7627de4b93263a6a7570b8dafa64bae812e5c394#code","refsource":"MISC","tags":["Third Party Advisory"],"title":"Nexxus Coin | 0x7627de4b93263a6a7570b8dafa64bae812e5c394","mime":"text/html","httpstatus":"200","archivestatus":"0"},{"url":"https://github.com/n0pn0pn0p/smart_contract_-vulnerability/blob/master/PolyAi.md","name":"https://github.com/n0pn0pn0p/smart_contract_-vulnerability/blob/master/PolyAi.md","refsource":"MISC","tags":["Exploit","Third Party Advisory"],"title":"smart_contract_-vulnerability/PolyAi.md at master · n0pn0pn0p/smart_contract_-vulnerability · GitHub","mime":"text/html","httpstatus":"200","archivestatus":"200"},{"url":"https://www.cve.org/CVERecord?id=CVE-2018-18665","name":"CVE Program record","refsource":"CVE.ORG","tags":["canonical"]},{"url":"https://nvd.nist.gov/vuln/detail/CVE-2018-18665","name":"NVD vulnerability detail","refsource":"NVD","tags":["canonical","analysis"]}],"affected":[],"timeline":[],"solutions":[],"workarounds":[],"exploits":[],"credits":[],"nvd_cpes":[{"cve_year":"2018","cve_id":"18665","vulnerable":"1","versionEndIncluding":"","cpe1":"cpe","cpe2":"2.3","cpe3":"a","cpe4":"nexxuscoin","cpe5":"nexxustoken","cpe6":"-","cpe7":"*","cpe8":"*","cpe9":"*","cpe10":"*","cpe11":"*","cpe12":"*","cpe13":"*"},{"cve_year":"2018","cve_id":"18665","vulnerable":"1","versionEndIncluding":"1","cpe1":"cpe","cpe2":"2.3","cpe3":"a","cpe4":"nexxuscoin","cpe5":"nexxustoken","cpe6":"-","cpe7":"*","cpe8":"*","cpe9":"*","cpe10":"*","cpe11":"*","cpe12":"*","cpe13":"*"}],"vendor_comments":[],"enrichments":{"kev":null,"epss":null,"legacy_qids":[]},"source_records":{"cve_program":{"CVE_data_meta":{"ASSIGNER":"cve@mitre.org","ID":"CVE-2018-18665","STATE":"PUBLIC"},"affects":{"vendor":{"vendor_data":[{"product":{"product_data":[{"product_name":"n/a","version":{"version_data":[{"version_value":"n/a"}]}}]},"vendor_name":"n/a"}]}},"data_format":"MITRE","data_type":"CVE","data_version":"4.0","description":{"description_data":[{"lang":"eng","value":"The mintToken function of Nexxus (NXX) aka NexxusToken, an Ethereum token, has an integer overflow that allows the owner of the contract to set the balance of an arbitrary user to any value."}]},"problemtype":{"problemtype_data":[{"description":[{"lang":"eng","value":"n/a"}]}]},"references":{"reference_data":[{"name":"https://github.com/n0pn0pn0p/smart_contract_-vulnerability/blob/master/PolyAi.md","refsource":"MISC","url":"https://github.com/n0pn0pn0p/smart_contract_-vulnerability/blob/master/PolyAi.md"},{"name":"https://etherscan.io/address/0x7627de4b93263a6a7570b8dafa64bae812e5c394#code","refsource":"MISC","url":"https://etherscan.io/address/0x7627de4b93263a6a7570b8dafa64bae812e5c394#code"},{"name":"https://github.com/NexxusUniversity/nexxuscoin/issues/2","refsource":"MISC","url":"https://github.com/NexxusUniversity/nexxuscoin/issues/2"}]}},"nvd":{"publishedDate":"2018-12-28 17:29:00","lastModifiedDate":"2019-01-11 20:34:00","problem_types":["CWE-190"],"metrics":{"baseMetricV3":{"cvssV3":{"version":"3.0","vectorString":"CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:H/A:N","attackVector":"NETWORK","attackComplexity":"LOW","privilegesRequired":"NONE","userInteraction":"NONE","scope":"UNCHANGED","confidentialityImpact":"NONE","integrityImpact":"HIGH","availabilityImpact":"NONE","baseScore":7.5,"baseSeverity":"HIGH"},"exploitabilityScore":3.9,"impactScore":3.6},"baseMetricV2":{"cvssV2":{"version":"2.0","vectorString":"AV:N/AC:L/Au:N/C:N/I:P/A:N","accessVector":"NETWORK","accessComplexity":"LOW","authentication":"NONE","confidentialityImpact":"NONE","integrityImpact":"PARTIAL","availabilityImpact":"NONE","baseScore":5},"severity":"MEDIUM","exploitabilityScore":10,"impactScore":2.9,"acInsufInfo":false,"obtainAllPrivilege":false,"obtainUserPrivilege":false,"obtainOtherPrivilege":false,"userInteractionRequired":false}},"configurations":{"CVE_data_version":"4.0","nodes":[{"operator":"OR","children":[],"cpe_match":[{"vulnerable":true,"cpe23Uri":"cpe:2.3:a:nexxuscoin:nexxustoken:-:*:*:*:*:*:*:*","cpe_name":[]}]}]}},"legacy_mitre":{"record":{"CveYear":"2018","CveId":"18665","Ordinal":"135586","Title":"CVE-2018-18665","CVE":"CVE-2018-18665","Year":"2018"},"notes":[{"CveYear":"2018","CveId":"18665","Ordinal":"1","NoteData":"The mintToken function of Nexxus (NXX) aka NexxusToken, an Ethereum token, has an integer overflow that allows the owner of the contract to set the balance of an arbitrary user to any value.","Type":"Description","Title":null},{"CveYear":"2018","CveId":"18665","Ordinal":"2","NoteData":"2018-12-28","Type":"Other","Title":"Published"},{"CveYear":"2018","CveId":"18665","Ordinal":"3","NoteData":"2018-12-28","Type":"Other","Title":"Modified"}]}}}