{"api_version":"1","generated_at":"2026-07-23T12:03:36+00:00","cve":"CVE-2018-18667","urls":{"html":"https://cve.report/CVE-2018-18667","api":"https://cve.report/api/cve/CVE-2018-18667.json","docs":"https://cve.report/api","cve_org":"https://www.cve.org/CVERecord?id=CVE-2018-18667","nvd":"https://nvd.nist.gov/vuln/detail/CVE-2018-18667"},"summary":{"title":"CVE-2018-18667","description":"The mintToken function of Pylon (PYLNT) aka PylonToken, an Ethereum token, has an integer overflow that allows the owner of the contract to set the balance of an arbitrary user to any value, a related issue to CVE-2018-11812.","state":"PUBLIC","assigner":"cve@mitre.org","published_at":"2018-12-28 17:29:00","updated_at":"2019-01-11 20:14:00"},"problem_types":["CWE-190"],"metrics":[],"references":[{"url":"https://etherscan.io/address/0x7703c35cffdc5cda8d27aa3df2f9ba6964544b6e#code","name":"https://etherscan.io/address/0x7703c35cffdc5cda8d27aa3df2f9ba6964544b6e#code","refsource":"MISC","tags":["Third Party Advisory"],"title":"PylonToken | 0x7703c35cffdc5cda8d27aa3df2f9ba6964544b6e","mime":"text/html","httpstatus":"200","archivestatus":"0"},{"url":"https://github.com/n0pn0pn0p/smart_contract_-vulnerability/blob/master/PolyAi.md","name":"https://github.com/n0pn0pn0p/smart_contract_-vulnerability/blob/master/PolyAi.md","refsource":"MISC","tags":["Exploit","Third Party Advisory"],"title":"smart_contract_-vulnerability/PolyAi.md at master · n0pn0pn0p/smart_contract_-vulnerability · GitHub","mime":"text/html","httpstatus":"200","archivestatus":"200"},{"url":"https://github.com/klenergy/ethereum-contracts/issues/1","name":"https://github.com/klenergy/ethereum-contracts/issues/1","refsource":"MISC","tags":["Exploit","Third Party Advisory"],"title":"a overflow vulnerability in mintToken · Issue #1 · klenergy/ethereum-contracts · GitHub","mime":"text/html","httpstatus":"200","archivestatus":"200"},{"url":"https://www.cve.org/CVERecord?id=CVE-2018-18667","name":"CVE Program record","refsource":"CVE.ORG","tags":["canonical"]},{"url":"https://nvd.nist.gov/vuln/detail/CVE-2018-18667","name":"NVD vulnerability detail","refsource":"NVD","tags":["canonical","analysis"]}],"affected":[],"timeline":[],"solutions":[],"workarounds":[],"exploits":[],"credits":[],"nvd_cpes":[{"cve_year":"2018","cve_id":"18667","vulnerable":"1","versionEndIncluding":"","cpe1":"cpe","cpe2":"2.3","cpe3":"a","cpe4":"pylon-network","cpe5":"pylontoken","cpe6":"-","cpe7":"*","cpe8":"*","cpe9":"*","cpe10":"*","cpe11":"*","cpe12":"*","cpe13":"*"},{"cve_year":"2018","cve_id":"18667","vulnerable":"1","versionEndIncluding":"1","cpe1":"cpe","cpe2":"2.3","cpe3":"a","cpe4":"pylon-network","cpe5":"pylontoken","cpe6":"-","cpe7":"*","cpe8":"*","cpe9":"*","cpe10":"*","cpe11":"*","cpe12":"*","cpe13":"*"}],"vendor_comments":[],"enrichments":{"kev":null,"epss":null,"legacy_qids":[]},"source_records":{"cve_program":{"CVE_data_meta":{"ASSIGNER":"cve@mitre.org","ID":"CVE-2018-18667","STATE":"PUBLIC"},"affects":{"vendor":{"vendor_data":[{"product":{"product_data":[{"product_name":"n/a","version":{"version_data":[{"version_value":"n/a"}]}}]},"vendor_name":"n/a"}]}},"data_format":"MITRE","data_type":"CVE","data_version":"4.0","description":{"description_data":[{"lang":"eng","value":"The mintToken function of Pylon (PYLNT) aka PylonToken, an Ethereum token, has an integer overflow that allows the owner of the contract to set the balance of an arbitrary user to any value, a related issue to CVE-2018-11812."}]},"problemtype":{"problemtype_data":[{"description":[{"lang":"eng","value":"n/a"}]}]},"references":{"reference_data":[{"name":"https://github.com/n0pn0pn0p/smart_contract_-vulnerability/blob/master/PolyAi.md","refsource":"MISC","url":"https://github.com/n0pn0pn0p/smart_contract_-vulnerability/blob/master/PolyAi.md"},{"name":"https://etherscan.io/address/0x7703c35cffdc5cda8d27aa3df2f9ba6964544b6e#code","refsource":"MISC","url":"https://etherscan.io/address/0x7703c35cffdc5cda8d27aa3df2f9ba6964544b6e#code"},{"name":"https://github.com/klenergy/ethereum-contracts/issues/1","refsource":"MISC","url":"https://github.com/klenergy/ethereum-contracts/issues/1"}]}},"nvd":{"publishedDate":"2018-12-28 17:29:00","lastModifiedDate":"2019-01-11 20:14:00","problem_types":["CWE-190"],"metrics":{"baseMetricV3":{"cvssV3":{"version":"3.0","vectorString":"CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:H/A:N","attackVector":"NETWORK","attackComplexity":"LOW","privilegesRequired":"NONE","userInteraction":"NONE","scope":"UNCHANGED","confidentialityImpact":"NONE","integrityImpact":"HIGH","availabilityImpact":"NONE","baseScore":7.5,"baseSeverity":"HIGH"},"exploitabilityScore":3.9,"impactScore":3.6},"baseMetricV2":{"cvssV2":{"version":"2.0","vectorString":"AV:N/AC:L/Au:N/C:N/I:P/A:N","accessVector":"NETWORK","accessComplexity":"LOW","authentication":"NONE","confidentialityImpact":"NONE","integrityImpact":"PARTIAL","availabilityImpact":"NONE","baseScore":5},"severity":"MEDIUM","exploitabilityScore":10,"impactScore":2.9,"acInsufInfo":false,"obtainAllPrivilege":false,"obtainUserPrivilege":false,"obtainOtherPrivilege":false,"userInteractionRequired":false}},"configurations":{"CVE_data_version":"4.0","nodes":[{"operator":"OR","children":[],"cpe_match":[{"vulnerable":true,"cpe23Uri":"cpe:2.3:a:pylon-network:pylontoken:-:*:*:*:*:*:*:*","cpe_name":[]}]}]}},"legacy_mitre":{"record":{"CveYear":"2018","CveId":"18667","Ordinal":"135588","Title":"CVE-2018-18667","CVE":"CVE-2018-18667","Year":"2018"},"notes":[{"CveYear":"2018","CveId":"18667","Ordinal":"1","NoteData":"The mintToken function of Pylon (PYLNT) aka PylonToken, an Ethereum token, has an integer overflow that allows the owner of the contract to set the balance of an arbitrary user to any value, a related issue to CVE-2018-11812.","Type":"Description","Title":null},{"CveYear":"2018","CveId":"18667","Ordinal":"2","NoteData":"2018-12-28","Type":"Other","Title":"Published"},{"CveYear":"2018","CveId":"18667","Ordinal":"3","NoteData":"2018-12-28","Type":"Other","Title":"Modified"}]}}}