-
Notifications
You must be signed in to change notification settings - Fork 1
Issues: sherlock-audit/2024-06-new-scope-judging
New issue
Have a question about this project? Sign up for a free GitHub account to open an issue and contact its maintainers and the community.
By clicking “Sign up for GitHub”, you agree to our terms of service and privacy statement. We’ll occasionally send you account related emails.
Already on GitHub? Sign in to your account
Author
Label
Projects
Milestones
Assignee
Sort
Issues list
ether_sky - The repayment process in the NFTPositionManager can sometimes be reverted
Has Duplicates
A valid issue with 1+ other issues describing the same vulnerability
Medium
A Medium severity issue.
Reward
A payout will be made for this issue
#488
opened Sep 10, 2024 by
sherlock-admin4
KupiaSec - Wrong calculation of supply/debt balance of a position, disrupting core system functionalities
Escalation Resolved
This issue's escalations have been approved/rejected
Has Duplicates
A valid issue with 1+ other issues describing the same vulnerability
High
A High severity issue.
Reward
A payout will be made for this issue
#473
opened Sep 10, 2024 by
sherlock-admin2
hyh - NFTPositionManager's This issue's escalations have been approved/rejected
Has Duplicates
A valid issue with 1+ other issues describing the same vulnerability
Medium
A Medium severity issue.
Reward
A payout will be made for this issue
repay()
and repayETH()
are unavailable unless preceded atomically by an accounting updating operation
Escalation Resolved
#467
opened Sep 10, 2024 by
sherlock-admin4
Nihavent - Curated Vault allocators cannot A valid issue with 1+ other issues describing the same vulnerability
Medium
A Medium severity issue.
Reward
A payout will be made for this issue
reallocate()
a pool to zero due to attempting to withdraw 0 tokens from the underlying pool
Has Duplicates
#434
opened Sep 10, 2024 by
sherlock-admin3
Nihavent - This issue's escalations have been approved/rejected
Has Duplicates
A valid issue with 1+ other issues describing the same vulnerability
Medium
A Medium severity issue.
Reward
A payout will be made for this issue
CuratedVaultSetters::_supplyPool()
does not consider the pool cap of the underlying pool, which may cause deposit()
to revert or lead to an unintended reordering of supplyQueue
Escalation Resolved
#433
opened Sep 10, 2024 by
sherlock-admin3
Nihavent - Supply interest is earned on This issue's escalations have been approved/rejected
Has Duplicates
A valid issue with 1+ other issues describing the same vulnerability
Medium
A Medium severity issue.
Reward
A payout will be made for this issue
accruedToTreasuryShares
resulting in higher than expected treasury fees and under rare circumstances DOSed pool withdrawals
Escalation Resolved
#430
opened Sep 10, 2024 by
sherlock-admin3
Nihavent - Unclaimable reserve assets will accrue in a pool due to the difference between interest paid on borrows and interest earned on supplies
Escalation Resolved
This issue's escalations have been approved/rejected
Has Duplicates
A valid issue with 1+ other issues describing the same vulnerability
Medium
A Medium severity issue.
Reward
A payout will be made for this issue
#429
opened Sep 10, 2024 by
sherlock-admin3
imsrybr0 - Interest rate is updated before updating the debt when repaying debt
Has Duplicates
A valid issue with 1+ other issues describing the same vulnerability
High
A High severity issue.
Reward
A payout will be made for this issue
#413
opened Sep 10, 2024 by
sherlock-admin3
A2-security - Inconsistent Application of Reserve Factor Changes Leads to Protocol Insolvency Risk
Escalation Resolved
This issue's escalations have been approved/rejected
Has Duplicates
A valid issue with 1+ other issues describing the same vulnerability
Medium
A Medium severity issue.
Reward
A payout will be made for this issue
#402
opened Sep 10, 2024 by
sherlock-admin3
Bigsam - Liquidation fails to update the interest Rate when liquidation funds are sent to the treasury thus the next user uses an inflated index
Has Duplicates
A valid issue with 1+ other issues describing the same vulnerability
Medium
A Medium severity issue.
Reward
A payout will be made for this issue
#401
opened Sep 10, 2024 by
sherlock-admin3
A2-security - Position Risk Management Functionality Missing in Position Manager and dos in certain conditions
Has Duplicates
A valid issue with 1+ other issues describing the same vulnerability
Medium
A Medium severity issue.
Reward
A payout will be made for this issue
#398
opened Sep 10, 2024 by
sherlock-admin3
ether_sky - The rewards distribution in the NFTPositionManager is unfair
Escalation Resolved
This issue's escalations have been approved/rejected
Has Duplicates
A valid issue with 1+ other issues describing the same vulnerability
Medium
A Medium severity issue.
Reward
A payout will be made for this issue
#393
opened Sep 10, 2024 by
sherlock-admin4
Bigsam - After a User withdraws The interest Rate is not updated accordingly leading to the next user using an inflated index during next deposit before the rate is normalized again
Has Duplicates
A valid issue with 1+ other issues describing the same vulnerability
Medium
A Medium severity issue.
Reward
A payout will be made for this issue
#387
opened Sep 10, 2024 by
sherlock-admin4
lemonmon - Function A valid issue with 1+ other issues describing the same vulnerability
High
A High severity issue.
Reward
A payout will be made for this issue
executeMintToTreasury
will incorrectly reduce the supplyShares
, therefore prevent the last users from withdrawing
Has Duplicates
#375
opened Sep 10, 2024 by
sherlock-admin3
tallo - Liquidated positions will still accrue rewards after being liquidated
Has Duplicates
A valid issue with 1+ other issues describing the same vulnerability
High
A High severity issue.
Reward
A payout will be made for this issue
#312
opened Sep 10, 2024 by
sherlock-admin4
Obsidian - When bad debt is accumulated, the loss is not shared amongst all suppliers, instead the last to withdraw will experience a huge loss
Has Duplicates
A valid issue with 1+ other issues describing the same vulnerability
High
A High severity issue.
Reward
A payout will be made for this issue
#275
opened Sep 10, 2024 by
sherlock-admin2
Obsidian - Malicious pool deployer can set a malicious interest rate contract to lock funds of vault depositors
Escalation Resolved
This issue's escalations have been approved/rejected
Has Duplicates
A valid issue with 1+ other issues describing the same vulnerability
High
A High severity issue.
Reward
A payout will be made for this issue
#233
opened Sep 10, 2024 by
sherlock-admin2
imsrybr0 - A valid issue with 1+ other issues describing the same vulnerability
High
A High severity issue.
Reward
A payout will be made for this issue
LiquidationLogic@_burnCollateralTokens
does not account for liquidation fees when withdrawing collateral during liquidation leading to incorrect accounting and Pools insolvency
Has Duplicates
#228
opened Sep 10, 2024 by
sherlock-admin3
iamnmt - An attacker can hijack the This issue's escalations have been approved/rejected
Has Duplicates
A valid issue with 1+ other issues describing the same vulnerability
High
A High severity issue.
Reward
A payout will be made for this issue
CuratedVault
's matured yield
Escalation Resolved
#199
opened Sep 10, 2024 by
sherlock-admin4
Flashloan44 - Liquidation can be DOSed due to lack of liquidity on collateral asset reserve
Escalation Resolved
This issue's escalations have been approved/rejected
Has Duplicates
A valid issue with 1+ other issues describing the same vulnerability
High
A High severity issue.
Reward
A payout will be made for this issue
#198
opened Sep 10, 2024 by
sherlock-admin3
nfmelendez - This issue's escalations have been approved/rejected
Has Duplicates
A valid issue with 1+ other issues describing the same vulnerability
Medium
A Medium severity issue.
Reward
A payout will be made for this issue
GenericLogic.sol
contract assumes all price feeds has the same decimals but is a wrong assumption that leads to an incorrect health factor math.
Escalation Resolved
#166
opened Sep 10, 2024 by
sherlock-admin4
0xNirix - Malicious actors can execute sandwich attacks during market addition with existing funds
Escalation Resolved
This issue's escalations have been approved/rejected
Medium
A Medium severity issue.
Reward
A payout will be made for this issue
#143
opened Sep 10, 2024 by
sherlock-admin3
BiasedMerc - CuratedVaults are prone to inflation attacks due to not utilising virtual shares
Escalation Resolved
This issue's escalations have been approved/rejected
Has Duplicates
A valid issue with 1+ other issues describing the same vulnerability
Medium
A Medium severity issue.
Reward
A payout will be made for this issue
#141
opened Sep 10, 2024 by
sherlock-admin3
stuart_the_minion - Full Liquidation Won't Sweep the Whole Debts With Leaving Some, And Will Wrongly Set Borrowing as False
Escalation Resolved
This issue's escalations have been approved/rejected
Has Duplicates
A valid issue with 1+ other issues describing the same vulnerability
High
A High severity issue.
Reward
A payout will be made for this issue
#107
opened Sep 10, 2024 by
sherlock-admin3
stuart_the_minion - A Reserve Borrow Rate can be significantly decreased after liquidation
Has Duplicates
A valid issue with 1+ other issues describing the same vulnerability
High
A High severity issue.
Reward
A payout will be made for this issue
#104
opened Sep 10, 2024 by
sherlock-admin2
Previous Next
ProTip!
Exclude everything labeled
bug
with -label:bug.