This repository has been archived by the owner on Nov 26, 2023. It is now read-only.
-
Notifications
You must be signed in to change notification settings - Fork 7
Issues: sherlock-audit/2023-05-USSD-judging
Author
Label
Projects
Milestones
Assignee
Sort
Issues list
WATCHPUG - Lack of Redeem Feature
Escalation Resolved
This issue's escalations have been approved/rejected
Has Duplicates
A valid issue with 1+ other issues describing the same vulnerability
Medium
A valid Medium severity issue
Reward
A payout will be made for this issue
#958
opened May 24, 2023 by
sherlock-admin
WATCHPUG - Oracle price should be denominated in DAI instead of USD
Escalation Resolved
This issue's escalations have been approved/rejected
Has Duplicates
A valid issue with 1+ other issues describing the same vulnerability
High
A valid High severity issue
Reward
A payout will be made for this issue
#909
opened May 24, 2023 by
sherlock-admin
neumo - If collateral factor is high enough, flutter ends up being out of bounds
Escalation Resolved
This issue's escalations have been approved/rejected
Has Duplicates
A valid issue with 1+ other issues describing the same vulnerability
Medium
A valid Medium severity issue
Reward
A payout will be made for this issue
#889
opened May 24, 2023 by
sherlock-admin
WATCHPUG - Using the collateral assets' oracle price at 100% of its value to mint USSD without a fee can be used for arbitrage.
Escalation Resolved
This issue's escalations have been approved/rejected
Medium
A valid Medium severity issue
Reward
A payout will be made for this issue
#836
opened May 24, 2023 by
sherlock-admin
WATCHPUG - Wrong Oracle feed addresses
Has Duplicates
A valid issue with 1+ other issues describing the same vulnerability
High
A valid High severity issue
Reward
A payout will be made for this issue
#817
opened May 24, 2023 by
sherlock-admin
WATCHPUG - Uniswap v3 pool token balance proportion does not necessarily correspond to the price, and it is easy to manipulate.
Escalation Resolved
This issue's escalations have been approved/rejected
Has Duplicates
A valid issue with 1+ other issues describing the same vulnerability
High
A valid High severity issue
Reward
A payout will be made for this issue
#808
opened May 24, 2023 by
sherlock-admin
WATCHPUG - Lack of access control for A valid issue with 1+ other issues describing the same vulnerability
High
A valid High severity issue
Reward
A payout will be made for this issue
mintRebalancer()
and burnRebalancer()
Has Duplicates
#777
opened May 24, 2023 by
sherlock-admin
Proxy - Not using slippage parameter or deadline while swapping on UniswapV3
Has Duplicates
A valid issue with 1+ other issues describing the same vulnerability
High
A valid High severity issue
Reward
A payout will be made for this issue
#673
opened May 24, 2023 by
sherlock-admin
T1MOH - This issue's escalations have been approved/rejected
Has Duplicates
A valid issue with 1+ other issues describing the same vulnerability
Medium
A valid Medium severity issue
Reward
A payout will be made for this issue
BuyUSSDSellCollateral()
always sells 0 amount if need to sell part of collateral
Escalation Resolved
#656
opened May 24, 2023 by
sherlock-admin
RaymondFam - Risk of Incorrect Asset Pricing by StableOracle in Case of Underlying Aggregator Reaching minAnswer
Has Duplicates
A valid issue with 1+ other issues describing the same vulnerability
Medium
A valid Medium severity issue
Reward
A payout will be made for this issue
#598
opened May 24, 2023 by
sherlock-admin
0xRobocop - Wrong computation of the amountToSellUnit variable
Has Duplicates
A valid issue with 1+ other issues describing the same vulnerability
High
A valid High severity issue
Reward
A payout will be made for this issue
#535
opened May 24, 2023 by
sherlock-admin
0xRobocop - Inconsistency handling of DAI as collateral in the BuyUSSDSellCollateral function
Has Duplicates
A valid issue with 1+ other issues describing the same vulnerability
Medium
A valid Medium severity issue
Reward
A payout will be made for this issue
#515
opened May 24, 2023 by
sherlock-admin
carrotsmuggler - Price calculation susceptible to flashloan exploits
Has Duplicates
A valid issue with 1+ other issues describing the same vulnerability
High
A valid High severity issue
Reward
A payout will be made for this issue
#451
opened May 23, 2023 by
sherlock-admin
Bauer - Inaccurate collateral factor calculation due to missing collateral asset
Has Duplicates
A valid issue with 1+ other issues describing the same vulnerability
Medium
A valid Medium severity issue
Reward
A payout will be made for this issue
#341
opened May 23, 2023 by
sherlock-admin
Bauchibred - StableOracleWBTC use BTC/USD chainlink oracle to price WBTC which is problematic if WBTC depegs
Escalation Resolved
This issue's escalations have been approved/rejected
Has Duplicates
A valid issue with 1+ other issues describing the same vulnerability
Medium
A valid Medium severity issue
Reward
A payout will be made for this issue
#310
opened May 23, 2023 by
sherlock-admin
Dug - The price from A valid issue with 1+ other issues describing the same vulnerability
High
A valid High severity issue
Reward
A payout will be made for this issue
StableOracleDAI
is returned with the incorrect number of decimals
Has Duplicates
#236
opened May 23, 2023 by
sherlock-admin
Bauer - The getOwnValuation() function contains errors in the price calculation
Has Duplicates
A valid issue with 1+ other issues describing the same vulnerability
High
A valid High severity issue
Reward
A payout will be made for this issue
#222
opened May 23, 2023 by
sherlock-admin
J4de - A valid issue with 1+ other issues describing the same vulnerability
High
A valid High severity issue
Reward
A payout will be made for this issue
USSDRebalancer.sol#SellUSSDBuyCollateral
the check of whether collateral is DAI is wrong
Has Duplicates
#193
opened May 23, 2023 by
sherlock-admin
saidam017 - rebalance process incase of selling the collateral, could revert because of underflow calculation
Has Duplicates
A valid issue with 1+ other issues describing the same vulnerability
Medium
A valid Medium severity issue
Reward
A payout will be made for this issue
#111
opened May 23, 2023 by
sherlock-admin
juancito - This issue's escalations have been approved/rejected
Has Duplicates
A valid issue with 1+ other issues describing the same vulnerability
High
A valid High severity issue
Reward
A payout will be made for this issue
StableOracleDAI
calculates getPriceUSD
with inverted base/rate tokens for Chainlink price
Escalation Resolved
#102
opened May 23, 2023 by
sherlock-admin
Kose - Because of missing slippage parameter, mintForToken() can be front-runned
Has Duplicates
A valid issue with 1+ other issues describing the same vulnerability
Medium
A valid Medium severity issue
Reward
A payout will be made for this issue
#97
opened May 23, 2023 by
sherlock-admin
dacian - Calls to Oracles don't check for stale prices
Has Duplicates
A valid issue with 1+ other issues describing the same vulnerability
Medium
A valid Medium severity issue
Reward
A payout will be made for this issue
#31
opened May 23, 2023 by
sherlock-admin
ProTip!
Type g i on any issue or pull request to go back to the issue listing page.