Перейти к содержимому
Noroxi

CWE-335 · 33 записей

Incorrect Usage of Seeds in Pseudo-Random Number Generator (PRNG)

CVE этого класса

33 записей

  • CVE-2017-11519
    40В плане

    passwd_recovery.lua on the TP-Link Archer C9(UN)_V2_160517 allows an attacker to reset the admin password by leveraging a predictable random

    КритическаяCVSS 9,8Proof of conceptEPSS 3 %

    tp-link · archer c9 \(2.0\) firmware21 июл. 2017 г.

  • CVE-2019-11495
    40В плане

    In Couchbase Server 5.1.1, the cookie used for intra-node communication was not generated securely.

    КритическаяCVSS 9,8Эксплойта нетEPSS 2 %

    couchbase · couchbase server10 сент. 2019 г.

  • CVE-2019-10908
    39Наблюдать

    In Airsonic 10.2.1, RecoverController.java generates passwords via org.apache.commons.lang.RandomStringUtils, which uses java.util.Random in

    КритическаяCVSS 9,8Эксплойта нетEPSS 2 %

    airsonic project · airsonic7 апр. 2019 г.

  • CVE-2012-1577
    39Наблюдать

    lib/libc/stdlib/random.c in OpenBSD returns 0 when seeded with 0.

    КритическаяCVSS 9,8Эксплойта нетEPSS 2 %

    openbsd · openbsd10 дек. 2019 г.

  • CVE-2024-36048
    39Наблюдать

    QAbstractOAuth in Qt Network Authorization in Qt before 5.15.17, 6.x before 6.2.13, 6.3.x through 6.5.x before 6.5.6, and 6.6.x through 6.7.

    КритическаяCVSS 9,8Эксплойта нетEPSS 1 %

    qt · qt18 мая 2024 г.

  • CVE-2023-4472
    39Наблюдать

    Cryptographically weak PRNG in Opinio 7.22

    КритическаяCVSS 9,8Эксплойта нетEPSS 1 %

    objectplanet · opinio1 февр. 2024 г.

  • CVE-2021-41117
    37Наблюдать

    Insecure random number generation

    КритическаяCVSS 9,1Proof of conceptEPSS 3 %

    keypair project · keypair11 окт. 2021 г.

  • CVE-2018-1426
    37Наблюдать

    IBM GSKit (IBM DB2 for Linux, UNIX and Windows 9.7, 10.1, 10.5, and 11.1) duplicates the PRNG state across fork() system calls when multiple

    КритическаяCVSS 9,1Эксплойта нетEPSS 2 %

    ibm · db222 мар. 2018 г.

  • CVE-2018-12520
    35Наблюдать

    An issue was discovered in ntopng 3.4 before 3.4.180617.

    ВысокаяCVSS 8,1Proof of conceptEPSS 11 %

    ntop · ntopng5 июл. 2018 г.

  • CVE-2024-27632
    35Наблюдать

    An issue in GNU Savane v.3.12 and before allows a remote attacker to escalate privileges via the form_id in the form_header() function.

    ВысокаяCVSS 8,8Proof of conceptEPSS 1 %

    gnu · savane8 апр. 2024 г.

  • CVE-2018-14647
    33Наблюдать

    Python's elementtree C accelerator failed to initialise Expat's hash salt during initialization.

    ВысокаяCVSS 7,5Эксплойта нетEPSS 11 %

    python · python24 сент. 2018 г.

  • CVE-2016-3735
    32Наблюдать

    Piwigo is image gallery software written in PHP.

    ВысокаяCVSS 8,1Эксплойта нетEPSS 1 %

    piwigo · piwigo28 янв. 2022 г.

  • CVE-2024-1579
    32Наблюдать

    Insufficient seeding of random number generator

    ВысокаяCVSS 8,1Эксплойта нетEPSS 1 %

    secomea · gatemanager29 апр. 2024 г.

  • CVE-2016-10180
    31Наблюдать

    An issue was discovered on the D-Link DWR-932B router.

    ВысокаяCVSS 7,5Эксплойта нетEPSS 4 %

    dlink · dwr-932b firmware30 янв. 2017 г.

  • CVE-2021-27211
    31Наблюдать

    steghide 0.5.1 relies on a certain 32-bit seed value, which makes it easier for attackers to detect hidden data.

    ВысокаяCVSS 7,5Proof of conceptEPSS 3 %

    steghide project · steghide15 февр. 2021 г.

  • CVE-2019-25061
    31Наблюдать

    The random_password_generator (aka RandomPasswordGenerator) gem through 1.0.0 for Ruby uses Kernel#rand to generate passwords, which, due to

    ВысокаяCVSS 7,5Эксплойта нетEPSS 2 %

    random password generator project · random password generator18 мая 2022 г.

  • CVE-2020-7010
    30Наблюдать

    Elastic Cloud on Kubernetes (ECK) versions prior to 1.1.0 generate passwords using a weak random number generator.

    ВысокаяCVSS 7,5Эксплойта нетEPSS 1 %

    elastic · elastic cloud on kubernetes3 июн. 2020 г.

  • CVE-2020-13784
    30Наблюдать

    D-Link DIR-865L Ax 1.20B01 Beta devices have a predictable seed in a Pseudo-Random Number Generator.

    ВысокаяCVSS 7,5Эксплойта нетEPSS 1 %

    dlink · dir-865l firmware3 июн. 2020 г.

  • CVE-2017-5214
    30Наблюдать

    The Codextrous B2J Contact (aka b2j_contact) extension before 2.1.13 for Joomla! allows prediction of a uniqid value based on knowledge of a

    ВысокаяCVSS 7,5Эксплойта нетEPSS 1 %

    codextrous · b2j contact17 мая 2017 г.

  • CVE-2022-39218
    30Наблюдать

    Random number seed fixed during compilation

    ВысокаяCVSS 7,5Эксплойта нетEPSS 1 %

    fastly · js-compute20 сент. 2022 г.

  • CVE-2025-24783
    30Наблюдать

    Apache Cocoon: continuations may not be private

    ВысокаяCVSS 7,5Эксплойта нетEPSS 1 %

    apache · cocoon27 янв. 2025 г.

  • CVE-2025-27580
    30Наблюдать

    NIH BRICS (aka Biomedical Research Informatics Computing System) through 14.0.0-67 generates predictable tokens (that depend on username, ti

    ВысокаяCVSS 7,5Proof of conceptEPSS 1 %

    nih · brics23 апр. 2025 г.

  • CVE-2026-41564
    30Наблюдать

    CryptX versions before 0.088 for Perl do not reseed the Crypt::PK PRNG state after forking

    ВысокаяCVSS 7,5Эксплойта нетEPSS 1 %

    dcit · cryptx23 апр. 2026 г.

  • CVE-2026-11702
    30Наблюдать

    Bytes::Random::Secure::Tiny versions through 1.011 for Perl share internal state across forked processes

    ВысокаяCVSS 7,5Эксплойта нетEPSS 1 %

    davido · bytes::random::secure::tiny26 июн. 2026 г.

  • CVE-2026-11625
    30Наблюдать

    Bytes::Random::Secure versions through 0.29 for Perl share internal state across forked processes

    ВысокаяCVSS 7,5Эксплойта нетEPSS 1 %

    davido · bytes::random::secure26 июн. 2026 г.

Все классы уязвимостей