CWE-335 · 33 записей
Incorrect Usage of Seeds in Pseudo-Random Number Generator (PRNG)
CVE этого класса
33 записей
| Срочность | CVE | Уязвимость | Критичность | KEV | EPSS | Опубликовано |
|---|---|---|---|---|---|---|
40В плане | CVE-2017-11519Proof of concept | passwd_recovery.lua on the TP-Link Archer C9(UN)_V2_160517 allows an attacker to reset the admin password by leveraging a predictable randomtp-link · archer c9 \(2.0\) firmware · CWE-335 | Критическая9,8 | — | 3,1 % | 21 июл. 2017 г. |
40В плане | CVE-2019-11495Эксплойта нет | In Couchbase Server 5.1.1, the cookie used for intra-node communication was not generated securely.couchbase · couchbase server · CWE-335 | Критическая9,8 | — | 2,1 % | 10 сент. 2019 г. |
39Наблюдать | CVE-2019-10908Эксплойта нет | In Airsonic 10.2.1, RecoverController.java generates passwords via org.apache.commons.lang.RandomStringUtils, which uses java.util.Random inairsonic project · airsonic · CWE-335 | Критическая9,8 | — | 1,6 % | 7 апр. 2019 г. |
39Наблюдать | CVE-2012-1577Эксплойта нет | lib/libc/stdlib/random.c in OpenBSD returns 0 when seeded with 0.openbsd · openbsd · CWE-335 | Критическая9,8 | — | 1,6 % | 10 дек. 2019 г. |
39Наблюдать | CVE-2024-36048Эксплойта нет | QAbstractOAuth in Qt Network Authorization in Qt before 5.15.17, 6.x before 6.2.13, 6.3.x through 6.5.x before 6.5.6, and 6.6.x through 6.7.qt · qt · CWE-335 | Критическая9,8 | — | 1,0 % | 18 мая 2024 г. |
39Наблюдать | CVE-2023-4472Эксплойта нет | Cryptographically weak PRNG in Opinio 7.22objectplanet · opinio · CWE-335 | Критическая9,8 | — | 0,7 % | 1 февр. 2024 г. |
37Наблюдать | CVE-2021-41117Proof of concept | Insecure random number generationkeypair project · keypair · CWE-335 | Критическая9,1 | — | 3,1 % | 11 окт. 2021 г. |
37Наблюдать | CVE-2018-1426Эксплойта нет | IBM GSKit (IBM DB2 for Linux, UNIX and Windows 9.7, 10.1, 10.5, and 11.1) duplicates the PRNG state across fork() system calls when multipleibm · db2 · CWE-335 | Критическая9,1 | — | 2,4 % | 22 мар. 2018 г. |
35Наблюдать | CVE-2018-12520Proof of concept | An issue was discovered in ntopng 3.4 before 3.4.180617.ntop · ntopng · CWE-335 | Высокая8,1 | — | 10,5 % | 5 июл. 2018 г. |
35Наблюдать | CVE-2024-27632Proof of concept | An issue in GNU Savane v.3.12 and before allows a remote attacker to escalate privileges via the form_id in the form_header() function.gnu · savane · CWE-335 | Высокая8,8 | — | 1,3 % | 8 апр. 2024 г. |
33Наблюдать | CVE-2018-14647Эксплойта нет | Python's elementtree C accelerator failed to initialise Expat's hash salt during initialization.python · python · CWE-335 | Высокая7,5 | — | 10,9 % | 24 сент. 2018 г. |
32Наблюдать | CVE-2016-3735Эксплойта нет | Piwigo is image gallery software written in PHP.piwigo · piwigo · CWE-335 | Высокая8,1 | — | 1,4 % | 28 янв. 2022 г. |
32Наблюдать | CVE-2024-1579Эксплойта нет | Insufficient seeding of random number generatorsecomea · gatemanager · CWE-335 | Высокая8,1 | — | 0,5 % | 29 апр. 2024 г. |
31Наблюдать | CVE-2016-10180Эксплойта нет | An issue was discovered on the D-Link DWR-932B router.dlink · dwr-932b firmware · CWE-335 | Высокая7,5 | — | 4,4 % | 30 янв. 2017 г. |
31Наблюдать | CVE-2021-27211Proof of concept | steghide 0.5.1 relies on a certain 32-bit seed value, which makes it easier for attackers to detect hidden data.steghide project · steghide · CWE-335 | Высокая7,5 | — | 3,3 % | 15 февр. 2021 г. |
31Наблюдать | CVE-2019-25061Эксплойта нет | The random_password_generator (aka RandomPasswordGenerator) gem through 1.0.0 for Ruby uses Kernel#rand to generate passwords, which, due torandom password generator project · random password generator · CWE-335 | Высокая7,5 | — | 1,9 % | 18 мая 2022 г. |
30Наблюдать | CVE-2020-7010Эксплойта нет | Elastic Cloud on Kubernetes (ECK) versions prior to 1.1.0 generate passwords using a weak random number generator.elastic · elastic cloud on kubernetes · CWE-335 | Высокая7,5 | — | 1,4 % | 3 июн. 2020 г. |
30Наблюдать | CVE-2020-13784Эксплойта нет | D-Link DIR-865L Ax 1.20B01 Beta devices have a predictable seed in a Pseudo-Random Number Generator.dlink · dir-865l firmware · CWE-335 | Высокая7,5 | — | 1,3 % | 3 июн. 2020 г. |
30Наблюдать | CVE-2017-5214Эксплойта нет | The Codextrous B2J Contact (aka b2j_contact) extension before 2.1.13 for Joomla! allows prediction of a uniqid value based on knowledge of acodextrous · b2j contact · CWE-335 | Высокая7,5 | — | 1,2 % | 17 мая 2017 г. |
30Наблюдать | CVE-2022-39218Эксплойта нет | Random number seed fixed during compilationfastly · js-compute · CWE-335 | Высокая7,5 | — | 0,9 % | 20 сент. 2022 г. |
30Наблюдать | CVE-2025-24783Эксплойта нет | Apache Cocoon: continuations may not be privateapache · cocoon · CWE-335 | Высокая7,5 | — | 0,8 % | 27 янв. 2025 г. |
30Наблюдать | CVE-2025-27580Proof of concept | NIH BRICS (aka Biomedical Research Informatics Computing System) through 14.0.0-67 generates predictable tokens (that depend on username, tinih · brics · CWE-335 | Высокая7,5 | — | 0,7 % | 23 апр. 2025 г. |
30Наблюдать | CVE-2026-41564Эксплойта нет | CryptX versions before 0.088 for Perl do not reseed the Crypt::PK PRNG state after forkingdcit · cryptx · CWE-335 | Высокая7,5 | — | 0,5 % | 23 апр. 2026 г. |
30Наблюдать | CVE-2026-11702Эксплойта нет | Bytes::Random::Secure::Tiny versions through 1.011 for Perl share internal state across forked processesdavido · bytes::random::secure::tiny · CWE-335 | Высокая7,5 | — | 0,5 % | 26 июн. 2026 г. |
30Наблюдать | CVE-2026-11625Эксплойта нет | Bytes::Random::Secure versions through 0.29 for Perl share internal state across forked processesdavido · bytes::random::secure · CWE-335 | Высокая7,5 | — | 0,5 % | 26 июн. 2026 г. |
- CVE-2017-1151940В плане
passwd_recovery.lua on the TP-Link Archer C9(UN)_V2_160517 allows an attacker to reset the admin password by leveraging a predictable random
КритическаяCVSS 9,8Proof of conceptEPSS 3 %tp-link · archer c9 \(2.0\) firmware21 июл. 2017 г.
- CVE-2019-1149540В плане
In Couchbase Server 5.1.1, the cookie used for intra-node communication was not generated securely.
КритическаяCVSS 9,8Эксплойта нетEPSS 2 %couchbase · couchbase server10 сент. 2019 г.
- CVE-2019-1090839Наблюдать
In Airsonic 10.2.1, RecoverController.java generates passwords via org.apache.commons.lang.RandomStringUtils, which uses java.util.Random in
КритическаяCVSS 9,8Эксплойта нетEPSS 2 %airsonic project · airsonic7 апр. 2019 г.
- CVE-2012-157739Наблюдать
lib/libc/stdlib/random.c in OpenBSD returns 0 when seeded with 0.
КритическаяCVSS 9,8Эксплойта нетEPSS 2 %openbsd · openbsd10 дек. 2019 г.
- CVE-2024-3604839Наблюдать
QAbstractOAuth in Qt Network Authorization in Qt before 5.15.17, 6.x before 6.2.13, 6.3.x through 6.5.x before 6.5.6, and 6.6.x through 6.7.
КритическаяCVSS 9,8Эксплойта нетEPSS 1 %qt · qt18 мая 2024 г.
- CVE-2023-447239Наблюдать
Cryptographically weak PRNG in Opinio 7.22
КритическаяCVSS 9,8Эксплойта нетEPSS 1 %objectplanet · opinio1 февр. 2024 г.
- CVE-2021-4111737Наблюдать
Insecure random number generation
КритическаяCVSS 9,1Proof of conceptEPSS 3 %keypair project · keypair11 окт. 2021 г.
- CVE-2018-142637Наблюдать
IBM GSKit (IBM DB2 for Linux, UNIX and Windows 9.7, 10.1, 10.5, and 11.1) duplicates the PRNG state across fork() system calls when multiple
КритическаяCVSS 9,1Эксплойта нетEPSS 2 %ibm · db222 мар. 2018 г.
- CVE-2018-1252035Наблюдать
An issue was discovered in ntopng 3.4 before 3.4.180617.
ВысокаяCVSS 8,1Proof of conceptEPSS 11 %ntop · ntopng5 июл. 2018 г.
- CVE-2024-2763235Наблюдать
An issue in GNU Savane v.3.12 and before allows a remote attacker to escalate privileges via the form_id in the form_header() function.
ВысокаяCVSS 8,8Proof of conceptEPSS 1 %gnu · savane8 апр. 2024 г.
- CVE-2018-1464733Наблюдать
Python's elementtree C accelerator failed to initialise Expat's hash salt during initialization.
ВысокаяCVSS 7,5Эксплойта нетEPSS 11 %python · python24 сент. 2018 г.
- CVE-2016-373532Наблюдать
Piwigo is image gallery software written in PHP.
ВысокаяCVSS 8,1Эксплойта нетEPSS 1 %piwigo · piwigo28 янв. 2022 г.
- CVE-2024-157932Наблюдать
Insufficient seeding of random number generator
ВысокаяCVSS 8,1Эксплойта нетEPSS 1 %secomea · gatemanager29 апр. 2024 г.
- CVE-2016-1018031Наблюдать
An issue was discovered on the D-Link DWR-932B router.
ВысокаяCVSS 7,5Эксплойта нетEPSS 4 %dlink · dwr-932b firmware30 янв. 2017 г.
- CVE-2021-2721131Наблюдать
steghide 0.5.1 relies on a certain 32-bit seed value, which makes it easier for attackers to detect hidden data.
ВысокаяCVSS 7,5Proof of conceptEPSS 3 %steghide project · steghide15 февр. 2021 г.
- CVE-2019-2506131Наблюдать
The random_password_generator (aka RandomPasswordGenerator) gem through 1.0.0 for Ruby uses Kernel#rand to generate passwords, which, due to
ВысокаяCVSS 7,5Эксплойта нетEPSS 2 %random password generator project · random password generator18 мая 2022 г.
- CVE-2020-701030Наблюдать
Elastic Cloud on Kubernetes (ECK) versions prior to 1.1.0 generate passwords using a weak random number generator.
ВысокаяCVSS 7,5Эксплойта нетEPSS 1 %elastic · elastic cloud on kubernetes3 июн. 2020 г.
- CVE-2020-1378430Наблюдать
D-Link DIR-865L Ax 1.20B01 Beta devices have a predictable seed in a Pseudo-Random Number Generator.
ВысокаяCVSS 7,5Эксплойта нетEPSS 1 %dlink · dir-865l firmware3 июн. 2020 г.
- CVE-2017-521430Наблюдать
The Codextrous B2J Contact (aka b2j_contact) extension before 2.1.13 for Joomla! allows prediction of a uniqid value based on knowledge of a
ВысокаяCVSS 7,5Эксплойта нетEPSS 1 %codextrous · b2j contact17 мая 2017 г.
- CVE-2022-3921830Наблюдать
Random number seed fixed during compilation
ВысокаяCVSS 7,5Эксплойта нетEPSS 1 %fastly · js-compute20 сент. 2022 г.
- CVE-2025-2478330Наблюдать
Apache Cocoon: continuations may not be private
ВысокаяCVSS 7,5Эксплойта нетEPSS 1 %apache · cocoon27 янв. 2025 г.
- CVE-2025-2758030Наблюдать
NIH BRICS (aka Biomedical Research Informatics Computing System) through 14.0.0-67 generates predictable tokens (that depend on username, ti
ВысокаяCVSS 7,5Proof of conceptEPSS 1 %nih · brics23 апр. 2025 г.
- CVE-2026-4156430Наблюдать
CryptX versions before 0.088 for Perl do not reseed the Crypt::PK PRNG state after forking
ВысокаяCVSS 7,5Эксплойта нетEPSS 1 %dcit · cryptx23 апр. 2026 г.
- CVE-2026-1170230Наблюдать
Bytes::Random::Secure::Tiny versions through 1.011 for Perl share internal state across forked processes
ВысокаяCVSS 7,5Эксплойта нетEPSS 1 %davido · bytes::random::secure::tiny26 июн. 2026 г.
- CVE-2026-1162530Наблюдать
Bytes::Random::Secure versions through 0.29 for Perl share internal state across forked processes
ВысокаяCVSS 7,5Эксплойта нетEPSS 1 %davido · bytes::random::secure26 июн. 2026 г.