CWE-330 · 329 записей
Use of Insufficiently Random Values
CVE этого класса
329 записей
| Срочность | CVE | Уязвимость | Критичность | KEV | EPSS | Опубликовано |
|---|---|---|---|---|---|---|
48В плане | CVE-2018-17888Готовый эксплойт | NUUO CMS all versions 3.1 and prior, The application uses a session identification mechanism that could allow attackers to obtain the activenuuo · nuuo cms · CWE-330 | Критическая9,8 | — | 29,6 % | 12 окт. 2018 г. |
46В плане | CVE-2017-6026Proof of concept | A Use of Insufficiently Random Values issue was discovered in Schneider Electric Modicon PLCs Modicon M241, firmware versions prior to Versischneider-electric · modicon m251 firmware · CWE-330 | Критическая9,1 | — | 31,8 % | 29 июн. 2017 г. |
42В плане | CVE-2008-2433Эксплойта нет | The web management console in Trend Micro OfficeScan 7.0 through 8.0, Worry-Free Business Security 5.0, and Client/Server/Messaging Suite 3.trendmicro · client server messaging suite · CWE-330 | Критическая9,8 | — | 10,9 % | 27 авг. 2008 г. |
42В плане | CVE-2017-16924Эксплойта нет | Remote Information Disclosure and Escalation of Privileges in ManageEngine Desktop Central MSP 10.0.137 allows attackers to download unencryzohocorp · manageengine desktop central · CWE-330 | Критическая9,8 | — | 8,6 % | 19 февр. 2018 г. |
41В плане | CVE-2019-0007Эксплойта нет | Junos OS: vMX series: Predictable IP ID sequence numbers vulnerabilityjuniper · junos · CWE-330 | Критическая10,0 | — | 1,7 % | 15 янв. 2019 г. |
40В плане | CVE-2008-0087Эксплойта нет | The DNS client in Microsoft Windows 2000 SP4, XP SP2, Server 2003 SP1 and SP2, and Vista uses predictable DNS transaction IDs, which allows microsoft · windows 2000 · CWE-330 | Высокая7,5 | — | 32,4 % | 8 апр. 2008 г. |
40В плане | CVE-2022-36536Готовый эксплойт | An issue in the component post_applogin.php of Super Flexible Software GmbH & Co.syncovery · syncovery · CWE-330 | Критическая9,8 | — | 4,7 % | 15 сент. 2022 г. |
40В плане | CVE-2019-7667Эксплойта нет | Prima Systems FlexAir, Versions 2.3.38 and prior.primasystems · flexair · CWE-330 | Критическая9,8 | — | 4,5 % | 1 июл. 2019 г. |
40В плане | CVE-2019-9898Эксплойта нет | Potential recycling of random numbers used in cryptography exists within PuTTY before 0.71.putty · putty · CWE-330 | Критическая9,8 | — | 3,9 % | 21 мар. 2019 г. |
40В плане | CVE-2008-3612Эксплойта нет | The Networking subsystem in Apple iPod touch 2.0 through 2.0.2, and iPhone 2.0 through 2.0.2, uses predictable TCP initial sequence numbers,apple · iphone os · CWE-330 | Критическая9,8 | — | 3,5 % | 10 сент. 2008 г. |
40В плане | CVE-2021-27200Эксплойта нет | In WoWonder 3.0.4, remote attackers can take over any account due to the weak cryptographic algorithm in recover.php.wowonder · wowonder · CWE-330 | Критическая9,8 | — | 3,4 % | 11 июн. 2021 г. |
40В плане | CVE-2019-0729Эксплойта нет | An Elevation of Privilege vulnerability exists in the way Azure IoT Java SDK generates symmetric keys for encryption, allowing an attacker tmicrosoft · java software development kit · CWE-330 | Критическая9,8 | — | 3,1 % | 5 мар. 2019 г. |
40В плане | CVE-2023-29332Эксплойта нет | Microsoft Azure Kubernetes Service Elevation of Privilege Vulnerabilitymicrosoft · azure kubernetes service · CWE-330 | Критическая9,8 | — | 2,7 % | 12 сент. 2023 г. |
40В плане | CVE-2019-15130Эксплойта нет | The Recruitment module in Humanica Humatrix 7 1.0.0.203 and 1.0.0.681 allows an unauthenticated attacker to upload any file type to a candidhumanica · humatrix 7 · CWE-330 | Критическая9,8 | — | 2,4 % | 18 авг. 2019 г. |
40В плане | CVE-2019-9863Эксплойта нет | Due to the use of an insecure algorithm for rolling codes in the ABUS Secvest wireless alarm system FUAA50000 3.01.01 and its remote controlabus · secvest wireless alarm system fuaa50000 firmware · CWE-330 | Критическая9,8 | — | 2,1 % | 27 мар. 2019 г. |
40В плане | CVE-2016-5100Эксплойта нет | Froxlor before 0.9.35 uses the PHP rand function for random number generation, which makes it easier for remote attackers to guess the passwfroxlor · froxlor · CWE-330 | Критическая9,8 | — | 1,9 % | 13 февр. 2017 г. |
40В плане | CVE-2019-16674Эксплойта нет | An issue was discovered on Weidmueller IE-SW-VL05M 3.6.6 Build 16102415, IE-SW-VL08MT 3.5.2 Build 16102415, and IE-SW-PL10M 3.3.16 Build 161weidmueller · ie-sw-pl09m-5gc-4gt firmware · CWE-330 | Критическая9,8 | — | 1,9 % | 6 дек. 2019 г. |
40В плане | CVE-2020-27743Эксплойта нет | libtac in pam_tacplus through 1.5.1 lacks a check for a failure of RAND_bytes()/RAND_pseudo_bytes().pam tacplus project · pam tacplus · CWE-330 | Критическая9,8 | — | 1,7 % | 26 окт. 2020 г. |
40В плане | CVE-2014-6311Эксплойта нет | generate_doygen.pl in ace before 6.2.7+dfsg-2 creates predictable file names in the /tmp directory which allows attackers to gain elevated pvanderbilt · adaptive communication environment · CWE-330 | Критическая9,8 | — | 1,7 % | 22 нояб. 2019 г. |
39Наблюдать | CVE-2020-35926Эксплойта нет | An issue was discovered in the nanorand crate before 0.5.1 for Rust.nanorand project · nanorand · CWE-330 | Критическая9,8 | — | 1,5 % | 31 дек. 2020 г. |
39Наблюдать | CVE-2020-9502Эксплойта нет | Some Dahua products with Build time before December 2019 have Session ID predictable vulnerabilities.dahuasecurity · sd6al firmware · CWE-330 | Критическая9,8 | — | 1,5 % | 13 мая 2020 г. |
39Наблюдать | CVE-2021-36166Эксплойта нет | An improper authentication vulnerability in FortiMail before 7.0.1 may allow a remote attacker to efficiently guess one administrative accoufortinet · fortimail · CWE-330 | Критическая9,8 | — | 1,5 % | 1 мар. 2022 г. |
39Наблюдать | CVE-2018-18531Эксплойта нет | text/impl/DefaultTextCreator.java, text/impl/ChineseTextProducer.java, and text/impl/FiveLetterFirstNameTextCreator.java in kaptcha 2.3.2 uskaptcha project · kaptcha · CWE-330 | Критическая9,8 | — | 1,5 % | 19 окт. 2018 г. |
39Наблюдать | CVE-2022-25752Эксплойта нет | A vulnerability has been identified in SCALANCE X302-7 EEC (230V), SCALANCE X302-7 EEC (230V, coated), SCALANCE X302-7 EEC (24V), SCALANCE Xsiemens · scalance x302-7eec firmware · CWE-330 | Критическая9,8 | — | 1,5 % | 12 апр. 2022 г. |
39Наблюдать | CVE-2020-7548Эксплойта нет | A CWE-330 - Use of Insufficiently Random Values vulnerability exists in Smartlink, PowerTag, and Wiser Series Gateways (see security notificschneider-electric · acti9 smartlink si d firmware · CWE-330 | Критическая9,8 | — | 1,4 % | 1 дек. 2020 г. |
- CVE-2018-1788848В плане
NUUO CMS all versions 3.1 and prior, The application uses a session identification mechanism that could allow attackers to obtain the active
КритическаяCVSS 9,8Готовый эксплойтEPSS 30 %nuuo · nuuo cms12 окт. 2018 г.
- CVE-2017-602646В плане
A Use of Insufficiently Random Values issue was discovered in Schneider Electric Modicon PLCs Modicon M241, firmware versions prior to Versi
КритическаяCVSS 9,1Proof of conceptEPSS 32 %schneider-electric · modicon m251 firmware29 июн. 2017 г.
- CVE-2008-243342В плане
The web management console in Trend Micro OfficeScan 7.0 through 8.0, Worry-Free Business Security 5.0, and Client/Server/Messaging Suite 3.
КритическаяCVSS 9,8Эксплойта нетEPSS 11 %trendmicro · client server messaging suite27 авг. 2008 г.
- CVE-2017-1692442В плане
Remote Information Disclosure and Escalation of Privileges in ManageEngine Desktop Central MSP 10.0.137 allows attackers to download unencry
КритическаяCVSS 9,8Эксплойта нетEPSS 9 %zohocorp · manageengine desktop central19 февр. 2018 г.
- CVE-2019-000741В плане
Junos OS: vMX series: Predictable IP ID sequence numbers vulnerability
КритическаяCVSS 10,0Эксплойта нетEPSS 2 %juniper · junos15 янв. 2019 г.
- CVE-2008-008740В плане
The DNS client in Microsoft Windows 2000 SP4, XP SP2, Server 2003 SP1 and SP2, and Vista uses predictable DNS transaction IDs, which allows
ВысокаяCVSS 7,5Эксплойта нетEPSS 32 %microsoft · windows 20008 апр. 2008 г.
- CVE-2022-3653640В плане
An issue in the component post_applogin.php of Super Flexible Software GmbH & Co.
КритическаяCVSS 9,8Готовый эксплойтEPSS 5 %syncovery · syncovery15 сент. 2022 г.
- CVE-2019-766740В плане
Prima Systems FlexAir, Versions 2.3.38 and prior.
КритическаяCVSS 9,8Эксплойта нетEPSS 4 %primasystems · flexair1 июл. 2019 г.
- CVE-2019-989840В плане
Potential recycling of random numbers used in cryptography exists within PuTTY before 0.71.
КритическаяCVSS 9,8Эксплойта нетEPSS 4 %putty · putty21 мар. 2019 г.
- CVE-2008-361240В плане
The Networking subsystem in Apple iPod touch 2.0 through 2.0.2, and iPhone 2.0 through 2.0.2, uses predictable TCP initial sequence numbers,
КритическаяCVSS 9,8Эксплойта нетEPSS 4 %apple · iphone os10 сент. 2008 г.
- CVE-2021-2720040В плане
In WoWonder 3.0.4, remote attackers can take over any account due to the weak cryptographic algorithm in recover.php.
КритическаяCVSS 9,8Эксплойта нетEPSS 3 %wowonder · wowonder11 июн. 2021 г.
- CVE-2019-072940В плане
An Elevation of Privilege vulnerability exists in the way Azure IoT Java SDK generates symmetric keys for encryption, allowing an attacker t
КритическаяCVSS 9,8Эксплойта нетEPSS 3 %microsoft · java software development kit5 мар. 2019 г.
- CVE-2023-2933240В плане
Microsoft Azure Kubernetes Service Elevation of Privilege Vulnerability
КритическаяCVSS 9,8Эксплойта нетEPSS 3 %microsoft · azure kubernetes service12 сент. 2023 г.
- CVE-2019-1513040В плане
The Recruitment module in Humanica Humatrix 7 1.0.0.203 and 1.0.0.681 allows an unauthenticated attacker to upload any file type to a candid
КритическаяCVSS 9,8Эксплойта нетEPSS 2 %humanica · humatrix 718 авг. 2019 г.
- CVE-2019-986340В плане
Due to the use of an insecure algorithm for rolling codes in the ABUS Secvest wireless alarm system FUAA50000 3.01.01 and its remote control
КритическаяCVSS 9,8Эксплойта нетEPSS 2 %abus · secvest wireless alarm system fuaa50000 firmware27 мар. 2019 г.
- CVE-2016-510040В плане
Froxlor before 0.9.35 uses the PHP rand function for random number generation, which makes it easier for remote attackers to guess the passw
КритическаяCVSS 9,8Эксплойта нетEPSS 2 %froxlor · froxlor13 февр. 2017 г.
- CVE-2019-1667440В плане
An issue was discovered on Weidmueller IE-SW-VL05M 3.6.6 Build 16102415, IE-SW-VL08MT 3.5.2 Build 16102415, and IE-SW-PL10M 3.3.16 Build 161
КритическаяCVSS 9,8Эксплойта нетEPSS 2 %weidmueller · ie-sw-pl09m-5gc-4gt firmware6 дек. 2019 г.
- CVE-2020-2774340В плане
libtac in pam_tacplus through 1.5.1 lacks a check for a failure of RAND_bytes()/RAND_pseudo_bytes().
КритическаяCVSS 9,8Эксплойта нетEPSS 2 %pam tacplus project · pam tacplus26 окт. 2020 г.
- CVE-2014-631140В плане
generate_doygen.pl in ace before 6.2.7+dfsg-2 creates predictable file names in the /tmp directory which allows attackers to gain elevated p
КритическаяCVSS 9,8Эксплойта нетEPSS 2 %vanderbilt · adaptive communication environment22 нояб. 2019 г.
- CVE-2020-3592639Наблюдать
An issue was discovered in the nanorand crate before 0.5.1 for Rust.
КритическаяCVSS 9,8Эксплойта нетEPSS 2 %nanorand project · nanorand31 дек. 2020 г.
- CVE-2020-950239Наблюдать
Some Dahua products with Build time before December 2019 have Session ID predictable vulnerabilities.
КритическаяCVSS 9,8Эксплойта нетEPSS 2 %dahuasecurity · sd6al firmware13 мая 2020 г.
- CVE-2021-3616639Наблюдать
An improper authentication vulnerability in FortiMail before 7.0.1 may allow a remote attacker to efficiently guess one administrative accou
КритическаяCVSS 9,8Эксплойта нетEPSS 1 %fortinet · fortimail1 мар. 2022 г.
- CVE-2018-1853139Наблюдать
text/impl/DefaultTextCreator.java, text/impl/ChineseTextProducer.java, and text/impl/FiveLetterFirstNameTextCreator.java in kaptcha 2.3.2 us
КритическаяCVSS 9,8Эксплойта нетEPSS 1 %kaptcha project · kaptcha19 окт. 2018 г.
- CVE-2022-2575239Наблюдать
A vulnerability has been identified in SCALANCE X302-7 EEC (230V), SCALANCE X302-7 EEC (230V, coated), SCALANCE X302-7 EEC (24V), SCALANCE X
КритическаяCVSS 9,8Эксплойта нетEPSS 1 %siemens · scalance x302-7eec firmware12 апр. 2022 г.
- CVE-2020-754839Наблюдать
A CWE-330 - Use of Insufficiently Random Values vulnerability exists in Smartlink, PowerTag, and Wiser Series Gateways (see security notific
КритическаяCVSS 9,8Эксплойта нетEPSS 1 %schneider-electric · acti9 smartlink si d firmware1 дек. 2020 г.