Перейти к содержимому
Noroxi

CWE-331 · 138 записей

Insufficient Entropy

CVE этого класса

138 записей

  • CVE-2008-1447
    56В плане

    The DNS protocol, as implemented in (1) BIND 8 and 9 before 9.5.0-P1, 9.4.2-P1, and 9.3.5-P1; (2) Microsoft DNS in Windows 2000 SP4, XP SP2

    СредняяCVSS 6,8Готовый эксплойтEPSS 95 %

    microsoft · windows 20008 июл. 2008 г.

  • CVE-2018-18326
    46В плане

    DNN (aka DotNetNuke) 9.2 through 9.2.2 incorrectly converts encryption key source values, resulting in lower than expected entropy.

    ВысокаяCVSS 7,5Готовый эксплойтEPSS 54 %

    dnnsoftware · dotnetnuke3 июл. 2019 г.

  • CVE-2018-15812
    44В плане

    DNN (aka DotNetNuke) 9.2 through 9.2.1 incorrectly converts encryption key source values, resulting in lower than expected entropy.

    ВысокаяCVSS 7,5Готовый эксплойтEPSS 47 %

    dnnsoftware · dotnetnuke3 июл. 2019 г.

  • CVE-2008-2108
    40В плане

    The GENERATE_SEED macro in PHP 4.x before 4.4.8 and 5.x before 5.2.5, when running on 64-bit systems, performs a multiplication that generat

    КритическаяCVSS 9,8Эксплойта нетEPSS 4 %

    php · php7 мая 2008 г.

  • CVE-2013-2260
    40В плане

    Cryptocat before 2.0.22: Cryptocat.random() Function Array Key has Entropy Weakness

    КритическаяCVSS 9,8Эксплойта нетEPSS 2 %

    cryptocat project · cryptocat4 нояб. 2019 г.

  • CVE-2022-34294
    40В плане

    totd 1.5.3 uses a fixed UDP source port in upstream queries sent to DNS resolvers.

    КритическаяCVSS 9,8Эксплойта нетEPSS 2 %

    totd project · totd15 авг. 2022 г.

  • CVE-2022-43755
    40В плане

    Rancher: Non-random authentication token

    КритическаяCVSS 9,8Эксплойта нетEPSS 2 %

    suse · rancher7 февр. 2023 г.

  • CVE-2020-12735
    40В плане

    reset.php in DomainMOD 4.13.0 uses insufficient entropy for password reset requests, leading to account takeover.

    КритическаяCVSS 9,8Эксплойта нетEPSS 2 %

    domainmod · domainmod8 мая 2020 г.

  • CVE-2018-1000620
    40В плане

    Eran Hammer cryptiles version 4.1.1 earlier contains a CWE-331: Insufficient Entropy vulnerability in randomDigits() method that can result

    КритическаяCVSS 9,8Эксплойта нетEPSS 2 %

    cryptiles project · cryptiles9 июл. 2018 г.

  • CVE-2021-36294
    39Наблюдать

    Dell VNX2 OE for File versions 8.1.21.266 and earlier, contain an authentication bypass vulnerability.

    КритическаяCVSS 9,8Эксплойта нетEPSS 2 %

    dell · emc unity operating environment25 янв. 2022 г.

  • CVE-2021-22727
    39Наблюдать

    A CWE-331: Insufficient Entropy vulnerability exists in EVlink City (EVC1S22P4 / EVC1S7P4 all versions prior to R8 V3.4.0.1), EVlink Parking

    КритическаяCVSS 9,8Эксплойта нетEPSS 1 %

    schneider-electric · evlink city evc1s22p4 firmware21 июл. 2021 г.

  • CVE-2021-41615
    39Наблюдать

    websda.c in GoAhead WebServer 2.1.8 has insufficient nonce entropy because the nonce calculation relies on the hardcoded onceuponatimeinpara

    КритическаяCVSS 9,8Эксплойта нетEPSS 1 %

    embedthis · goahead8 авг. 2022 г.

  • CVE-2021-33027
    39Наблюдать

    Sylabs Singularity Enterprise through 1.6.2 has Insufficient Entropy in a nonce.

    КритическаяCVSS 9,8Эксплойта нетEPSS 1 %

    sylabs · singularity19 июл. 2021 г.

  • CVE-2021-36320
    39Наблюдать

    Dell Networking X-Series firmware versions prior to 3.0.1.8 contain an authentication bypass vulnerability.

    КритическаяCVSS 9,8Эксплойта нетEPSS 1 %

    dell · x1008p firmware19 нояб. 2021 г.

  • CVE-2020-29508
    39Наблюдать

    Dell BSAFE Crypto-C Micro Edition, versions before 4.1.5, and Dell BSAFE Micro Edition Suite, versions before 4.6, contain an Improper Input

    КритическаяCVSS 9,8Эксплойта нетEPSS 1 %

    dell · bsafe crypto-c-micro-edition11 июл. 2022 г.

  • CVE-2023-49599
    39Наблюдать

    An insufficient entropy vulnerability exists in the salt generation functionality of WWBN AVideo dev master commit 15fed957fb.

    КритическаяCVSS 9,8Эксплойта нетEPSS 1 %

    wwbn · avideo10 янв. 2024 г.

  • CVE-2023-31176
    39Наблюдать

    Insufficient entropy vulnerability could lead to authentication bypass

    КритическаяCVSS 9,8Эксплойта нетEPSS 1 %

    selinc · sel-451 firmware30 нояб. 2023 г.

  • CVE-2024-25730
    39Наблюдать

    Hitron CODA-4582 and CODA-4589 devices have default PSKs that are generated from 5-digit hex values concatenated with a "Hitron" substring,

    КритическаяCVSS 9,8Эксплойта нетEPSS 1 %

    hitrontech · coda-4582u firmware23 февр. 2024 г.

  • CVE-2024-36400
    39Наблюдать

    nano-id is unable to generate the correct character set

    КритическаяCVSS 9,8Эксплойта нетEPSS 1 %

    viz · nano id4 июн. 2024 г.

  • CVE-2023-4344
    39Наблюдать

    Broadcom RAID Controller web interface is vulnerable to insufficient randomness due to improper use of ssl.rnd to setup CIM connection

    КритическаяCVSS 9,8Эксплойта нетEPSS 1 %

    broadcom · raid controller web interface15 авг. 2023 г.

  • CVE-2026-38447
    39Наблюдать

    osTicket 1.18.3 generates API keys using a predictable construction based on MD5 hashing.

    КритическаяCVSS 9,8Эксплойта нетEPSS 1 %

    3 авг. 2026 г.

  • CVE-2026-13639
    39Наблюдать

    An insufficient entropy vulnerability in login logic in Synology DiskStation Manager (DSM) before 7.2.1-69057-12, 7.2.2-72806-9, 7.3.2-86009

    КритическаяCVSS 9,8Эксплойта нетEPSS 1 %

    synology · diskstation manager (dsm)18 сент. 2026 г.

  • CVE-2025-47781
    39Наблюдать

    Rallly Insufficient Password Login Token Entropy Leads to Account Takeover

    КритическаяCVSS 9,8Эксплойта нетEPSS 1 %

    rallly · rallly14 мая 2025 г.

  • CVE-2025-67504
    39Наблюдать

    WBCE CMS has Weak Random Number Generator in Password Generation Function

    КритическаяCVSS 9,8Эксплойта нетEPSS 1 %

    wbce · wbce cms9 дек. 2025 г.

  • CVE-2026-34236
    39Наблюдать

    Auth0 PHP SDK Insufficient Entropy in Cookie Encryption

    КритическаяCVSS 9,8Эксплойта нетEPSS 0 %

    auth0 · auth0-php1 апр. 2026 г.

Все классы уязвимостей