CWE-361 · 7 записей
7PK - Time and State
CVE этого класса
7 записей
| Срочность | CVE | Уязвимость | Критичность | KEV | EPSS | Опубликовано |
|---|---|---|---|---|---|---|
67На этой неделе | CVE-2016-7547Готовый эксплойт | A command execution flaw on the Trend Micro Threat Discovery Appliance 2.6.1062r1 exists with the timezone parameter in the admin_sys_time.ctrendmicro · threat discovery appliance · CWE-361 | Критическая9,8 | — | 92,7 % | 12 апр. 2017 г. |
40В плане | CVE-2016-7036Эксплойта нет | python-jose before 1.3.2 allows attackers to have unspecified impact by leveraging failure to use a constant time comparison for HMAC keys.python-jose project · python-jose · CWE-361 | Критическая9,8 | — | 2,1 % | 23 янв. 2017 г. |
36Наблюдать | CVE-2016-1643Эксплойта нет | The ImageInputType::ensurePrimaryContent function in WebKit/Source/core/html/forms/ImageInputType.cpp in Blink, as used in Google Chrome befgoogle · chrome · CWE-361 | Высокая8,8 | — | 2,7 % | 13 мар. 2016 г. |
33Наблюдать | CVE-2015-5300Эксплойта нет | The panic_gate check in NTP before 4.2.8p5 is only re-enabled after the first change to the system clock that was greater than 128 millisecontp · ntp · CWE-361 | Высокая7,5 | — | 9,1 % | 21 июл. 2017 г. |
30Наблюдать | CVE-2016-7037Эксплойта нет | The verify function in Encryption/Symmetric.php in Malcolm Fell jwt before 1.0.3 does not use a timing-safe function for hash comparison, whemarref · jwt · CWE-361 | Высокая7,5 | — | 0,7 % | 23 янв. 2017 г. |
24Наблюдать | CVE-2016-1000345Эксплойта нет | In the Bouncy Castle JCE Provider version 1.55 and earlier the DHIES/ECIES CBC mode vulnerable to padding oracle attack.bouncycastle · bc-java · CWE-361 | Средняя5,9 | — | 2,6 % | 4 июн. 2018 г. |
24Наблюдать | CVE-2016-1000341Эксплойта нет | In the Bouncy Castle JCE Provider version 1.55 and earlier DSA signature generation is vulnerable to timing attack.bouncycastle · bc-java · CWE-361 | Средняя5,9 | — | 2,6 % | 4 июн. 2018 г. |
- CVE-2016-754767На этой неделе
A command execution flaw on the Trend Micro Threat Discovery Appliance 2.6.1062r1 exists with the timezone parameter in the admin_sys_time.c
КритическаяCVSS 9,8Готовый эксплойтEPSS 93 %trendmicro · threat discovery appliance12 апр. 2017 г.
- CVE-2016-703640В плане
python-jose before 1.3.2 allows attackers to have unspecified impact by leveraging failure to use a constant time comparison for HMAC keys.
КритическаяCVSS 9,8Эксплойта нетEPSS 2 %python-jose project · python-jose23 янв. 2017 г.
- CVE-2016-164336Наблюдать
The ImageInputType::ensurePrimaryContent function in WebKit/Source/core/html/forms/ImageInputType.cpp in Blink, as used in Google Chrome bef
ВысокаяCVSS 8,8Эксплойта нетEPSS 3 %google · chrome13 мар. 2016 г.
- CVE-2015-530033Наблюдать
The panic_gate check in NTP before 4.2.8p5 is only re-enabled after the first change to the system clock that was greater than 128 milliseco
ВысокаяCVSS 7,5Эксплойта нетEPSS 9 %ntp · ntp21 июл. 2017 г.
- CVE-2016-703730Наблюдать
The verify function in Encryption/Symmetric.php in Malcolm Fell jwt before 1.0.3 does not use a timing-safe function for hash comparison, wh
ВысокаяCVSS 7,5Эксплойта нетEPSS 1 %emarref · jwt23 янв. 2017 г.
- CVE-2016-100034524Наблюдать
In the Bouncy Castle JCE Provider version 1.55 and earlier the DHIES/ECIES CBC mode vulnerable to padding oracle attack.
СредняяCVSS 5,9Эксплойта нетEPSS 3 %bouncycastle · bc-java4 июн. 2018 г.
- CVE-2016-100034124Наблюдать
In the Bouncy Castle JCE Provider version 1.55 and earlier DSA signature generation is vulnerable to timing attack.
СредняяCVSS 5,9Эксплойта нетEPSS 3 %bouncycastle · bc-java4 июн. 2018 г.