CWE-330 · 328 kayıt
Use of Insufficiently Random Values
Bu sınıftaki CVE’ler
329 kayıt
| Aksiyon | CVE | Zafiyet | Ciddiyet | KEV | EPSS | Yayın |
|---|---|---|---|---|---|---|
48Planlayın | CVE-2018-17888Silahlaştırılmış | NUUO CMS all versions 3.1 and prior, The application uses a session identification mechanism that could allow attackers to obtain the activenuuo · nuuo cms · CWE-330 | Kritik9,8 | — | %29,6 | 12 Eki 2018 |
46Planlayın | CVE-2017-6026Kavram kanıtı | A Use of Insufficiently Random Values issue was discovered in Schneider Electric Modicon PLCs Modicon M241, firmware versions prior to Versischneider-electric · modicon m251 firmware · CWE-330 | Kritik9,1 | — | %31,8 | 29 Haz 2017 |
42Planlayın | CVE-2008-2433İstismar yok | The web management console in Trend Micro OfficeScan 7.0 through 8.0, Worry-Free Business Security 5.0, and Client/Server/Messaging Suite 3.trendmicro · client server messaging suite · CWE-330 | Kritik9,8 | — | %10,9 | 27 Ağu 2008 |
42Planlayın | CVE-2017-16924İstismar yok | Remote Information Disclosure and Escalation of Privileges in ManageEngine Desktop Central MSP 10.0.137 allows attackers to download unencryzohocorp · manageengine desktop central · CWE-330 | Kritik9,8 | — | %8,6 | 19 Şub 2018 |
41Planlayın | CVE-2019-0007İstismar yok | Junos OS: vMX series: Predictable IP ID sequence numbers vulnerabilityjuniper · junos · CWE-330 | Kritik10,0 | — | %1,7 | 15 Oca 2019 |
40Planlayın | CVE-2008-0087İstismar yok | The DNS client in Microsoft Windows 2000 SP4, XP SP2, Server 2003 SP1 and SP2, and Vista uses predictable DNS transaction IDs, which allows microsoft · windows 2000 · CWE-330 | Yüksek7,5 | — | %32,4 | 8 Nis 2008 |
40Planlayın | CVE-2022-36536Silahlaştırılmış | An issue in the component post_applogin.php of Super Flexible Software GmbH & Co.syncovery · syncovery · CWE-330 | Kritik9,8 | — | %4,7 | 15 Eyl 2022 |
40Planlayın | CVE-2019-7667İstismar yok | Prima Systems FlexAir, Versions 2.3.38 and prior.primasystems · flexair · CWE-330 | Kritik9,8 | — | %4,5 | 1 Tem 2019 |
40Planlayın | CVE-2019-9898İstismar yok | Potential recycling of random numbers used in cryptography exists within PuTTY before 0.71.putty · putty · CWE-330 | Kritik9,8 | — | %3,9 | 21 Mar 2019 |
40Planlayın | CVE-2008-3612İstismar yok | The Networking subsystem in Apple iPod touch 2.0 through 2.0.2, and iPhone 2.0 through 2.0.2, uses predictable TCP initial sequence numbers,apple · iphone os · CWE-330 | Kritik9,8 | — | %3,5 | 10 Eyl 2008 |
40Planlayın | CVE-2021-27200İstismar yok | In WoWonder 3.0.4, remote attackers can take over any account due to the weak cryptographic algorithm in recover.php.wowonder · wowonder · CWE-330 | Kritik9,8 | — | %3,4 | 11 Haz 2021 |
40Planlayın | CVE-2019-0729İstismar yok | An Elevation of Privilege vulnerability exists in the way Azure IoT Java SDK generates symmetric keys for encryption, allowing an attacker tmicrosoft · java software development kit · CWE-330 | Kritik9,8 | — | %3,1 | 5 Mar 2019 |
40Planlayın | CVE-2023-29332İstismar yok | Microsoft Azure Kubernetes Service Elevation of Privilege Vulnerabilitymicrosoft · azure kubernetes service · CWE-330 | Kritik9,8 | — | %2,7 | 12 Eyl 2023 |
40Planlayın | CVE-2019-15130İstismar yok | The Recruitment module in Humanica Humatrix 7 1.0.0.203 and 1.0.0.681 allows an unauthenticated attacker to upload any file type to a candidhumanica · humatrix 7 · CWE-330 | Kritik9,8 | — | %2,4 | 18 Ağu 2019 |
40Planlayın | CVE-2019-9863İstismar yok | Due to the use of an insecure algorithm for rolling codes in the ABUS Secvest wireless alarm system FUAA50000 3.01.01 and its remote controlabus · secvest wireless alarm system fuaa50000 firmware · CWE-330 | Kritik9,8 | — | %2,1 | 27 Mar 2019 |
40Planlayın | CVE-2016-5100İstismar yok | Froxlor before 0.9.35 uses the PHP rand function for random number generation, which makes it easier for remote attackers to guess the passwfroxlor · froxlor · CWE-330 | Kritik9,8 | — | %1,9 | 13 Şub 2017 |
40Planlayın | CVE-2019-16674İstismar yok | An issue was discovered on Weidmueller IE-SW-VL05M 3.6.6 Build 16102415, IE-SW-VL08MT 3.5.2 Build 16102415, and IE-SW-PL10M 3.3.16 Build 161weidmueller · ie-sw-pl09m-5gc-4gt firmware · CWE-330 | Kritik9,8 | — | %1,9 | 6 Ara 2019 |
40Planlayın | CVE-2020-27743İstismar yok | libtac in pam_tacplus through 1.5.1 lacks a check for a failure of RAND_bytes()/RAND_pseudo_bytes().pam tacplus project · pam tacplus · CWE-330 | Kritik9,8 | — | %1,7 | 26 Eki 2020 |
40Planlayın | CVE-2014-6311İstismar yok | generate_doygen.pl in ace before 6.2.7+dfsg-2 creates predictable file names in the /tmp directory which allows attackers to gain elevated pvanderbilt · adaptive communication environment · CWE-330 | Kritik9,8 | — | %1,7 | 22 Kas 2019 |
39İzleyin | CVE-2020-35926İstismar yok | An issue was discovered in the nanorand crate before 0.5.1 for Rust.nanorand project · nanorand · CWE-330 | Kritik9,8 | — | %1,5 | 31 Ara 2020 |
39İzleyin | CVE-2020-9502İstismar yok | Some Dahua products with Build time before December 2019 have Session ID predictable vulnerabilities.dahuasecurity · sd6al firmware · CWE-330 | Kritik9,8 | — | %1,5 | 13 May 2020 |
39İzleyin | CVE-2021-36166İstismar yok | An improper authentication vulnerability in FortiMail before 7.0.1 may allow a remote attacker to efficiently guess one administrative accoufortinet · fortimail · CWE-330 | Kritik9,8 | — | %1,5 | 1 Mar 2022 |
39İzleyin | CVE-2018-18531İstismar yok | text/impl/DefaultTextCreator.java, text/impl/ChineseTextProducer.java, and text/impl/FiveLetterFirstNameTextCreator.java in kaptcha 2.3.2 uskaptcha project · kaptcha · CWE-330 | Kritik9,8 | — | %1,5 | 19 Eki 2018 |
39İzleyin | CVE-2022-25752İstismar yok | A vulnerability has been identified in SCALANCE X302-7 EEC (230V), SCALANCE X302-7 EEC (230V, coated), SCALANCE X302-7 EEC (24V), SCALANCE Xsiemens · scalance x302-7eec firmware · CWE-330 | Kritik9,8 | — | %1,5 | 12 Nis 2022 |
39İzleyin | CVE-2020-7548İstismar yok | A CWE-330 - Use of Insufficiently Random Values vulnerability exists in Smartlink, PowerTag, and Wiser Series Gateways (see security notificschneider-electric · acti9 smartlink si d firmware · CWE-330 | Kritik9,8 | — | %1,4 | 1 Ara 2020 |
- CVE-2018-1788848Planlayın
NUUO CMS all versions 3.1 and prior, The application uses a session identification mechanism that could allow attackers to obtain the active
KritikCVSS 9,8SilahlaştırılmışEPSS %30nuuo · nuuo cms12 Eki 2018
- CVE-2017-602646Planlayın
A Use of Insufficiently Random Values issue was discovered in Schneider Electric Modicon PLCs Modicon M241, firmware versions prior to Versi
KritikCVSS 9,1Kavram kanıtıEPSS %32schneider-electric · modicon m251 firmware29 Haz 2017
- CVE-2008-243342Planlayın
The web management console in Trend Micro OfficeScan 7.0 through 8.0, Worry-Free Business Security 5.0, and Client/Server/Messaging Suite 3.
KritikCVSS 9,8İstismar yokEPSS %11trendmicro · client server messaging suite27 Ağu 2008
- CVE-2017-1692442Planlayın
Remote Information Disclosure and Escalation of Privileges in ManageEngine Desktop Central MSP 10.0.137 allows attackers to download unencry
KritikCVSS 9,8İstismar yokEPSS %9zohocorp · manageengine desktop central19 Şub 2018
- CVE-2019-000741Planlayın
Junos OS: vMX series: Predictable IP ID sequence numbers vulnerability
KritikCVSS 10,0İstismar yokEPSS %2juniper · junos15 Oca 2019
- CVE-2008-008740Planlayın
The DNS client in Microsoft Windows 2000 SP4, XP SP2, Server 2003 SP1 and SP2, and Vista uses predictable DNS transaction IDs, which allows
YüksekCVSS 7,5İstismar yokEPSS %32microsoft · windows 20008 Nis 2008
- CVE-2022-3653640Planlayın
An issue in the component post_applogin.php of Super Flexible Software GmbH & Co.
KritikCVSS 9,8SilahlaştırılmışEPSS %5syncovery · syncovery15 Eyl 2022
- CVE-2019-766740Planlayın
Prima Systems FlexAir, Versions 2.3.38 and prior.
KritikCVSS 9,8İstismar yokEPSS %4primasystems · flexair1 Tem 2019
- CVE-2019-989840Planlayın
Potential recycling of random numbers used in cryptography exists within PuTTY before 0.71.
KritikCVSS 9,8İstismar yokEPSS %4putty · putty21 Mar 2019
- CVE-2008-361240Planlayın
The Networking subsystem in Apple iPod touch 2.0 through 2.0.2, and iPhone 2.0 through 2.0.2, uses predictable TCP initial sequence numbers,
KritikCVSS 9,8İstismar yokEPSS %4apple · iphone os10 Eyl 2008
- CVE-2021-2720040Planlayın
In WoWonder 3.0.4, remote attackers can take over any account due to the weak cryptographic algorithm in recover.php.
KritikCVSS 9,8İstismar yokEPSS %3wowonder · wowonder11 Haz 2021
- CVE-2019-072940Planlayın
An Elevation of Privilege vulnerability exists in the way Azure IoT Java SDK generates symmetric keys for encryption, allowing an attacker t
KritikCVSS 9,8İstismar yokEPSS %3microsoft · java software development kit5 Mar 2019
- CVE-2023-2933240Planlayın
Microsoft Azure Kubernetes Service Elevation of Privilege Vulnerability
KritikCVSS 9,8İstismar yokEPSS %3microsoft · azure kubernetes service12 Eyl 2023
- CVE-2019-1513040Planlayın
The Recruitment module in Humanica Humatrix 7 1.0.0.203 and 1.0.0.681 allows an unauthenticated attacker to upload any file type to a candid
KritikCVSS 9,8İstismar yokEPSS %2humanica · humatrix 718 Ağu 2019
- CVE-2019-986340Planlayın
Due to the use of an insecure algorithm for rolling codes in the ABUS Secvest wireless alarm system FUAA50000 3.01.01 and its remote control
KritikCVSS 9,8İstismar yokEPSS %2abus · secvest wireless alarm system fuaa50000 firmware27 Mar 2019
- CVE-2016-510040Planlayın
Froxlor before 0.9.35 uses the PHP rand function for random number generation, which makes it easier for remote attackers to guess the passw
KritikCVSS 9,8İstismar yokEPSS %2froxlor · froxlor13 Şub 2017
- CVE-2019-1667440Planlayın
An issue was discovered on Weidmueller IE-SW-VL05M 3.6.6 Build 16102415, IE-SW-VL08MT 3.5.2 Build 16102415, and IE-SW-PL10M 3.3.16 Build 161
KritikCVSS 9,8İstismar yokEPSS %2weidmueller · ie-sw-pl09m-5gc-4gt firmware6 Ara 2019
- CVE-2020-2774340Planlayın
libtac in pam_tacplus through 1.5.1 lacks a check for a failure of RAND_bytes()/RAND_pseudo_bytes().
KritikCVSS 9,8İstismar yokEPSS %2pam tacplus project · pam tacplus26 Eki 2020
- CVE-2014-631140Planlayın
generate_doygen.pl in ace before 6.2.7+dfsg-2 creates predictable file names in the /tmp directory which allows attackers to gain elevated p
KritikCVSS 9,8İstismar yokEPSS %2vanderbilt · adaptive communication environment22 Kas 2019
- CVE-2020-3592639İzleyin
An issue was discovered in the nanorand crate before 0.5.1 for Rust.
KritikCVSS 9,8İstismar yokEPSS %2nanorand project · nanorand31 Ara 2020
- CVE-2020-950239İzleyin
Some Dahua products with Build time before December 2019 have Session ID predictable vulnerabilities.
KritikCVSS 9,8İstismar yokEPSS %2dahuasecurity · sd6al firmware13 May 2020
- CVE-2021-3616639İzleyin
An improper authentication vulnerability in FortiMail before 7.0.1 may allow a remote attacker to efficiently guess one administrative accou
KritikCVSS 9,8İstismar yokEPSS %1fortinet · fortimail1 Mar 2022
- CVE-2018-1853139İzleyin
text/impl/DefaultTextCreator.java, text/impl/ChineseTextProducer.java, and text/impl/FiveLetterFirstNameTextCreator.java in kaptcha 2.3.2 us
KritikCVSS 9,8İstismar yokEPSS %1kaptcha project · kaptcha19 Eki 2018
- CVE-2022-2575239İzleyin
A vulnerability has been identified in SCALANCE X302-7 EEC (230V), SCALANCE X302-7 EEC (230V, coated), SCALANCE X302-7 EEC (24V), SCALANCE X
KritikCVSS 9,8İstismar yokEPSS %1siemens · scalance x302-7eec firmware12 Nis 2022
- CVE-2020-754839İzleyin
A CWE-330 - Use of Insufficiently Random Values vulnerability exists in Smartlink, PowerTag, and Wiser Series Gateways (see security notific
KritikCVSS 9,8İstismar yokEPSS %1schneider-electric · acti9 smartlink si d firmware1 Ara 2020