İçeriğe atla
Noroxi

CWE-330 · 328 kayıt

Use of Insufficiently Random Values

Bu sınıftaki CVE’ler

329 kayıt

  • CVE-2018-17888
    48Planlayın

    NUUO CMS all versions 3.1 and prior, The application uses a session identification mechanism that could allow attackers to obtain the active

    KritikCVSS 9,8SilahlaştırılmışEPSS %30

    nuuo · nuuo cms12 Eki 2018

  • CVE-2017-6026
    46Planlayın

    A Use of Insufficiently Random Values issue was discovered in Schneider Electric Modicon PLCs Modicon M241, firmware versions prior to Versi

    KritikCVSS 9,1Kavram kanıtıEPSS %32

    schneider-electric · modicon m251 firmware29 Haz 2017

  • CVE-2008-2433
    42Planlayın

    The web management console in Trend Micro OfficeScan 7.0 through 8.0, Worry-Free Business Security 5.0, and Client/Server/Messaging Suite 3.

    KritikCVSS 9,8İstismar yokEPSS %11

    trendmicro · client server messaging suite27 Ağu 2008

  • CVE-2017-16924
    42Planlayın

    Remote Information Disclosure and Escalation of Privileges in ManageEngine Desktop Central MSP 10.0.137 allows attackers to download unencry

    KritikCVSS 9,8İstismar yokEPSS %9

    zohocorp · manageengine desktop central19 Şub 2018

  • CVE-2019-0007
    41Planlayın

    Junos OS: vMX series: Predictable IP ID sequence numbers vulnerability

    KritikCVSS 10,0İstismar yokEPSS %2

    juniper · junos15 Oca 2019

  • CVE-2008-0087
    40Planlayın

    The DNS client in Microsoft Windows 2000 SP4, XP SP2, Server 2003 SP1 and SP2, and Vista uses predictable DNS transaction IDs, which allows

    YüksekCVSS 7,5İstismar yokEPSS %32

    microsoft · windows 20008 Nis 2008

  • CVE-2022-36536
    40Planlayın

    An issue in the component post_applogin.php of Super Flexible Software GmbH & Co.

    KritikCVSS 9,8SilahlaştırılmışEPSS %5

    syncovery · syncovery15 Eyl 2022

  • CVE-2019-7667
    40Planlayın

    Prima Systems FlexAir, Versions 2.3.38 and prior.

    KritikCVSS 9,8İstismar yokEPSS %4

    primasystems · flexair1 Tem 2019

  • CVE-2019-9898
    40Planlayın

    Potential recycling of random numbers used in cryptography exists within PuTTY before 0.71.

    KritikCVSS 9,8İstismar yokEPSS %4

    putty · putty21 Mar 2019

  • CVE-2008-3612
    40Planlayın

    The Networking subsystem in Apple iPod touch 2.0 through 2.0.2, and iPhone 2.0 through 2.0.2, uses predictable TCP initial sequence numbers,

    KritikCVSS 9,8İstismar yokEPSS %4

    apple · iphone os10 Eyl 2008

  • CVE-2021-27200
    40Planlayın

    In WoWonder 3.0.4, remote attackers can take over any account due to the weak cryptographic algorithm in recover.php.

    KritikCVSS 9,8İstismar yokEPSS %3

    wowonder · wowonder11 Haz 2021

  • CVE-2019-0729
    40Planlayın

    An Elevation of Privilege vulnerability exists in the way Azure IoT Java SDK generates symmetric keys for encryption, allowing an attacker t

    KritikCVSS 9,8İstismar yokEPSS %3

    microsoft · java software development kit5 Mar 2019

  • CVE-2023-29332
    40Planlayın

    Microsoft Azure Kubernetes Service Elevation of Privilege Vulnerability

    KritikCVSS 9,8İstismar yokEPSS %3

    microsoft · azure kubernetes service12 Eyl 2023

  • CVE-2019-15130
    40Planlayın

    The Recruitment module in Humanica Humatrix 7 1.0.0.203 and 1.0.0.681 allows an unauthenticated attacker to upload any file type to a candid

    KritikCVSS 9,8İstismar yokEPSS %2

    humanica · humatrix 718 Ağu 2019

  • CVE-2019-9863
    40Planlayın

    Due to the use of an insecure algorithm for rolling codes in the ABUS Secvest wireless alarm system FUAA50000 3.01.01 and its remote control

    KritikCVSS 9,8İstismar yokEPSS %2

    abus · secvest wireless alarm system fuaa50000 firmware27 Mar 2019

  • CVE-2016-5100
    40Planlayın

    Froxlor before 0.9.35 uses the PHP rand function for random number generation, which makes it easier for remote attackers to guess the passw

    KritikCVSS 9,8İstismar yokEPSS %2

    froxlor · froxlor13 Şub 2017

  • CVE-2019-16674
    40Planlayın

    An issue was discovered on Weidmueller IE-SW-VL05M 3.6.6 Build 16102415, IE-SW-VL08MT 3.5.2 Build 16102415, and IE-SW-PL10M 3.3.16 Build 161

    KritikCVSS 9,8İstismar yokEPSS %2

    weidmueller · ie-sw-pl09m-5gc-4gt firmware6 Ara 2019

  • CVE-2020-27743
    40Planlayın

    libtac in pam_tacplus through 1.5.1 lacks a check for a failure of RAND_bytes()/RAND_pseudo_bytes().

    KritikCVSS 9,8İstismar yokEPSS %2

    pam tacplus project · pam tacplus26 Eki 2020

  • CVE-2014-6311
    40Planlayın

    generate_doygen.pl in ace before 6.2.7+dfsg-2 creates predictable file names in the /tmp directory which allows attackers to gain elevated p

    KritikCVSS 9,8İstismar yokEPSS %2

    vanderbilt · adaptive communication environment22 Kas 2019

  • CVE-2020-35926
    39İzleyin

    An issue was discovered in the nanorand crate before 0.5.1 for Rust.

    KritikCVSS 9,8İstismar yokEPSS %2

    nanorand project · nanorand31 Ara 2020

  • CVE-2020-9502
    39İzleyin

    Some Dahua products with Build time before December 2019 have Session ID predictable vulnerabilities.

    KritikCVSS 9,8İstismar yokEPSS %2

    dahuasecurity · sd6al firmware13 May 2020

  • CVE-2021-36166
    39İzleyin

    An improper authentication vulnerability in FortiMail before 7.0.1 may allow a remote attacker to efficiently guess one administrative accou

    KritikCVSS 9,8İstismar yokEPSS %1

    fortinet · fortimail1 Mar 2022

  • CVE-2018-18531
    39İzleyin

    text/impl/DefaultTextCreator.java, text/impl/ChineseTextProducer.java, and text/impl/FiveLetterFirstNameTextCreator.java in kaptcha 2.3.2 us

    KritikCVSS 9,8İstismar yokEPSS %1

    kaptcha project · kaptcha19 Eki 2018

  • CVE-2022-25752
    39İzleyin

    A vulnerability has been identified in SCALANCE X302-7 EEC (230V), SCALANCE X302-7 EEC (230V, coated), SCALANCE X302-7 EEC (24V), SCALANCE X

    KritikCVSS 9,8İstismar yokEPSS %1

    siemens · scalance x302-7eec firmware12 Nis 2022

  • CVE-2020-7548
    39İzleyin

    A CWE-330 - Use of Insufficiently Random Values vulnerability exists in Smartlink, PowerTag, and Wiser Series Gateways (see security notific

    KritikCVSS 9,8İstismar yokEPSS %1

    schneider-electric · acti9 smartlink si d firmware1 Ara 2020

Tüm zafiyet sınıfları