İçeriğe atla
Noroxi

CWE-335 · 33 kayıt

Incorrect Usage of Seeds in Pseudo-Random Number Generator (PRNG)

Bu sınıftaki CVE’ler

33 kayıt

  • CVE-2017-11519
    40Planlayın

    passwd_recovery.lua on the TP-Link Archer C9(UN)_V2_160517 allows an attacker to reset the admin password by leveraging a predictable random

    KritikCVSS 9,8Kavram kanıtıEPSS %3

    tp-link · archer c9 \(2.0\) firmware21 Tem 2017

  • CVE-2019-11495
    40Planlayın

    In Couchbase Server 5.1.1, the cookie used for intra-node communication was not generated securely.

    KritikCVSS 9,8İstismar yokEPSS %2

    couchbase · couchbase server10 Eyl 2019

  • CVE-2019-10908
    39İzleyin

    In Airsonic 10.2.1, RecoverController.java generates passwords via org.apache.commons.lang.RandomStringUtils, which uses java.util.Random in

    KritikCVSS 9,8İstismar yokEPSS %2

    airsonic project · airsonic7 Nis 2019

  • CVE-2012-1577
    39İzleyin

    lib/libc/stdlib/random.c in OpenBSD returns 0 when seeded with 0.

    KritikCVSS 9,8İstismar yokEPSS %2

    openbsd · openbsd10 Ara 2019

  • CVE-2024-36048
    39İzleyin

    QAbstractOAuth in Qt Network Authorization in Qt before 5.15.17, 6.x before 6.2.13, 6.3.x through 6.5.x before 6.5.6, and 6.6.x through 6.7.

    KritikCVSS 9,8İstismar yokEPSS %1

    qt · qt18 May 2024

  • CVE-2023-4472
    39İzleyin

    Cryptographically weak PRNG in Opinio 7.22

    KritikCVSS 9,8İstismar yokEPSS %1

    objectplanet · opinio1 Şub 2024

  • CVE-2021-41117
    37İzleyin

    Insecure random number generation

    KritikCVSS 9,1Kavram kanıtıEPSS %3

    keypair project · keypair11 Eki 2021

  • CVE-2018-1426
    37İzleyin

    IBM GSKit (IBM DB2 for Linux, UNIX and Windows 9.7, 10.1, 10.5, and 11.1) duplicates the PRNG state across fork() system calls when multiple

    KritikCVSS 9,1İstismar yokEPSS %2

    ibm · db222 Mar 2018

  • CVE-2018-12520
    35İzleyin

    An issue was discovered in ntopng 3.4 before 3.4.180617.

    YüksekCVSS 8,1Kavram kanıtıEPSS %11

    ntop · ntopng5 Tem 2018

  • CVE-2024-27632
    35İzleyin

    An issue in GNU Savane v.3.12 and before allows a remote attacker to escalate privileges via the form_id in the form_header() function.

    YüksekCVSS 8,8Kavram kanıtıEPSS %1

    gnu · savane8 Nis 2024

  • CVE-2018-14647
    33İzleyin

    Python's elementtree C accelerator failed to initialise Expat's hash salt during initialization.

    YüksekCVSS 7,5İstismar yokEPSS %11

    python · python24 Eyl 2018

  • CVE-2016-3735
    32İzleyin

    Piwigo is image gallery software written in PHP.

    YüksekCVSS 8,1İstismar yokEPSS %1

    piwigo · piwigo28 Oca 2022

  • CVE-2024-1579
    32İzleyin

    Insufficient seeding of random number generator

    YüksekCVSS 8,1İstismar yokEPSS %1

    secomea · gatemanager29 Nis 2024

  • CVE-2016-10180
    31İzleyin

    An issue was discovered on the D-Link DWR-932B router.

    YüksekCVSS 7,5İstismar yokEPSS %4

    dlink · dwr-932b firmware30 Oca 2017

  • CVE-2021-27211
    31İzleyin

    steghide 0.5.1 relies on a certain 32-bit seed value, which makes it easier for attackers to detect hidden data.

    YüksekCVSS 7,5Kavram kanıtıEPSS %3

    steghide project · steghide15 Şub 2021

  • CVE-2019-25061
    31İzleyin

    The random_password_generator (aka RandomPasswordGenerator) gem through 1.0.0 for Ruby uses Kernel#rand to generate passwords, which, due to

    YüksekCVSS 7,5İstismar yokEPSS %2

    random password generator project · random password generator18 May 2022

  • CVE-2020-7010
    30İzleyin

    Elastic Cloud on Kubernetes (ECK) versions prior to 1.1.0 generate passwords using a weak random number generator.

    YüksekCVSS 7,5İstismar yokEPSS %1

    elastic · elastic cloud on kubernetes3 Haz 2020

  • CVE-2020-13784
    30İzleyin

    D-Link DIR-865L Ax 1.20B01 Beta devices have a predictable seed in a Pseudo-Random Number Generator.

    YüksekCVSS 7,5İstismar yokEPSS %1

    dlink · dir-865l firmware3 Haz 2020

  • CVE-2017-5214
    30İzleyin

    The Codextrous B2J Contact (aka b2j_contact) extension before 2.1.13 for Joomla! allows prediction of a uniqid value based on knowledge of a

    YüksekCVSS 7,5İstismar yokEPSS %1

    codextrous · b2j contact17 May 2017

  • CVE-2022-39218
    30İzleyin

    Random number seed fixed during compilation

    YüksekCVSS 7,5İstismar yokEPSS %1

    fastly · js-compute20 Eyl 2022

  • CVE-2025-24783
    30İzleyin

    Apache Cocoon: continuations may not be private

    YüksekCVSS 7,5İstismar yokEPSS %1

    apache · cocoon27 Oca 2025

  • CVE-2025-27580
    30İzleyin

    NIH BRICS (aka Biomedical Research Informatics Computing System) through 14.0.0-67 generates predictable tokens (that depend on username, ti

    YüksekCVSS 7,5Kavram kanıtıEPSS %1

    nih · brics23 Nis 2025

  • CVE-2026-41564
    30İzleyin

    CryptX versions before 0.088 for Perl do not reseed the Crypt::PK PRNG state after forking

    YüksekCVSS 7,5İstismar yokEPSS %1

    dcit · cryptx23 Nis 2026

  • CVE-2026-11702
    30İzleyin

    Bytes::Random::Secure::Tiny versions through 1.011 for Perl share internal state across forked processes

    YüksekCVSS 7,5İstismar yokEPSS %1

    davido · bytes::random::secure::tiny26 Haz 2026

  • CVE-2026-11625
    30İzleyin

    Bytes::Random::Secure versions through 0.29 for Perl share internal state across forked processes

    YüksekCVSS 7,5İstismar yokEPSS %1

    davido · bytes::random::secure26 Haz 2026

Tüm zafiyet sınıfları