CWE-335 · 33 kayıt
Incorrect Usage of Seeds in Pseudo-Random Number Generator (PRNG)
Bu sınıftaki CVE’ler
33 kayıt
| Aksiyon | CVE | Zafiyet | Ciddiyet | KEV | EPSS | Yayın |
|---|---|---|---|---|---|---|
40Planlayın | CVE-2017-11519Kavram kanıtı | passwd_recovery.lua on the TP-Link Archer C9(UN)_V2_160517 allows an attacker to reset the admin password by leveraging a predictable randomtp-link · archer c9 \(2.0\) firmware · CWE-335 | Kritik9,8 | — | %3,1 | 21 Tem 2017 |
40Planlayın | CVE-2019-11495İstismar yok | In Couchbase Server 5.1.1, the cookie used for intra-node communication was not generated securely.couchbase · couchbase server · CWE-335 | Kritik9,8 | — | %2,1 | 10 Eyl 2019 |
39İzleyin | CVE-2019-10908İstismar yok | In Airsonic 10.2.1, RecoverController.java generates passwords via org.apache.commons.lang.RandomStringUtils, which uses java.util.Random inairsonic project · airsonic · CWE-335 | Kritik9,8 | — | %1,6 | 7 Nis 2019 |
39İzleyin | CVE-2012-1577İstismar yok | lib/libc/stdlib/random.c in OpenBSD returns 0 when seeded with 0.openbsd · openbsd · CWE-335 | Kritik9,8 | — | %1,6 | 10 Ara 2019 |
39İzleyin | CVE-2024-36048İstismar yok | QAbstractOAuth in Qt Network Authorization in Qt before 5.15.17, 6.x before 6.2.13, 6.3.x through 6.5.x before 6.5.6, and 6.6.x through 6.7.qt · qt · CWE-335 | Kritik9,8 | — | %1,0 | 18 May 2024 |
39İzleyin | CVE-2023-4472İstismar yok | Cryptographically weak PRNG in Opinio 7.22objectplanet · opinio · CWE-335 | Kritik9,8 | — | %0,7 | 1 Şub 2024 |
37İzleyin | CVE-2021-41117Kavram kanıtı | Insecure random number generationkeypair project · keypair · CWE-335 | Kritik9,1 | — | %3,1 | 11 Eki 2021 |
37İzleyin | CVE-2018-1426İstismar yok | IBM GSKit (IBM DB2 for Linux, UNIX and Windows 9.7, 10.1, 10.5, and 11.1) duplicates the PRNG state across fork() system calls when multipleibm · db2 · CWE-335 | Kritik9,1 | — | %2,4 | 22 Mar 2018 |
35İzleyin | CVE-2018-12520Kavram kanıtı | An issue was discovered in ntopng 3.4 before 3.4.180617.ntop · ntopng · CWE-335 | Yüksek8,1 | — | %10,5 | 5 Tem 2018 |
35İzleyin | CVE-2024-27632Kavram kanıtı | An issue in GNU Savane v.3.12 and before allows a remote attacker to escalate privileges via the form_id in the form_header() function.gnu · savane · CWE-335 | Yüksek8,8 | — | %1,3 | 8 Nis 2024 |
33İzleyin | CVE-2018-14647İstismar yok | Python's elementtree C accelerator failed to initialise Expat's hash salt during initialization.python · python · CWE-335 | Yüksek7,5 | — | %10,9 | 24 Eyl 2018 |
32İzleyin | CVE-2016-3735İstismar yok | Piwigo is image gallery software written in PHP.piwigo · piwigo · CWE-335 | Yüksek8,1 | — | %1,4 | 28 Oca 2022 |
32İzleyin | CVE-2024-1579İstismar yok | Insufficient seeding of random number generatorsecomea · gatemanager · CWE-335 | Yüksek8,1 | — | %0,5 | 29 Nis 2024 |
31İzleyin | CVE-2016-10180İstismar yok | An issue was discovered on the D-Link DWR-932B router.dlink · dwr-932b firmware · CWE-335 | Yüksek7,5 | — | %4,4 | 30 Oca 2017 |
31İzleyin | CVE-2021-27211Kavram kanıtı | steghide 0.5.1 relies on a certain 32-bit seed value, which makes it easier for attackers to detect hidden data.steghide project · steghide · CWE-335 | Yüksek7,5 | — | %3,3 | 15 Şub 2021 |
31İzleyin | CVE-2019-25061İstismar yok | The random_password_generator (aka RandomPasswordGenerator) gem through 1.0.0 for Ruby uses Kernel#rand to generate passwords, which, due torandom password generator project · random password generator · CWE-335 | Yüksek7,5 | — | %1,9 | 18 May 2022 |
30İzleyin | CVE-2020-7010İstismar yok | Elastic Cloud on Kubernetes (ECK) versions prior to 1.1.0 generate passwords using a weak random number generator.elastic · elastic cloud on kubernetes · CWE-335 | Yüksek7,5 | — | %1,4 | 3 Haz 2020 |
30İzleyin | CVE-2020-13784İstismar yok | D-Link DIR-865L Ax 1.20B01 Beta devices have a predictable seed in a Pseudo-Random Number Generator.dlink · dir-865l firmware · CWE-335 | Yüksek7,5 | — | %1,3 | 3 Haz 2020 |
30İzleyin | CVE-2017-5214İstismar yok | The Codextrous B2J Contact (aka b2j_contact) extension before 2.1.13 for Joomla! allows prediction of a uniqid value based on knowledge of acodextrous · b2j contact · CWE-335 | Yüksek7,5 | — | %1,2 | 17 May 2017 |
30İzleyin | CVE-2022-39218İstismar yok | Random number seed fixed during compilationfastly · js-compute · CWE-335 | Yüksek7,5 | — | %0,9 | 20 Eyl 2022 |
30İzleyin | CVE-2025-24783İstismar yok | Apache Cocoon: continuations may not be privateapache · cocoon · CWE-335 | Yüksek7,5 | — | %0,8 | 27 Oca 2025 |
30İzleyin | CVE-2025-27580Kavram kanıtı | NIH BRICS (aka Biomedical Research Informatics Computing System) through 14.0.0-67 generates predictable tokens (that depend on username, tinih · brics · CWE-335 | Yüksek7,5 | — | %0,7 | 23 Nis 2025 |
30İzleyin | CVE-2026-41564İstismar yok | CryptX versions before 0.088 for Perl do not reseed the Crypt::PK PRNG state after forkingdcit · cryptx · CWE-335 | Yüksek7,5 | — | %0,5 | 23 Nis 2026 |
30İzleyin | CVE-2026-11702İstismar yok | Bytes::Random::Secure::Tiny versions through 1.011 for Perl share internal state across forked processesdavido · bytes::random::secure::tiny · CWE-335 | Yüksek7,5 | — | %0,5 | 26 Haz 2026 |
30İzleyin | CVE-2026-11625İstismar yok | Bytes::Random::Secure versions through 0.29 for Perl share internal state across forked processesdavido · bytes::random::secure · CWE-335 | Yüksek7,5 | — | %0,5 | 26 Haz 2026 |
- CVE-2017-1151940Planlayın
passwd_recovery.lua on the TP-Link Archer C9(UN)_V2_160517 allows an attacker to reset the admin password by leveraging a predictable random
KritikCVSS 9,8Kavram kanıtıEPSS %3tp-link · archer c9 \(2.0\) firmware21 Tem 2017
- CVE-2019-1149540Planlayın
In Couchbase Server 5.1.1, the cookie used for intra-node communication was not generated securely.
KritikCVSS 9,8İstismar yokEPSS %2couchbase · couchbase server10 Eyl 2019
- CVE-2019-1090839İzleyin
In Airsonic 10.2.1, RecoverController.java generates passwords via org.apache.commons.lang.RandomStringUtils, which uses java.util.Random in
KritikCVSS 9,8İstismar yokEPSS %2airsonic project · airsonic7 Nis 2019
- CVE-2012-157739İzleyin
lib/libc/stdlib/random.c in OpenBSD returns 0 when seeded with 0.
KritikCVSS 9,8İstismar yokEPSS %2openbsd · openbsd10 Ara 2019
- CVE-2024-3604839İzleyin
QAbstractOAuth in Qt Network Authorization in Qt before 5.15.17, 6.x before 6.2.13, 6.3.x through 6.5.x before 6.5.6, and 6.6.x through 6.7.
KritikCVSS 9,8İstismar yokEPSS %1qt · qt18 May 2024
- CVE-2023-447239İzleyin
Cryptographically weak PRNG in Opinio 7.22
KritikCVSS 9,8İstismar yokEPSS %1objectplanet · opinio1 Şub 2024
- CVE-2021-4111737İzleyin
Insecure random number generation
KritikCVSS 9,1Kavram kanıtıEPSS %3keypair project · keypair11 Eki 2021
- CVE-2018-142637İzleyin
IBM GSKit (IBM DB2 for Linux, UNIX and Windows 9.7, 10.1, 10.5, and 11.1) duplicates the PRNG state across fork() system calls when multiple
KritikCVSS 9,1İstismar yokEPSS %2ibm · db222 Mar 2018
- CVE-2018-1252035İzleyin
An issue was discovered in ntopng 3.4 before 3.4.180617.
YüksekCVSS 8,1Kavram kanıtıEPSS %11ntop · ntopng5 Tem 2018
- CVE-2024-2763235İzleyin
An issue in GNU Savane v.3.12 and before allows a remote attacker to escalate privileges via the form_id in the form_header() function.
YüksekCVSS 8,8Kavram kanıtıEPSS %1gnu · savane8 Nis 2024
- CVE-2018-1464733İzleyin
Python's elementtree C accelerator failed to initialise Expat's hash salt during initialization.
YüksekCVSS 7,5İstismar yokEPSS %11python · python24 Eyl 2018
- CVE-2016-373532İzleyin
Piwigo is image gallery software written in PHP.
YüksekCVSS 8,1İstismar yokEPSS %1piwigo · piwigo28 Oca 2022
- CVE-2024-157932İzleyin
Insufficient seeding of random number generator
YüksekCVSS 8,1İstismar yokEPSS %1secomea · gatemanager29 Nis 2024
- CVE-2016-1018031İzleyin
An issue was discovered on the D-Link DWR-932B router.
YüksekCVSS 7,5İstismar yokEPSS %4dlink · dwr-932b firmware30 Oca 2017
- CVE-2021-2721131İzleyin
steghide 0.5.1 relies on a certain 32-bit seed value, which makes it easier for attackers to detect hidden data.
YüksekCVSS 7,5Kavram kanıtıEPSS %3steghide project · steghide15 Şub 2021
- CVE-2019-2506131İzleyin
The random_password_generator (aka RandomPasswordGenerator) gem through 1.0.0 for Ruby uses Kernel#rand to generate passwords, which, due to
YüksekCVSS 7,5İstismar yokEPSS %2random password generator project · random password generator18 May 2022
- CVE-2020-701030İzleyin
Elastic Cloud on Kubernetes (ECK) versions prior to 1.1.0 generate passwords using a weak random number generator.
YüksekCVSS 7,5İstismar yokEPSS %1elastic · elastic cloud on kubernetes3 Haz 2020
- CVE-2020-1378430İzleyin
D-Link DIR-865L Ax 1.20B01 Beta devices have a predictable seed in a Pseudo-Random Number Generator.
YüksekCVSS 7,5İstismar yokEPSS %1dlink · dir-865l firmware3 Haz 2020
- CVE-2017-521430İzleyin
The Codextrous B2J Contact (aka b2j_contact) extension before 2.1.13 for Joomla! allows prediction of a uniqid value based on knowledge of a
YüksekCVSS 7,5İstismar yokEPSS %1codextrous · b2j contact17 May 2017
- CVE-2022-3921830İzleyin
Random number seed fixed during compilation
YüksekCVSS 7,5İstismar yokEPSS %1fastly · js-compute20 Eyl 2022
- CVE-2025-2478330İzleyin
Apache Cocoon: continuations may not be private
YüksekCVSS 7,5İstismar yokEPSS %1apache · cocoon27 Oca 2025
- CVE-2025-2758030İzleyin
NIH BRICS (aka Biomedical Research Informatics Computing System) through 14.0.0-67 generates predictable tokens (that depend on username, ti
YüksekCVSS 7,5Kavram kanıtıEPSS %1nih · brics23 Nis 2025
- CVE-2026-4156430İzleyin
CryptX versions before 0.088 for Perl do not reseed the Crypt::PK PRNG state after forking
YüksekCVSS 7,5İstismar yokEPSS %1dcit · cryptx23 Nis 2026
- CVE-2026-1170230İzleyin
Bytes::Random::Secure::Tiny versions through 1.011 for Perl share internal state across forked processes
YüksekCVSS 7,5İstismar yokEPSS %1davido · bytes::random::secure::tiny26 Haz 2026
- CVE-2026-1162530İzleyin
Bytes::Random::Secure versions through 0.29 for Perl share internal state across forked processes
YüksekCVSS 7,5İstismar yokEPSS %1davido · bytes::random::secure26 Haz 2026