İçeriğe atla
Noroxi

CWE-361 · 7 kayıt

7PK - Time and State

Bu sınıftaki CVE’ler

7 kayıt

  • CVE-2016-7547
    67Bu hafta

    A command execution flaw on the Trend Micro Threat Discovery Appliance 2.6.1062r1 exists with the timezone parameter in the admin_sys_time.c

    KritikCVSS 9,8SilahlaştırılmışEPSS %93

    trendmicro · threat discovery appliance12 Nis 2017

  • CVE-2016-7036
    40Planlayın

    python-jose before 1.3.2 allows attackers to have unspecified impact by leveraging failure to use a constant time comparison for HMAC keys.

    KritikCVSS 9,8İstismar yokEPSS %2

    python-jose project · python-jose23 Oca 2017

  • CVE-2016-1643
    36İzleyin

    The ImageInputType::ensurePrimaryContent function in WebKit/Source/core/html/forms/ImageInputType.cpp in Blink, as used in Google Chrome bef

    YüksekCVSS 8,8İstismar yokEPSS %3

    google · chrome13 Mar 2016

  • CVE-2015-5300
    33İzleyin

    The panic_gate check in NTP before 4.2.8p5 is only re-enabled after the first change to the system clock that was greater than 128 milliseco

    YüksekCVSS 7,5İstismar yokEPSS %9

    ntp · ntp21 Tem 2017

  • CVE-2016-7037
    30İzleyin

    The verify function in Encryption/Symmetric.php in Malcolm Fell jwt before 1.0.3 does not use a timing-safe function for hash comparison, wh

    YüksekCVSS 7,5İstismar yokEPSS %1

    emarref · jwt23 Oca 2017

  • In the Bouncy Castle JCE Provider version 1.55 and earlier the DHIES/ECIES CBC mode vulnerable to padding oracle attack.

    OrtaCVSS 5,9İstismar yokEPSS %3

    bouncycastle · bc-java4 Haz 2018

  • In the Bouncy Castle JCE Provider version 1.55 and earlier DSA signature generation is vulnerable to timing attack.

    OrtaCVSS 5,9İstismar yokEPSS %3

    bouncycastle · bc-java4 Haz 2018

Tüm zafiyet sınıfları