CWE-361 · 7 kayıt
7PK - Time and State
Bu sınıftaki CVE’ler
7 kayıt
| Aksiyon | CVE | Zafiyet | Ciddiyet | KEV | EPSS | Yayın |
|---|---|---|---|---|---|---|
67Bu hafta | CVE-2016-7547Silahlaştırılmış | A command execution flaw on the Trend Micro Threat Discovery Appliance 2.6.1062r1 exists with the timezone parameter in the admin_sys_time.ctrendmicro · threat discovery appliance · CWE-361 | Kritik9,8 | — | %92,7 | 12 Nis 2017 |
40Planlayın | CVE-2016-7036İstismar yok | python-jose before 1.3.2 allows attackers to have unspecified impact by leveraging failure to use a constant time comparison for HMAC keys.python-jose project · python-jose · CWE-361 | Kritik9,8 | — | %2,1 | 23 Oca 2017 |
36İzleyin | CVE-2016-1643İstismar yok | The ImageInputType::ensurePrimaryContent function in WebKit/Source/core/html/forms/ImageInputType.cpp in Blink, as used in Google Chrome befgoogle · chrome · CWE-361 | Yüksek8,8 | — | %2,7 | 13 Mar 2016 |
33İzleyin | CVE-2015-5300İstismar yok | The panic_gate check in NTP before 4.2.8p5 is only re-enabled after the first change to the system clock that was greater than 128 millisecontp · ntp · CWE-361 | Yüksek7,5 | — | %9,1 | 21 Tem 2017 |
30İzleyin | CVE-2016-7037İstismar yok | The verify function in Encryption/Symmetric.php in Malcolm Fell jwt before 1.0.3 does not use a timing-safe function for hash comparison, whemarref · jwt · CWE-361 | Yüksek7,5 | — | %0,7 | 23 Oca 2017 |
24İzleyin | CVE-2016-1000345İstismar yok | In the Bouncy Castle JCE Provider version 1.55 and earlier the DHIES/ECIES CBC mode vulnerable to padding oracle attack.bouncycastle · bc-java · CWE-361 | Orta5,9 | — | %2,6 | 4 Haz 2018 |
24İzleyin | CVE-2016-1000341İstismar yok | In the Bouncy Castle JCE Provider version 1.55 and earlier DSA signature generation is vulnerable to timing attack.bouncycastle · bc-java · CWE-361 | Orta5,9 | — | %2,6 | 4 Haz 2018 |
- CVE-2016-754767Bu hafta
A command execution flaw on the Trend Micro Threat Discovery Appliance 2.6.1062r1 exists with the timezone parameter in the admin_sys_time.c
KritikCVSS 9,8SilahlaştırılmışEPSS %93trendmicro · threat discovery appliance12 Nis 2017
- CVE-2016-703640Planlayın
python-jose before 1.3.2 allows attackers to have unspecified impact by leveraging failure to use a constant time comparison for HMAC keys.
KritikCVSS 9,8İstismar yokEPSS %2python-jose project · python-jose23 Oca 2017
- CVE-2016-164336İzleyin
The ImageInputType::ensurePrimaryContent function in WebKit/Source/core/html/forms/ImageInputType.cpp in Blink, as used in Google Chrome bef
YüksekCVSS 8,8İstismar yokEPSS %3google · chrome13 Mar 2016
- CVE-2015-530033İzleyin
The panic_gate check in NTP before 4.2.8p5 is only re-enabled after the first change to the system clock that was greater than 128 milliseco
YüksekCVSS 7,5İstismar yokEPSS %9ntp · ntp21 Tem 2017
- CVE-2016-703730İzleyin
The verify function in Encryption/Symmetric.php in Malcolm Fell jwt before 1.0.3 does not use a timing-safe function for hash comparison, wh
YüksekCVSS 7,5İstismar yokEPSS %1emarref · jwt23 Oca 2017
- CVE-2016-100034524İzleyin
In the Bouncy Castle JCE Provider version 1.55 and earlier the DHIES/ECIES CBC mode vulnerable to padding oracle attack.
OrtaCVSS 5,9İstismar yokEPSS %3bouncycastle · bc-java4 Haz 2018
- CVE-2016-100034124İzleyin
In the Bouncy Castle JCE Provider version 1.55 and earlier DSA signature generation is vulnerable to timing attack.
OrtaCVSS 5,9İstismar yokEPSS %3bouncycastle · bc-java4 Haz 2018