CWE-330

High likelihood

Use of Insufficiently Random Values

Parent: CWE-693 - Protection Mechanism Failure

The product uses insufficiently random numbers or values in a security context that depends on unpredictable numbers.

375 vulnerabilities with CWE-330
CVE-2020-13860 HIGH
Mofi Network MOFI4500-4GXeLTE <4.0.8-std - Info Disclosure
CVSS 7.5
CVE-2020-27264 HIGH
SOOIL Developments Co., Ltd Diabecare RS - Unauthenticated RCE
CVSS 8.8
CVE-2020-35926 CRITICAL
nanorand < 0.5.1 - Incorrect Conversion between Numeric Types
CVSS 9.8
CVE-2020-17470 MEDIUM
FNET < 4.6.4 - DNS Cache Poisoning via Predictable Transaction IDs
CVSS 5.3
CVE-2020-15023 MEDIUM
Askey AP5100W <AP5100W_Dual_SIG_1.01.097 - Info Disclosure
CVSS 5.9
CVE-2020-7548 CRITICAL
Smartlink PowerTag Wiser Series Gateways - Info Disclosure
CVSS 9.8
CVE-2020-26550 HIGH
Aviatrix Controller <R5.3.1151 - Info Disclosure
CVSS 7.5
CVE-2020-27556 MEDIUM
BASETech GE-131 BT-1837836 - Info Disclosure
CVSS 5.3
CVE-2020-25705 HIGH
Linux Kernel < 5.10.0 - UDP Port Scan via ICMP Packet Source Port Prediction
CVSS 7.4
CVE-2020-27180 HIGH
konzept-ix publiXone <2020.015 - Info Disclosure
CVSS 7.5
CVE-2020-27743 CRITICAL
pam_tacplus < 1.5.1 - Use of Insufficiently Random Values in libtac Session ID
CVSS 9.8
CVE-2020-1905 LOW
WhatsApp for Android <v2.20.185 - Info Disclosure
CVSS 3.3
CVE-2020-26107 HIGH
cPanel < 88.0.3 - Use of Insufficiently Random Values in PowerDNS API Key Generation
CVSS 7.5
CVE-2020-0407 MEDIUM
Android - Use of Insufficiently Random Values in f2fs Encryption IV Handling
CVSS 4.4
CVE-2020-13304 LOW
GitLab <13.1.10-13.3.4 - Privilege Escalation
CVSS 3.8
CVE-2020-16271 CRITICAL
Kee Vault KeePassRPC <1.12.0 - Info Disclosure
CVSS 9.1
CVE-2020-16166 LOW
Linux kernel <5.7.11 - Info Disclosure
CVSS 3.7
CVE-2020-10274 HIGH
Mobile Industrial Robots MIR100 Firmware < 2.8.1.1 - Predictable REST API Access Tokens
CVSS 7.1
CVE-2020-4188 MEDIUM
IBM Security Guardium <11.1 - Info Disclosure
CVSS 5.3
CVE-2020-14423 MEDIUM
Convos < 4.20 - Use of Insufficiently Random Values in Local Secret Generation
CVSS 5.3
CVE-2020-14422 MEDIUM
Python < 3.5.10 - Denial of Service via IPv4Interface and IPv6Interface Hash Calculation
CVSS 5.9
CVE-2020-11901 CRITICAL
Treck TCP/IP < 6.0.1.66 - Remote Code Execution via Invalid DNS Response
CVSS 9.0
CVE-2020-12712 HIGH
SOS JobScheduler <1.13 - Info Disclosure
CVSS 7.5
CVE-2020-13817 HIGH
ntp < 4.2.8p14 and 4.3.x < 4.3.100 - Denial of Service via Predictable Transmit Timestamps
CVSS 7.4
CVE-2020-5365 MEDIUM
Dell EMC Isilon <8.2.2 - Info Disclosure
CVSS 5.3
Details
Vulnerabilities 375
Exploit Likelihood High