CWE-330

High likelihood

Use of Insufficiently Random Values

Parent: CWE-693 - Protection Mechanism Failure

The product uses insufficiently random numbers or values in a security context that depends on unpredictable numbers.

381 vulnerabilities with CWE-330
CVE-2019-11840 MEDIUM
golang.org/x/crypto <0.0.0-20190320223903 - Memory Corruption
CVSS 5.9
CVE-2019-11690 MEDIUM
Das U-Boot <2019.04 - Info Disclosure
CVSS 5.9
CVE-2019-11641 HIGH
Anomali Agave <1.0.0 - Info Disclosure
CVSS 7.5
CVE-2019-11219 HIGH
Shenzhen Yunni Technology iLnkP2P - Info Disclosure
CVSS 8.2
CVE-2019-3795 MEDIUM
Spring Security <4.2.12, 5.0.x<5.0.12, 5.1.x<5.1.5 - Info Disclosure
CVSS 5.3
CVE-2019-9860 HIGH
ABUS Secvest FUAA50000 3.01.01 Cleartext Transmission of Sensitive Information
CVSS 7.5
CVE-2019-9863 CRITICAL
ABUS Secvest FUAA50000 3.01.01 - Info Disclosure
CVSS 9.8
CVE-2019-5420 CRITICAL
Ruby On Rails DoubleTap Development Mode secret_key_base Vulnerability
CVSS 9.8
CVE-2019-9898 CRITICAL
PuTTY < 0.71 - Use of Insufficiently Random Values in Cryptographic Operations
CVSS 9.8
CVE-2019-5885 HIGH
Matrix Synapse <0.34.0.1 - Privilege Escalation
CVSS 7.5
CVE-2019-1543 HIGH
OpenSSL 1.1.0-1.1.0j - Nonce Reuse in ChaCha20-Poly1305
CVSS 7.4
CVE-2019-0729 CRITICAL
Azure IoT Java SDK - Privilege Escalation
CVSS 9.8
CVE-2019-1997 HIGH
Android 7.0-9 - Local Information Disclosure via Insecure Randomness in random_get_bytes
CVSS 7.5
CVE-2019-8919 HIGH
Seafile Android Client <2.2.13 - Info Disclosure
CVSS 7.5
CVE-2019-0007 CRITICAL
Juniper Networks Junos OS <15.1F5 - Info Disclosure
CVSS 9.3
CVE-2018-19441 MEDIUM
Neato Botvac Connected 2.2.0 - Info Disclosure
CVSS 4.7
CVE-2018-18425 MEDIUM
Primeo - Arbitrary Token Minting via doAirdrop Function
CVSS 6.5
CVE-2018-20025 HIGH
CODESYS V3 <3.5.14.0 - Info Disclosure
CVSS 7.5
CVE-2018-18602 CRITICAL
Guardzilla Smart Cameras - Info Disclosure
CVSS 9.8
CVE-2018-17987 HIGH
HashHeroes - Use of Insufficiently Random Values in determineWinner Function
CVSS 7.5
CVE-2018-1279 HIGH
Pivotal RabbitMQ for PCF - Unauthenticated Cluster Takeover via Deterministic Cookie
CVSS 8.5
CVE-2018-19983 MEDIUM
Silabs Z-Wave S0 Firmware - Denial of Service via Continuous Nonce Get Frame Transmission
CVSS 6.5
CVE-2018-18531 CRITICAL
kaptcha 2.3.2 - Use of Insufficiently Random Values in CAPTCHA Generation
CVSS 9.8
CVE-2018-18375 CRITICAL
Orange AirBox Y858_FL_01.16_04 - Info Disclosure
CVSS 9.8
CVE-2018-17888 CRITICAL
NUUO CMS < 3.1 - Remote Code Execution via Session ID Prediction
CVSS 9.8
Details
Vulnerabilities 381
Exploit Likelihood High