CWE-330

High likelihood

Use of Insufficiently Random Values

Parent: CWE-693 - Protection Mechanism Failure

The product uses insufficiently random numbers or values in a security context that depends on unpredictable numbers.

381 vulnerabilities with CWE-330
CVE-2018-16239 CRITICAL
damicms 6.0.1 - Session Hijacking via Predictable Cookie Generation
CVSS 9.8
CVE-2018-15807 HIGH
POSIM EVO 15.13 - Unauthenticated Bypass via Emergency Override Code Prediction
CVSS 7.8
CVE-2018-13280 HIGH
Synology DSM <6.2-23739 - Info Disclosure
CVSS 7.4
CVE-2018-11045 MEDIUM
Pivotal Operations Manager <2.1.6, <2.0.15, <1.12.22 - Info Disclosure
CVSS 5.9
CVE-2018-1108 MEDIUM
kernel drivers <4.17-rc1 - Info Disclosure
CVSS 5.9
CVE-2018-1266 HIGH
Cloudfoundry Capi-release < 1.52.0 - Path Traversal
CVSS 8.1
CVE-2017-5242 HIGH
Nexpose & InsightVM - Info Disclosure
CVSS 7.7
CVE-2017-16031 HIGH
socket.io < 0.9.6 - Predictable Socket ID via Math.random()
CVSS 7.5
CVE-2017-16028 MEDIUM
react-native-meteor-oauth - Info Disclosure
CVSS 5.3
CVE-2017-16924 CRITICAL
ManageEngine Desktop Central MSP <10.0.137 - Info Disclosure
CVSS 9.8
CVE-2017-15654 HIGH
Asus asuswrt <= 3.0.0.4.380.7743 - Info Disclosure
CVSS 8.3
CVE-2017-17704 HIGH
Software House iStar Ultra <6.5.2.20569 - Replay Attack
CVSS 7.4
CVE-2017-17910 MEDIUM
Hoermann BiSecur <2018 - Info Disclosure
CVSS 6.5
CVE-2017-17091 HIGH
WordPress < 4.9.1 - Use of Insufficiently Random Values in User ID Key Generation
CVSS 8.8
CVE-2017-10874 HIGH
PWR-Q200 Firmware - DNS Cache Poisoning via Predictable Source Ports
CVSS 7.5
CVE-2017-12361 MEDIUM
Cisco Jabber for Windows - Info Disclosure
CVSS 4.0
CVE-2017-1000246 MEDIUM
Python pysaml2 <4.4.0 - Info Disclosure
CVSS 5.3
CVE-2017-13088 MEDIUM
WPA/WPA2 - Reinstallation
CVSS 5.3
CVE-2017-13087 MEDIUM
hostapd - Use of Insufficiently Random Values in WPA/WPA2 GTK Reinstallation
CVSS 5.3
CVE-2017-13086 MEDIUM
WPA/WPA2 - Reinstallation
CVSS 6.8
CVE-2017-13084 MEDIUM
Wi-Fi Protected Access - Replay Attack
CVSS 6.8
CVE-2017-13082 HIGH
WPA/WPA2 - Reinstallation
CVSS 8.1
CVE-2017-13081 MEDIUM
WPA/WPA2 - Reinstallation
CVSS 5.3
CVE-2017-13080 MEDIUM
WPA/WPA2 - Reinstallation
CVSS 5.3
CVE-2017-13079 MEDIUM
Wi-Fi Protected Access - Reinstallation
CVSS 5.3
Details
Vulnerabilities 381
Exploit Likelihood High