CWE-330
High likelihoodUse of Insufficiently Random Values
The product uses insufficiently random numbers or values in a security context that depends on unpredictable numbers.
381 vulnerabilities with CWE-330
CVE-2017-13078
MEDIUM
WPA/WPA2 - Reinstallation
CVSS 5.3
CVE-2017-13077
MEDIUM
WPA/WPA2 - Replay Attack
CVSS 6.8
CVE-2017-7905
CRITICAL
GE Multilin SR, UR, and URplus Protective Relays - Weak Password Encoding via Non-Random Initialization Vector
CVSS 9.8
CVE-2017-7902
CRITICAL
Rockwell Automation Allen-Bradley - Reuse of Nonce
CVSS 9.8
CVE-2017-7901
HIGH
Rockwellautomation 1763-l16awa Series A < 16.000 - Denial of Service
CVSS 8.6
CVE-2017-6026
CRITICAL
Schneider Electric Modicon PLCs <4.0.5.11 - Info Disclosure
CVSS 9.1
CVE-2017-0897
HIGH
ExpressionEngine <2.11.8, <3.5.5 - RCE
CVSS 7.5
CVE-2016-4980
LOW
xquest <2016-06-13 - Info Disclosure
CVSS 2.5
CVE-2016-5100
CRITICAL
Froxlor < 0.9.35 - Predictable Password Reset Token via Weak PHP rand Function
CVSS 9.8
CVE-2016-10180
HIGH
D-Link DWR-932B Firmware - Predictable WPS PIN Generation via srand(time(0)) Seeding
CVSS 7.5
CVE-2016-5085
HIGH
Johnson & Johnson Animas OneTouch Ping - Info Disclosure
CVSS 7.5
CVE-2015-9019
MEDIUM
libxslt < 1.1.29 - Use of Insufficiently Random Values in EXSLT math.random
CVSS 5.3
CVE-2015-3963
Wind River VxWorks <7 - Info Disclosure
CVE-2014-6311
CRITICAL
generate_doygen.pl <6.2.7+dfsg-2 - Privilege Escalation
CVSS 9.8
CVE-2013-0294
MEDIUM
pyrad < 2.1 - Use of Insufficiently Random Values in RADIUS Authenticator and Password Hash Generation
CVSS 5.9
CVE-2013-4102
CRITICAL
Cryptocat <2.0.22 - Info Disclosure
CVSS 9.1
CVE-2013-7463
HIGH
aescrypt gem 1.0.0 - Info Disclosure
CVSS 7.5
CVE-2013-6925
Siemens RuggedCom ROS <3.12.2 - SSRF
CVE-2013-4734
HIGH
Digital Alert Systems DASDEC <2.0-2 - Info Disclosure
CVSS 7.3
CVE-2012-1562
HIGH
Joomla! <2.5.3 - Privilege Escalation
CVSS 7.5
CVE-2010-3666
MEDIUM
TYPO3 <4.1.14, <4.2.13, <4.3.4, <4.4.1 - Info Disclosure
CVSS 5.3
CVE-2009-2158
HIGH
TorrentTrader Classic 1.09 - Info Disclosure
CVSS 7.5
CVE-2009-0255
HIGH
TYPO3 4.0.0-4.0.9 4.1.0-4.1.7 4.2.0-4.2.3 - Use of Insufficiently Random Values in System Extension Install Tool
CVSS 7.5
CVE-2008-5162
HIGH
FreeBSD 6.3-7.1 - Use of Insufficiently Random Values in arc4random Function
CVSS 7.0
CVE-2008-4929
HIGH
MyBB 1.4.2 - Insufficiently Random Filename Generation for Uploaded Attachments
CVSS 7.5
Details
Vulnerabilities
381
Exploit Likelihood
High