CWE-338

Medium likelihood

Use of Cryptographically Weak Pseudo-Random Number Generator (PRNG)

Parent: CWE-330 - Use of Insufficiently Random Values

The product uses a Pseudo-Random Number Generator (PRNG) in a security context, but the PRNG's algorithm is not cryptographically strong.

205 vulnerabilities with CWE-338
CVE-2009-3238 MEDIUM
Linux kernel <2.6.30 - Info Disclosure
CVSS 5.5
CVE-2009-2367 CRITICAL
Iomega StorCenter Pro - Info Disclosure
CVSS 9.8
CVE-2008-3280 MEDIUM
OpenID - Use of Cryptographically Weak Pseudo-Random Number Generator
CVSS 5.9
CVE-2008-0166 HIGH
OpenSSL <0.9.8g-9 - Info Disclosure
CVSS 7.5
CVE-2002-20002 MEDIUM
Net::EasyTCP <0.15 - Info Disclosure
CVSS 5.4
Details
Vulnerabilities 205
Exploit Likelihood Medium