CWE-330
380 CVEs • Abstraction: Class • Likelihood of Exploit: High
Use of Insufficiently Random Values
The product uses insufficiently random numbers or values in a security context that depends on unpredictable numbers.
CVEs (380)
CVE VENDORS PRODUCTS UPDATED PUBLISHED CVSS |
|---|
2Linux Redhat2Enterprise Linux Linux KernelJun 17, 2026 Nov 17, 2020 N/A· v4 7.4 HIGH· v3 5.8 MEDIUM· v2 A flaw in ICMP packets in the Linux kernel may allow an attacker to quickly scan open UDP ports. This flaw allows an off-path remote attacker to effectively bypass source port UDP randomization. Software that relies on U...Show more |
konzept-ix publiXone before 2020.015 allows attackers to download files by iterating over the IXCopy fileID parameter. |
1Pam Tacplus Project 1Pam Tacplus Jun 17, 2026 Oct 26, 2020 N/A· v4 9.8 CRITICAL· v3 7.5 HIGH· v2 libtac in pam_tacplus through 1.5.1 lacks a check for a failure of RAND_bytes()/RAND_pseudo_bytes(). This could lead to use of a non-random/predictable session_id. |
Media ContentProvider URIs used for opening attachments in other apps were generated sequentially prior to WhatsApp for Android v2.20.185, which could have allowed a malicious third party app chosen to open the file to g...Show more |
cPanel before 88.0.3, upon an upgrade, establishes predictable PowerDNS API keys (SEC-561). |
In various functions in fscrypt_ice.c and related files in some implementations of f2fs encryption that use encryption hardware which only supports 32-bit IVs (Initialization Vectors), 64-bit IVs are used and later are t...Show more |
A vulnerability was discovered in GitLab versions before 13.1.10, 13.2.8 and 13.3.4. Same 2 factor Authentication secret code was generated which resulted an attacker to maintain access under certain conditions. |
The SRP-6a implementation in Kee Vault KeePassRPC before 1.12.0 generates insufficiently random numbers, which allows remote attackers to read and modify data in the KeePass database via a WebSocket connection. |
7Canonical DebianFedoraproject+4 more15Active Iq Unified Manager Cloud Volumes Ontap MediatorDebian Linux+12 moreJun 17, 2026 Jul 30, 2020 N/A· v4 3.7 LOW· v3 4.3 MEDIUM· v2 The Linux kernel through 5.7.11 allows remote attackers to make observations that help to obtain sensitive information about the internal state of the network RNG, aka CID-f227e3ec3b5c. This is related to drivers/char/ra...Show more |
3Easyrobotics Mobile Industrial RobotsUvd Robots10Er Flex Firmware Er Lite FirmwareEr One Firmware+7 moreJun 17, 2026 Jun 24, 2020 N/A· v4 7.1 HIGH· v3 5.5 MEDIUM· v2 The access tokens for the REST API are directly derived (sha256 and base64 encoding) from the publicly available default credentials from the Control Dashboard (refer to CVE-2020-10270 for related flaws). This flaw in co...Show more |
IBM Security Guardium 10.6 and 11.1 may use insufficiently random numbers or values in a security context that depends on unpredictable numbers. IBM X-Force ID: 174807. |
Convos before 4.20 does not properly generate a random secret in Core/Settings.pm and Util.pm. This leads to a predictable CONVOS_LOCAL_SECRET value, affecting password resets and invitations. |
4Fedoraproject OpensuseOracle+1 more4Enterprise Manager Ops Center FedoraLeap+1 moreJun 17, 2026 Jun 18, 2020 N/A· v4 5.9 MEDIUM· v3 4.3 MEDIUM· v2 Lib/ipaddress.py in Python through 3.8.3 improperly computes hash values in the IPv4Interface and IPv6Interface classes, which might allow a remote attacker to cause a denial of service if an application is affected by t...Show more |
The Treck TCP/IP stack before 6.0.1.66 allows Remote Code execution via a single invalid DNS response. |
A vulnerability based on insecure user/password encryption in the JOE (job editor) component of SOS JobScheduler 1.12 and 1.13 allows attackers to decrypt the user/password that is optionally stored with a user's profile...Show more |
4Fujitsu NetappNtp+1 more25Cloud Backup Clustered Data OntapData Ontap+22 moreJun 17, 2026 Jun 4, 2020 N/A· v4 7.4 HIGH· v3 5.8 MEDIUM· v2 ntpd in ntp before 4.2.8p14 and 4.3.x before 4.3.100 allows remote attackers to cause a denial of service (daemon exit or system time change) by predicting transmit timestamps for use in spoofed packets. The victim must...Show more |
Dell EMC Isilon versions 8.2.2 and earlier contain a remotesupport vulnerability. The pre-configured support account, remotesupport, is bundled in the Dell EMC Isilon OneFS installation. This account is used for diagnost...Show more |
1Netgear 3Rbs50y Firmware Srr60 FirmwareSrs60 FirmwareJun 17, 2026 May 18, 2020 N/A· v4 8.8 HIGH· v3 5.8 MEDIUM· v2 An issue was discovered on NETGEAR Orbi Tri-Band Business WiFi Add-on Satellite (SRS60) AC3000 V2.5.1.106, Outdoor Satellite (RBS50Y) V2.5.1.106, and Pro Tri-Band Business WiFi Router (SRR60) AC3000 V2.5.1.106. The admin...Show more |
Non-reinitialisation of random data in the advertising payload in COVIDSafe v1.0.15 and v1.0.16 allows a remote attacker to re-identify Android devices running COVIDSafe by scanning for their advertising beacons. |
2Pivotal Software Vmware2Spring Security Spring SecurityJun 17, 2026 May 14, 2020 N/A· v4 6.5 MEDIUM· v3 4.0 MEDIUM· v2 Spring Security versions 5.3.x prior to 5.3.2, 5.2.x prior to 5.2.4, 5.1.x prior to 5.1.10, 5.0.x prior to 5.0.16 and 4.2.x prior to 4.2.16 use a fixed null initialization vector with CBC Mode in the implementation of th...Show more |