Vulnerabilities > Use of Cryptographically Weak Pseudo-Random Number Generator (PRNG)

DATE CVE VULNERABILITY TITLE RISK
2021-06-09 CVE-2021-0131 Use of Cryptographically Weak Pseudo-Random Number Generator (PRNG) vulnerability in Intel Secl-Dc
Use of cryptographically weak pseudo-random number generator (PRNG) in an API for the Intel(R) Security Library before version 3.3 may allow an authenticated user to potentially enable information disclosure via network access.
network
low complexity
intel CWE-338
4.0
2021-06-02 CVE-2021-3538 Use of Cryptographically Weak Pseudo-Random Number Generator (PRNG) vulnerability in Satori Uuid
A flaw was found in github.com/satori/go.uuid in versions from commit 0ef6afb2f6cdd6cdaeee3885a95099c63f18fc8c to d91630c8510268e75203009fe7daf2b8e1d60c45.
network
low complexity
satori CWE-338
critical
9.8
2021-05-21 CVE-2008-3280 Use of Cryptographically Weak Pseudo-Random Number Generator (PRNG) vulnerability in Openid
It was found that various OpenID Providers (OPs) had TLS Server Certificates that used weak keys, as a result of the Debian Predictable Random Number Generator (CVE-2008-0166).
network
openid CWE-338
4.3
2021-05-05 CVE-2021-29245 Use of Cryptographically Weak Pseudo-Random Number Generator (PRNG) vulnerability in Btcpayserver Btcpay Server
BTCPay Server through 1.0.7.0 uses a weak method Next to produce pseudo-random values to generate a legacy API key.
network
low complexity
btcpayserver CWE-338
5.0
2021-03-04 CVE-2021-23126 Use of Cryptographically Weak Pseudo-Random Number Generator (PRNG) vulnerability in Joomla Joomla!
An issue was discovered in Joomla! 3.2.0 through 3.9.24.
network
low complexity
joomla CWE-338
5.3
2020-12-31 CVE-2020-35926 Use of Cryptographically Weak Pseudo-Random Number Generator (PRNG) vulnerability in Nanorand Project Nanorand
An issue was discovered in the nanorand crate before 0.5.1 for Rust.
network
low complexity
nanorand-project CWE-338
7.5
2020-11-19 CVE-2020-28924 Use of Cryptographically Weak Pseudo-Random Number Generator (PRNG) vulnerability in multiple products
An issue was discovered in Rclone before 1.53.3.
network
low complexity
rclone fedoraproject CWE-338
7.5
2020-11-16 CVE-2020-28642 Use of Cryptographically Weak Pseudo-Random Number Generator (PRNG) vulnerability in Infinitewp 2.4.2/2.4.3
In InfiniteWP Admin Panel before 3.1.12.3, resetPasswordSendMail generates a weak password-reset code, which makes it easier for remote attackers to conduct admin Account Takeover attacks.
network
low complexity
infinitewp CWE-338
7.5
2020-03-20 CVE-2019-15075 Use of Cryptographically Weak Pseudo-Random Number Generator (PRNG) vulnerability in Inextrix Astpp
An issue was discovered in iNextrix ASTPP before 4.0.1.
network
low complexity
inextrix CWE-338
5.0
2019-12-13 CVE-2019-19794 Use of Cryptographically Weak Pseudo-Random Number Generator (PRNG) vulnerability in Miekg-Dns Project Miekg-Dns
The miekg Go DNS package before 1.1.25, as used in CoreDNS before 1.6.6 and other products, improperly generates random numbers because math/rand is used.
4.3