Vulnerabilities > Use of Insufficiently Random Values

DATE CVE VULNERABILITY TITLE RISK
2020-01-16 CVE-2019-18282 Use of Insufficiently Random Values vulnerability in multiple products
The flow_dissector feature in the Linux kernel 4.3 through 5.x before 5.3.10 has a device tracking vulnerability, aka CID-55667441c84f.
network
low complexity
linux debian netapp CWE-330
5.3
2020-01-15 CVE-2012-1562 Use of Insufficiently Random Values vulnerability in Joomla Joomla!
Joomla! core before 2.5.3 allows unauthorized password change.
network
low complexity
joomla CWE-330
7.5
2020-01-14 CVE-2020-0644 Use of Insufficiently Random Values vulnerability in Microsoft products
An elevation of privilege vulnerability exists when Microsoft Windows implements predictable memory section names, aka 'Windows Elevation of Privilege Vulnerability'.
local
low complexity
microsoft CWE-330
7.8
2019-12-06 CVE-2019-16674 Use of Insufficiently Random Values vulnerability in Weidmueller products
An issue was discovered on Weidmueller IE-SW-VL05M 3.6.6 Build 16102415, IE-SW-VL08MT 3.5.2 Build 16102415, and IE-SW-PL10M 3.3.16 Build 16102416 devices.
network
low complexity
weidmueller CWE-330
critical
9.8
2019-11-29 CVE-2019-5232 Use of Insufficiently Random Values vulnerability in Huawei Vp9630 Firmware, Vp9650 Firmware and Vp9660 Firmware
There is a use of insufficiently random values vulnerability in Huawei ViewPoint products.
network
low complexity
huawei CWE-330
7.5
2019-11-27 CVE-2016-4980 Use of Insufficiently Random Values vulnerability in multiple products
A password generation weakness exists in xquest through 2016-06-13.
local
high complexity
ethz fedoraproject redhat CWE-330
2.5
2019-11-22 CVE-2014-6311 Use of Insufficiently Random Values vulnerability in multiple products
generate_doygen.pl in ace before 6.2.7+dfsg-2 creates predictable file names in the /tmp directory which allows attackers to gain elevated privileges.
network
low complexity
vanderbilt debian CWE-330
critical
9.8
2019-11-09 CVE-2019-4411 Use of Insufficiently Random Values vulnerability in IBM Cognos Controller
IBM Cognos Controller 10.3.0, 10.3.1, 10.4.0, and 10.4.1 could allow an authenticated user to obtain sensitive information due to easy to guess session identifier names.
network
low complexity
ibm CWE-330
4.3
2019-11-08 CVE-2019-16205 Use of Insufficiently Random Values vulnerability in Broadcom Brocade Sannav 1.1.0/1.1.1
A vulnerability, in Brocade SANnav versions before v2.0, could allow remote attackers to brute-force a valid session ID.
network
low complexity
broadcom CWE-330
8.8
2019-11-04 CVE-2010-3666 Use of Insufficiently Random Values vulnerability in Typo3
TYPO3 before 4.1.14, 4.2.x before 4.2.13, 4.3.x before 4.3.4 and 4.4.x before 4.4.1 contains insecure randomness in the uniqid function.
network
low complexity
typo3 CWE-330
5.3