Vulnerabilities > Use of Insufficiently Random Values

DATE CVE VULNERABILITY TITLE RISK
2019-11-04 CVE-2013-4102 Use of Insufficiently Random Values vulnerability in Cryptocat Project Cryptocat
Cryptocat before 2.0.22 strophe.js Math.random() Random Number Generator Weakness
network
low complexity
cryptocat-project CWE-330
6.4
2019-10-10 CVE-2019-13929 Use of Insufficiently Random Values vulnerability in Siemens Simatic IT Uadm
A vulnerability has been identified in SIMATIC IT UADM (All versions < V1.3).
network
low complexity
siemens CWE-330
4.0
2019-10-08 CVE-2019-17105 Use of Insufficiently Random Values vulnerability in Centreon web
The token generator in index.php in Centreon Web before 2.8.27 is predictable.
network
low complexity
centreon CWE-330
5.0
2019-09-30 CVE-2019-2294 Use of Insufficiently Random Values vulnerability in Qualcomm products
Usage of hard-coded magic number for calculating heap guard bytes can allow users to corrupt heap blocks without heap algorithm knowledge in Snapdragon Auto, Snapdragon Compute, Snapdragon Connectivity, Snapdragon Consumer Electronics Connectivity, Snapdragon Consumer IOT, Snapdragon Industrial IOT, Snapdragon IoT, Snapdragon Mobile, Snapdragon Voice & Music, Snapdragon Wearables in MDM9205, MDM9206, MDM9607, MDM9615, MDM9625, MDM9635M, MDM9655, MSM8909W, MSM8996AU, QCS605, Qualcomm 215, SD 210/SD 212/SD 205, SD 410/12, SD 425, SD 427, SD 430, SD 435, SD 439 / SD 429, SD 450, SD 625, SD 632, SD 636, SD 650/52, SD 665, SD 675, SD 712 / SD 710 / SD 670, SD 730, SD 820, SD 820A, SD 835, SD 845 / SD 850, SD 855, SD 8CX, SDA660, SDM439, SDM630, SDM660, Snapdragon_High_Med_2016, SXR1130
network
low complexity
qualcomm CWE-330
critical
10.0
2019-09-10 CVE-2019-1549 Use of Insufficiently Random Values vulnerability in Openssl
OpenSSL 1.1.1 introduced a rewritten random number generator (RNG).
network
low complexity
openssl CWE-330
5.3
2019-07-19 CVE-2019-12821 Use of Insufficiently Random Values vulnerability in Jisiwei I3 Firmware 2.0
A vulnerability was found in the app 2.0 of the Shenzhen Jisiwei i3 robot vacuum cleaner, while adding a device to the account using a QR-code.
network
high complexity
jisiwei CWE-330
4.8
2019-07-15 CVE-2019-1010025 Use of Insufficiently Random Values vulnerability in GNU Glibc
GNU Libc current is affected by: Mitigation bypass.
network
low complexity
gnu CWE-330
5.3
2019-07-01 CVE-2019-7667 Use of Insufficiently Random Values vulnerability in Primasystems Flexair 2.3.38
Prima Systems FlexAir, Versions 2.3.38 and prior.
network
low complexity
primasystems CWE-330
critical
9.8
2019-06-19 CVE-2018-18425 Use of Insufficiently Random Values vulnerability in Primeo Project Primeo
The doAirdrop function of a smart contract implementation for Primeo (PEO), an Ethereum token, does not check the numerical relationship between the amount of the air drop and the token's total supply, which lets the owner of the contract issue an arbitrary amount of currency.
network
low complexity
primeo-project CWE-330
4.0
2019-05-22 CVE-2019-6821 Use of Insufficiently Random Values vulnerability in Schneider-Electric products
CWE-330: Use of Insufficiently Random Values vulnerability, which could cause the hijacking of the TCP connection when using Ethernet communication in Modicon M580 firmware versions prior to V2.30, and all firmware versions of Modicon M340, Modicon Premium, Modicon Quantum.
network
low complexity
schneider-electric CWE-330
6.4