Vulnerabilities (CVE)

Filtered by CWE-330
Total 303 CVE
CVE Vendors Products Updated CVSS v2 CVSS v3
CVE-2015-9019 1 Xmlsoft 1 Libxslt 2017-04-11 5.0 MEDIUM 5.3 MEDIUM
In libxslt 1.1.29 and earlier, the EXSLT math.random function was not initialized with a random seed during startup, which could cause usage of this function to produce predictable outputs.
CVE-2016-5100 1 Froxlor 1 Froxlor 2017-02-24 5.0 MEDIUM 9.8 CRITICAL
Froxlor before 0.9.35 uses the PHP rand function for random number generation, which makes it easier for remote attackers to guess the password reset token by predicting a value.
CVE-2016-5085 1 Animas 2 Onetouch Ping, Onetouch Ping Firmware 2016-12-24 7.8 HIGH 7.5 HIGH
Johnson & Johnson Animas OneTouch Ping devices do not properly generate random numbers, which makes it easier for remote attackers to spoof meters by sniffing the network and then engaging in an authentication handshake.