Browse and filter security vulnerabilities across ecosystems
Browse and filter security vulnerabilities across ecosystems
Dancer2 versions through 2.1.0 for Perl generate insecure session ids when required CSPRNG modules are unavailable
An issue was discovered in cyrus-imapd in Cyrus IMAP through 3
CGI::Session::ID::md5 versions before 4.49 for Perl generate predictable session ids from low-entropy sources
Setracker2 Children's Smartwatch Ecosystem Generation of Predictable Numbers or Identifiers
Account Takeover via Predictable SSO Ticket Generation
Mojolicious::Plugin::Web::Auth::OAuth2 versions through 0.17 for Perl have an insecure default state parameter
Mojolicious::Sessions::Storable versions through 0.05 for Perl generate session ids insecurely
Naxclow IoT Platform Generation of Predictable Numbers or Identifiers
Netty: DNS Cache Poisoning due to Predictable PRNG and Default Static Source Port
Apache::Session::Generate::SHA256 versions before 1.3.19 for Perl create insecure session ids
WebDyne::Session versions through 2.075 for Perl generates the session id insecurely
Apache::Session::Generate::ModUniqueId versions from 1.54 through 1.94 for Perl session ids are insecure
Dancer::Session::Abstract versions through 1.3522 for Perl generates session ids insecurely
FreeScout has Predictable Attachment Token that Allows Unauthenticated Private File Download via Brute Force
Solstice::Session versions through 1440 for Perl generates session ids insecurely
Ado::Sessions versions through 0.935 for Perl generates insecure session ids
Amon2::Plugin::Web::CSRFDefender versions from 7.00 through 7.03 for Perl generate an insecure session id
Predictable DNS Transaction IDs Enable Cache Poisoning in Built-in Resolver
Multiple Vulnerabilities in IBM Concert Software
HTTP::Session versions before 0.54 for Perl defaults to using insecurely generated session ids
Showing 1 - 20 of 1,000+ results