Auto-created placeholder
Volume of CVEs assigned to CWE-361 and their average CVSS base score over time.
Top CVEs that have been assigned this CWE. A single CVE can have multiple CWE assignments, though many have just one.
7 CVEs · Highest risk first
| CVE | Published | CVSS | Risk | KEV | Exploit |
|---|---|---|---|---|---|
CVE-2016-7547CRITICAL A command execution flaw on the Trend Micro Threat Discovery Appliance 2.6.1062r1 exists with the timezone parameter in the admin_sys_time.cgi interface. | Apr 12, 2017 | 9.8 | 86 | NO | YES |
CVE-2016-1643HIGH The ImageInputType::ensurePrimaryContent function in WebKit/Source/core/html/forms/ImageInputType.cpp in Blink, as used in Google Chrome before 49.0.2623.87, does not properly main | Mar 13, 2016 | 8.8 | 26 | NO | NO |
CVE-2016-7036CRITICAL python-jose before 1.3.2 allows attackers to have unspecified impact by leveraging failure to use a constant time comparison for HMAC keys. | Jan 23, 2017 | 9.8 | 24 | NO | NO |
CVE-2015-5300HIGH The panic_gate check in NTP before 4.2.8p5 is only re-enabled after the first change to the system clock that was greater than 128 milliseconds by default, which allows remote atta | Jul 21, 2017 | 7.5 | 22 | NO | NO |
CVE-2016-1000345MEDIUM In the Bouncy Castle JCE Provider version 1.55 and earlier the DHIES/ECIES CBC mode vulnerable to padding oracle attack. For BC 1.55 and older, in an environment where timings can | Jun 4, 2018 | 5.9 | 21 | NO | NO |
CVE-2016-1000341MEDIUM In the Bouncy Castle JCE Provider version 1.55 and earlier DSA signature generation is vulnerable to timing attack. Where timings can be closely observed for the generation of sign | Jun 4, 2018 | 5.9 | 21 | NO | NO |
CVE-2016-7037HIGH The verify function in Encryption/Symmetric.php in Malcolm Fell jwt before 1.0.3 does not use a timing-safe function for hash comparison, which allows attackers to spoof signatures | Jan 23, 2017 | 7.5 | 19 | NO | NO |
Exploit activity across CVEs assigned to this CWE, including CVEs that carry other CWE assignments.
Social posts that mention CVE IDs assigned to this CWE. This is assigned-CVE activity, not mentions of the CWE label itself.
Media articles that mention CVE IDs assigned to this CWE. This is assigned-CVE coverage, not mentions of the CWE label itself.