Threats Tagged 'cwe-329'
View all threats tagged with 'cwe-329'. Filter and sort to focus on specific types of threats.
Stop chasing alerts. Route them.
Start free, then upgrade once to turn Radar into an automated delivery engine for your security stack.
Custom feeds / Automations: email, Slack, webhooks, SIEM/MISP / API access (baseline limits)
API access activates after upgrading in Console -> Billing.
Check if your credentials are on the dark web
Instant breach scanning across billions of leaked records. Free tier available.
Filter Threats
Narrow down the results by type, severity, or affected countries
Threats Tagged 'cwe-329'
Click on any threat for detailed analysis and mitigation recommendations
0 CVE-2026-47842 is a vulnerability in Spring Security where applications using AesBytesEncryptor with certain constructors or null IV generators and CBC mode encrypt data with AES/CBC using a null (all-zero) initialization vector. This affects multiple versions of Spring Security including 5.7.0 through 7.1.0. The vulnerability has a CVSS score of 6.5, indicating medium severity. No official patch or remediation guidance is currently provided by the vendor. Join the discussion | CVE Database V5 | 08/26/2026, 19:22:23 UTC Added: 08/26/2026, 19:37:50 UTC |
0 Minosoft is an open-source, multi-version Minecraft Java Edition client written in Kotlin. Starting in commit f1ae30e2b046a490026a8413b075685deb795122, the CryptManager encryption routine ( CryptManager.kt ) initializes its AES cipher using an initialization vector (IV) that is set equal to the secret key rather than to a sufficiently random value. Because the IV is not random and is derived directly from the key, the encryption is vulnerable to chosen-ciphertext/chosen-plaintext attacks: an attacker who can submit specific messages for encryption can recover the secret key. This affects all versions supporting Minecraft protocol 1.7 and later. No patched version is available, and no known workarounds are available. Join the discussion | CVE Database V5 | 07/06/2026, 23:17:54 UTC Added: 07/06/2026, 23:37:01 UTC |
0 Crypt::CBC versions between 1.21 and 3.05 for Perl may use the rand() function as the default source of entropy, which is not cryptographically secure, for cryptographic functions. This issue affects operating systems where "/dev/urandom'" is unavailable. In that case, Crypt::CBC will fallback to use the insecure rand() function. Join the discussion | CVE Database V5 | 04/12/2025, 23:41:48 UTC Added: 06/14/2025, 20:19:29 UTC |
Showing 1 to 3 of 3 results