cbcvebase.
CVE-2016-1902
published 2016-06-01

CVE-2016-1902: The nextBytes function in the SecureRandom class in Symfony before 2.3.37, 2.6.x before 2.6.13, and 2.7.x before 2.7.9 does not properly generate random…

PriorityP339high7.5CVSS 3.0
AVNACLPRNUINSUCHINAN
EPSS
1.91%
77.4th percentile
The nextBytes function in the SecureRandom class in Symfony before 2.3.37, 2.6.x before 2.6.13, and 2.7.x before 2.7.9 does not properly generate random numbers when used with PHP 5.x without the paragonie/random_compat library and the openssl_random_pseudo_bytes function fails, which makes it easier for attackers to defeat cryptographic protection mechanisms via unspecified vectors.

Affected

37 ranges· showing 25
VendorProductVersion rangeFixed in
debiandebian_linux
debiansymfony< symfony 2.7.9+dfsg-1 (bookworm)symfony 2.7.9+dfsg-1 (bookworm)
sensiolabssymfony<= 2.3.36
sensiolabssymfony
sensiolabssymfony
sensiolabssymfony
sensiolabssymfony
sensiolabssymfony
sensiolabssymfony
sensiolabssymfony
sensiolabssymfony
sensiolabssymfony
sensiolabssymfony
sensiolabssymfony
sensiolabssymfony
sensiolabssymfony
sensiolabssymfony
sensiolabssymfony
sensiolabssymfony
sensiolabssymfony
sensiolabssymfony
sensiolabssymfony
sensiolabssymfony
sensiolabssymfony
sensiolabssymfony

CVSS provenance

nvdv3.07.5HIGHCVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N
nvdv2.05.0MEDIUMAV:N/AC:L/Au:N/C:P/I:N/A:N
osv7.5HIGH
vendor_debian7.5HIGH
Stop checking back — get the weekly exploitation signal.

Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.