CWE-203

Observable Discrepancy

Parent: CWE-200 - Exposure of Sensitive Information to an Unauthorized Actor

The product behaves differently or sends different responses under different circumstances in a way that is observable to an unauthorized actor.

751 vulnerabilities with CWE-203
CVE-2023-50781 HIGH
Red Hat Enterprise Linux - Observable Discrepancy in RSA Key Exchange
CVSS 7.5
CVE-2023-6240 MEDIUM
Linux Kernel - RSA Decryption Side-Channel Information Disclosure via Marvin Attack
CVSS 6.5
CVE-2023-5992 MEDIUM
OpenSC < 0.25.0 - Side-Channel Information Disclosure via PKCS#1 Padding Removal
CVSS 5.6
CVE-2023-6258 HIGH
pkcs11-provider - Bleichenbacher-like Side-Channel Attack on PKCS#1 1.5 Decryption
CVSS 8.1
CVE-2023-52323 MEDIUM
PyCryptodome and PyCryptodomeX < 3.19.1 - Side-Channel Leakage for OAEP Decryption
CVSS 5.9
CVE-2023-46739 MEDIUM
CubeFS < 3.3.1 - Timing Attack via UserService Password Comparison
CVSS 6.5
CVE-2023-50708 MEDIUM
yii2-authclient < 2.2.15 - Timing Attack via OAuth State and OpenID Connect Nonce Comparison
CVSS 6.1
CVE-2023-41097 MEDIUM
Silabs Gecko Software Development Kit < 4.4.0 - Observable Timing Discrepancy in CBC PKCS7 Padding
CVSS 4.6
CVE-2023-6135 MEDIUM
Firefox < 121.0 - Side-Channel Attack via Minerva on NSS NIST Curves
CVSS 4.3
CVE-2023-23584 MEDIUM
Gallagher Command Centre < 8.50 - Information Disclosure via RESTAPI Response Discrepancy
CVSS 4.3
CVE-2023-50979 MEDIUM
Crypto++ < 8.9.0 - Marvin Side Channel via PKCS#1 v1.5 Padding
CVSS 5.9
CVE-2023-4421 MEDIUM
NSS < 3.61 - Timing Side-Channel Attack via PKCS#1 v1.5 Padding Check
CVSS 6.5
CVE-2023-45287 HIGH
GO < 1.20.0 - Information Disclosure
CVSS 7.5
CVE-2023-40090 MEDIUM
Android - Remote Privilege Escalation via BTM_BleVerifySignature Side Channel
CVSS 6.5
CVE-2023-49092 MEDIUM
RustCrypto RSA - Covert Timing Channel via Non-Constant-Time Implementation
CVSS 5.9
CVE-2023-5981 MEDIUM
GnuTLS - Timing Side-Channel in RSA-PSK ClientKeyExchange
CVSS 5.9
CVE-2023-47102 MEDIUM
UrBackup Server 2.5.31 - User Enumeration via Login Failure Message
CVSS 5.3
CVE-2023-21354 MEDIUM
Android - Local Information Disclosure via Package Manager Service Side Channel
CVSS 5.5
CVE-2023-21350 MEDIUM
Android - Local Information Disclosure via Media Projection Side Channel
CVSS 5.5
CVE-2023-21349 LOW
Android < 14.0 - Unauthenticated App Installation Status Disclosure via Package Manager Side Channel
CVSS 3.3
CVE-2023-21348 LOW
Android < 14.0 - Unauthenticated App Presence Detection via Window Manager Side Channel
CVSS 3.3
CVE-2023-21346 LOW
Android < 14.0 - Unauthenticated App Installation Detection via Device Idle Controller Side Channel
CVSS 3.3
CVE-2023-21345 LOW
Android < 14.0 - Unauthenticated Local Information Disclosure via Game Manager Service
CVSS 3.3
CVE-2023-21344 MEDIUM
Android < 14.0 - Unauthenticated App Presence Detection via Job Scheduler Side Channel
CVSS 5.5
CVE-2023-21338 MEDIUM
Android < 14.0 - Local Escalation of Privilege via Input Method Side Channel
CVSS 5.5
Details
Vulnerabilities 751