CWE-203

Observable Discrepancy

Parent: CWE-200 - Exposure of Sensitive Information to an Unauthorized Actor

The product behaves differently or sends different responses under different circumstances in a way that is observable to an unauthorized actor.

733 vulnerabilities with CWE-203
CVE-2023-20583 MEDIUM
AMD Processors - Power Side-Channel Information Disclosure via Cache Line Monitoring
CVSS 4.7
CVE-2023-3462 MEDIUM
HashiCorp Vault < 1.13.5 - User Enumeration via LDAP Auth Method
CVSS 5.3
CVE-2023-37217 MEDIUM
Tadiran Telecom Aeonix - Observable Response Discrepancy
CVSS 5.3
CVE-2023-3897 MEDIUM
SureMDM On-premise <6.31 - Info Disclosure
CVSS 4.8
CVE-2023-3640 HIGH
Linux Kernel - Unauthorized Memory Access via Per-CPU Entry Area Mapping
CVSS 7.0
CVE-2023-34669 HIGH
TOTOLINK CP300+ V5.2cu.7594 - Denial of Service via RebootSystem Function
CVSS 7.5
CVE-2023-20575 MEDIUM
AMD EPYC Firmware - Authenticated Power Side-Channel Information Leak via Power Reporting
CVSS 6.5
CVE-2023-35698 MEDIUM
SICK ICR890-4 Firmware < 2.5.0 - Observable Response Discrepancy via FTP Login
CVSS 5.3
CVE-2023-3529 MEDIUM
Rotem Dynamics Rotem CRM <20230729 - Info Disclosure
CVSS 5.3
CVE-2023-3336 MEDIUM
TN-5900 Series <3.3 - Info Disclosure
CVSS 5.3
CVE-2023-37305 MEDIUM
MediaWiki ProofreadPage Extension < 1.39.3 - Hidden User Data Exposure via Public Interfaces
CVSS 5.3
CVE-2023-22359 MEDIUM
Checkmk <=2.2.0p4 - Info Disclosure
CVSS 4.3
CVE-2023-34878 HIGH
ujcms v6.0.2 - Information Disclosure via Web File HTML Download ZIP Endpoint
CVSS 7.5
CVE-2023-1707 HIGH
HP Enterprise LaserJet/Managed Printers <5.6 - Info Disclosure
CVSS 7.5
CVE-2023-34344 MEDIUM
AMI MegaRAC SP-X 12.0-12.7 - Unauthenticated Username Enumeration via IPMI Handler
CVSS 5.3
CVE-2023-33518 MEDIUM
emoncms v11 and later - Information Disclosure via Crafted Web Request
CVSS 5.3
CVE-2023-25741 MEDIUM
Firefox < 110.0 - Cross-Origin Image Size Leak via Drag-and-Drop
CVSS 6.5
CVE-2023-25728 MEDIUM
Firefox < 110.0 and Firefox ESR < 102.8 - Information Disclosure via CSP Report-Only Header
CVSS 6.5
CVE-2023-33741 HIGH
Macrovideo v380pro <1.4.97 - Info Disclosure
CVSS 7.5
CVE-2023-32342 HIGH
IBM HTTP Server 8.5.0.0-8.5.5.24 - Timing-Based Side Channel Information Disclosure in RSA Decryption
CVSS 7.5
CVE-2023-31186 MEDIUM
Avaya IX Workforce Engagement <15.2.7.1195 - Info Disclosure
CVSS 5.3
CVE-2023-32691 MEDIUM
go_simple_tunnel < 2.11.5 - Timing Side-Channel Attack via HTTP Header Comparison
CVSS 5.9
CVE-2023-24598 MEDIUM
OX App Suite <7.10.6-rev37 - Info Disclosure
CVSS 4.3
CVE-2023-26215 HIGH
TIBCO EBX Add-ons <4.5.16 - Info Disclosure
CVSS 7.7
CVE-2023-32694 MEDIUM
Saleor Core <3.7.67 - Timing Attack
CVSS 4.8
Details
Vulnerabilities 733