CWE-203

Observable Discrepancy

Parent: CWE-200 - Exposure of Sensitive Information to an Unauthorized Actor

The product behaves differently or sends different responses under different circumstances in a way that is observable to an unauthorized actor.

733 vulnerabilities with CWE-203
CVE-2023-28015 MEDIUM
HCL Domino AppDev Pack < 1.0.16 - User Account Enumeration via Login Error Messages
CVSS 5.3
CVE-2023-28412 MEDIUM
Snapone Orvc < 7.3.0 - Information Disclosure
CVSS 5.3
CVE-2023-1696 HIGH
Huawei EMUI and HarmonyOS - Denial of Service in Multimedia Video Module
CVSS 7.5
CVE-2023-23449 MEDIUM
SICK FTMg AIR FLOW SENSOR Firmware < 2.0 - Observable Response Discrepancy via REST Interface
CVSS 5.3
CVE-2023-27870 MEDIUM
IBM Spectrum Virtualize 8.5 - Sensitive Credential Exposure During Fix Central Download
CVSS 5.9
CVE-2023-28200 MEDIUM
iPadOS < 15.7.4 - Kernel Memory Disclosure via Input Validation Issue
CVSS 5.5
CVE-2023-27931 MEDIUM
iPadOS < 16.4 - Unauthorized User-Sensitive Data Access
CVSS 5.5
CVE-2023-28770 HIGH
Zyxel DX5401-B0 <V5.17(ABYO.1)C0 - Info Disclosure
CVSS 7.5
CVE-2023-26560 MEDIUM
Northern.tech CFEngine Enterprise <3.21.1 - Info Disclosure
CVSS 6.5
CVE-2023-30458 MEDIUM
Medicine Tracker System 1.0 - Username Enumeration via Login Response Time Discrepancy
CVSS 5.3
CVE-2023-26557 HIGH
io.finnet tss-lib <2.0.0 - Info Disclosure
CVSS 7.5
CVE-2023-26556 CRITICAL
io.finnet tss-lib <2.0.0 - Info Disclosure
CVSS 9.1
CVE-2023-1998 MEDIUM
Linux Kernel < 6.3 - Microarchitectural Resource Sharing via IBRS STIBP Bypass
CVSS 5.6
CVE-2023-29850 HIGH
SENAYAN Library Management System Bulian v9.5.2 - Information Exposure via EXIF Metadata in Uploaded Images
CVSS 7.5
CVE-2023-27464 MEDIUM
Mendix Forgot Password < 3.7.1 - Information Disclosure via Observable Response Discrepancy
CVSS 5.3
CVE-2023-28840 HIGH
Moby 1.12.0-20.10.24 - Denial of Service via VXLAN Packet Injection
CVSS 7.5
CVE-2023-25000 MEDIUM
HashiCorp Vault <1.13.1-1.12.5-1.11.9 - Info Disclosure
CVSS 5.0
CVE-2023-26071 HIGH
MCUBO ICT <10.12.4 - Info Disclosure
CVSS 7.5
CVE-2023-1540 MEDIUM
answerdev/answer <1.0.6 - Info Disclosure
CVSS 5.3
CVE-2023-1538 MEDIUM
answerdev/answer <1.0.6 - Info Disclosure
CVSS 5.3
CVE-2023-25806 MEDIUM
OpenSearch Security - Info Disclosure
CVSS 5.3
CVE-2023-0361 HIGH
GnuTLS - Timing Side-Channel in RSA ClientKeyExchange Handling
CVSS 7.4
CVE-2023-0440 MEDIUM
healthchecks < 2.6 - Observable Discrepancy
CVSS 5.3
CVE-2022-50800 HIGH
H3C SSL VPN 1.1 - User Enumeration via Login Script Credential Verification
CVSS 7.5
CVE-2022-48730 MEDIUM
Linux Kernel 5.6-5.10.99 5.11-5.15.22 5.16-5.16.8 - Information Leak via Spectre v1 Gadget in DMA-BUF Heaps
CVSS 5.5
Details
Vulnerabilities 733