CWE-203

Observable Discrepancy

Parent: CWE-200 - Exposure of Sensitive Information to an Unauthorized Actor

The product behaves differently or sends different responses under different circumstances in a way that is observable to an unauthorized actor.

751 vulnerabilities with CWE-203
CVE-2023-35698 MEDIUM
SICK ICR890-4 Firmware < 2.5.0 - Observable Response Discrepancy via FTP Login
CVSS 5.3
CVE-2023-3529 MEDIUM
Rotem Dynamics Rotem CRM <20230729 - Info Disclosure
CVSS 5.3
CVE-2023-3336 MEDIUM
TN-5900 Series <3.3 - Info Disclosure
CVSS 5.3
CVE-2023-37305 MEDIUM
MediaWiki ProofreadPage Extension < 1.39.3 - Hidden User Data Exposure via Public Interfaces
CVSS 5.3
CVE-2023-22359 MEDIUM
Checkmk <=2.2.0p4 - Info Disclosure
CVSS 4.3
CVE-2023-34878 HIGH
ujcms v6.0.2 - Information Disclosure via Web File HTML Download ZIP Endpoint
CVSS 7.5
CVE-2023-1707 HIGH
HP Enterprise LaserJet/Managed Printers <5.6 - Info Disclosure
CVSS 7.5
CVE-2023-34344 MEDIUM
AMI MegaRAC SP-X 12.0-12.7 - Unauthenticated Username Enumeration via IPMI Handler
CVSS 5.3
CVE-2023-33518 MEDIUM
emoncms v11 and later - Information Disclosure via Crafted Web Request
CVSS 5.3
CVE-2023-25741 MEDIUM
Firefox < 110.0 - Cross-Origin Image Size Leak via Drag-and-Drop
CVSS 6.5
CVE-2023-25728 MEDIUM
Firefox < 110.0 and Firefox ESR < 102.8 - Information Disclosure via CSP Report-Only Header
CVSS 6.5
CVE-2023-33741 HIGH
Macrovideo v380pro <1.4.97 - Info Disclosure
CVSS 7.5
CVE-2023-32342 HIGH
IBM HTTP Server 8.5.0.0-8.5.5.24 - Timing-Based Side Channel Information Disclosure in RSA Decryption
CVSS 7.5
CVE-2023-31186 MEDIUM
Avaya IX Workforce Engagement <15.2.7.1195 - Info Disclosure
CVSS 5.3
CVE-2023-32691 MEDIUM
go_simple_tunnel < 2.11.5 - Timing Side-Channel Attack via HTTP Header Comparison
CVSS 5.9
CVE-2023-24598 MEDIUM
OX App Suite <7.10.6-rev37 - Info Disclosure
CVSS 4.3
CVE-2023-26215 HIGH
TIBCO EBX Add-ons <4.5.16 - Info Disclosure
CVSS 7.7
CVE-2023-32694 MEDIUM
Saleor Core <3.7.67 - Timing Attack
CVSS 4.8
CVE-2023-28015 MEDIUM
HCL Domino AppDev Pack < 1.0.16 - User Account Enumeration via Login Error Messages
CVSS 5.3
CVE-2023-28412 MEDIUM
Snapone Orvc < 7.3.0 - Information Disclosure
CVSS 5.3
CVE-2023-1696 HIGH
Huawei EMUI and HarmonyOS - Denial of Service in Multimedia Video Module
CVSS 7.5
CVE-2023-23449 MEDIUM
SICK FTMg AIR FLOW SENSOR Firmware < 2.0 - Observable Response Discrepancy via REST Interface
CVSS 5.3
CVE-2023-27870 MEDIUM
IBM Spectrum Virtualize 8.5 - Sensitive Credential Exposure During Fix Central Download
CVSS 5.9
CVE-2023-28200 MEDIUM
iPadOS < 15.7.4 - Kernel Memory Disclosure via Input Validation Issue
CVSS 5.5
CVE-2023-27931 MEDIUM
iPadOS < 16.4 - Unauthorized User-Sensitive Data Access
CVSS 5.5
Details
Vulnerabilities 751