CWE-203

Observable Discrepancy

Parent: CWE-200 - Exposure of Sensitive Information to an Unauthorized Actor

The product behaves differently or sends different responses under different circumstances in a way that is observable to an unauthorized actor.

751 vulnerabilities with CWE-203
CVE-2023-28770 HIGH
Zyxel DX5401-B0 <V5.17(ABYO.1)C0 - Info Disclosure
CVSS 7.5
CVE-2023-26560 MEDIUM
Northern.tech CFEngine Enterprise <3.21.1 - Info Disclosure
CVSS 6.5
CVE-2023-30458 MEDIUM
Medicine Tracker System 1.0 - Username Enumeration via Login Response Time Discrepancy
CVSS 5.3
CVE-2023-26557 HIGH
io.finnet tss-lib <2.0.0 - Info Disclosure
CVSS 7.5
CVE-2023-26556 CRITICAL
io.finnet tss-lib <2.0.0 - Info Disclosure
CVSS 9.1
CVE-2023-1998 MEDIUM
Linux Kernel < 6.3 - Microarchitectural Resource Sharing via IBRS STIBP Bypass
CVSS 5.6
CVE-2023-29850 HIGH
SENAYAN Library Management System Bulian v9.5.2 - Information Exposure via EXIF Metadata in Uploaded Images
CVSS 7.5
CVE-2023-27464 MEDIUM
Mendix Forgot Password < 3.7.1 - Information Disclosure via Observable Response Discrepancy
CVSS 5.3
CVE-2023-28840 HIGH
Moby 1.12.0-20.10.24 - Denial of Service via VXLAN Packet Injection
CVSS 7.5
CVE-2023-25000 MEDIUM
HashiCorp Vault <1.13.1-1.12.5-1.11.9 - Info Disclosure
CVSS 5.0
CVE-2023-26071 HIGH
MCUBO ICT <10.12.4 - Info Disclosure
CVSS 7.5
CVE-2023-1540 MEDIUM
answerdev/answer <1.0.6 - Info Disclosure
CVSS 5.3
CVE-2023-1538 MEDIUM
answerdev/answer <1.0.6 - Info Disclosure
CVSS 5.3
CVE-2023-25806 MEDIUM
OpenSearch Security - Info Disclosure
CVSS 5.3
CVE-2023-0361 HIGH
GnuTLS - Timing Side-Channel in RSA ClientKeyExchange Handling
CVSS 7.4
CVE-2023-0440 MEDIUM
healthchecks < 2.6 - Observable Discrepancy
CVSS 5.3
CVE-2022-50800 HIGH
H3C SSL VPN 1.1 - User Enumeration via Login Script Credential Verification
CVSS 7.5
CVE-2022-48730 MEDIUM
Linux Kernel 5.6-5.10.99 5.11-5.15.22 5.16-5.16.8 - Information Leak via Spectre v1 Gadget in DMA-BUF Heaps
CVSS 5.5
CVE-2022-45177 HIGH
LIVEBOX Collaboration vDesk <= v031 - Observable Response Discrepancy in User Enable and Shared Search Endpoints
CVSS 7.5
CVE-2022-48220 MEDIUM
HP Elite and EliteDesk G8/G9 Firmware - Intrusion Detection Bypass via Physical TamperLock Attack
CVSS 6.4
CVE-2022-20264 MEDIUM
Usage Stats Service - Info Disclosure
CVSS 5.5
CVE-2022-25332 MEDIUM
Texas Instruments OMAP L138 - Timing Side Channel
CVSS 4.4
CVE-2022-46724 LOW
iPadOS < 16.4 - Unprotected User Data Exposure via Lock Screen Magnifier
CVSS 2.4
CVE-2022-40982 MEDIUM
Intel(R) Processors - Info Disclosure
CVSS 6.5
CVE-2022-42792 MEDIUM
iPadOS < 16.0 and iPhone OS < 16.1 - Unauthorized Sensitive Location Information Access
CVSS 5.5
Details
Vulnerabilities 751