CWE-203

Observable Discrepancy

Parent: CWE-200 - Exposure of Sensitive Information to an Unauthorized Actor

The product behaves differently or sends different responses under different circumstances in a way that is observable to an unauthorized actor.

733 vulnerabilities with CWE-203
CVE-2022-45177 HIGH
LIVEBOX Collaboration vDesk <= v031 - Observable Response Discrepancy in User Enable and Shared Search Endpoints
CVSS 7.5
CVE-2022-48220 MEDIUM
HP Elite and EliteDesk G8/G9 Firmware - Intrusion Detection Bypass via Physical TamperLock Attack
CVSS 6.4
CVE-2022-20264 MEDIUM
Usage Stats Service - Info Disclosure
CVSS 5.5
CVE-2022-25332 MEDIUM
Texas Instruments OMAP L138 - Timing Side Channel
CVSS 4.4
CVE-2022-46724 LOW
iPadOS < 16.4 - Unprotected User Data Exposure via Lock Screen Magnifier
CVSS 2.4
CVE-2022-40982 MEDIUM
Intel(R) Processors - Info Disclosure
CVSS 6.5
CVE-2022-42792 MEDIUM
iPadOS < 16.0 and iPhone OS < 16.1 - Unauthorized Sensitive Location Information Access
CVSS 5.5
CVE-2022-24695 MEDIUM
Bluetooth Core Specification <5.3 - Info Disclosure
CVSS 4.3
CVE-2022-40482 MEDIUM
Laravel Framework 8.0.0-8.83.24 - User Enumeration via Timing Attack
CVSS 5.3
CVE-2022-34125 MEDIUM
GLPI CMDB < 3.0.3 - Unauthenticated Sensitive Information Exposure via File Parameter
CVSS 6.5
CVE-2022-41354 MEDIUM
Argo CD < 2.4.28 and 2.5.0-2.5.16 - Unauthenticated Application Enumeration
CVSS 4.3
CVE-2022-39228 MEDIUM
vantage6 3.3.3-3.7.9 - User Enumeration via Login Response Timing
CVSS 5.3
CVE-2022-4304 MEDIUM
OpenSSL - Timing Side-Channel Attack in RSA Decryption
CVSS 5.9
CVE-2022-3143 HIGH
Wildfly-elytron < 1.15.15.Final - Timing Attack via Unsafe Comparator
CVSS 7.4
CVE-2022-42288 MEDIUM
NVIDIA DGX A100 Firmware < 00.19.07 - Unauthenticated Username Enumeration via IPMI Handler Timing Discrepancy
CVSS 5.3
CVE-2022-4499 HIGH
TP-Link Archer C5 and WR710N-V1 - Timing Side-Channel Attack via strcmp Credential Check
CVSS 7.5
CVE-2022-4543 MEDIUM
Linux Kernel - KASLR Base Leak via EntryBleed TLB Prefetch Side-Channel
CVSS 5.5
CVE-2022-30332 MEDIUM
Talend Administration Center 7.3.1.20200219 - Account Enumeration via Forgot Password Error Messages
CVSS 5.3
CVE-2022-48251 HIGH
ARM Cortex-A Firmware - Side-Channel Information Disclosure via AES Instructions
CVSS 7.5
CVE-2022-4025 MEDIUM
Google Chrome < 98.0.4758.80 - Cross-Origin Data Leak via Paint Implementation
CVSS 4.3
CVE-2022-47952 LOW
lxc < 5.0.1 - Information Disclosure via lxc-user-nic Error Messages
CVSS 3.3
CVE-2022-4823 LOW
InSTEDD Nuntium - Timing Discrepancy
CVSS 3.1
CVE-2022-41765 MEDIUM
MediaWiki <1.35.8-1.38.3 - Info Disclosure
CVSS 5.3
CVE-2022-44381 MEDIUM
Snipe-IT < 6.0.14 - User Enumeration via Password Reset Request
CVSS 5.3
CVE-2022-45416 MEDIUM
Firefox < 107.0 and Firefox ESR < 102.5 - Keyboard Event Timing Side-Channel
CVSS 6.5
Details
Vulnerabilities 733