CWE-203
Observable Discrepancy
The product behaves differently or sends different responses under different circumstances in a way that is observable to an unauthorized actor.
733 vulnerabilities with CWE-203
CVE-2022-45403
MEDIUM
Firefox < 107.0, Firefox ESR < 102.5, Thunderbird < 102.5 - Information Disclosure via Cross-Origin Media Timing
CVSS 6.5
CVE-2022-34477
HIGH
Firefox < 102.0 - Cross-Site Leak via MediaError Message Inconsistency
CVSS 7.5
CVE-2022-31742
MEDIUM
Firefox < 101 and Firefox ESR < 91.10 - Cross-Origin Account Linking via WebAuthn Timing Attack
CVSS 6.5
CVE-2022-26382
MEDIUM
Firefox < 98.0 - Information Disclosure via Autofill Tooltip Font Rendering
CVSS 4.3
CVE-2022-20559
LOW
Android 13 - Local Information Disclosure via Permission Revocation Side Channel
CVSS 3.3
CVE-2022-20538
MEDIUM
Android 13 - Local Information Disclosure via Side Channel in RoleService
CVSS 5.5
CVE-2022-20535
LOW
Android 13 - Unauthenticated Local Information Disclosure via WifiManager Side Channel
CVSS 3.3
CVE-2022-46392
MEDIUM
Mbed TLS <2.28.2, <3.3.0 - Info Disclosure
CVSS 5.3
CVE-2022-3907
HIGH
Clerk WordPress Plugin < 4.0.0 - Timing Attack via API Key Validation
CVSS 7.5
CVE-2022-4087
LOW
iPXE < 2022-11-08 - Information Exposure via TLS Ciphertext Padding Length
CVSS 2.6
CVE-2022-45163
MEDIUM
NXP i.MX Firmware - Information Disclosure via Serial Download Protocol
CVSS 5.3
CVE-2022-41914
LOW
Zulip Server 5.0-5.6 - SCIM Bearer Token Timing Side-Channel Exposure
CVSS 3.7
CVE-2022-20940
MEDIUM
Cisco Firepower Threat Defense 6.2.3 - Unauthenticated Information Disclosure via TLS Bleichenbacher Attack
CVSS 5.3
CVE-2022-40084
MEDIUM
opencrx < 5.2.2 - User Enumeration via Password Reset Error Message Discrepancy
CVSS 5.3
CVE-2022-43412
MEDIUM
Jenkins Generic Webhook Trigger Plugin <1.84.1 - Info Disclosure
CVSS 5.3
CVE-2022-43411
MEDIUM
Jenkins GitLab Plugin <1.5.35 - Info Disclosure
CVSS 5.3
CVE-2022-2891
MEDIUM
WP 2FA <2.3.0 - Info Disclosure
CVSS 5.9
CVE-2022-40895
CRITICAL
NeDi <= 1.0.7 - Unauthenticated User Enumeration via Forgot Password Utility
CVSS 9.1
CVE-2022-35888
MEDIUM
Ampere Altra/Ampere Altra Max <2022-07-15 - Info Disclosure
CVSS 6.5
CVE-2022-32218
MEDIUM
Rocket.Chat < 4.7.5 - Message ID Enumeration via Regex MongoDB Queries
CVSS 4.3
CVE-2022-36105
MEDIUM
TYPO3 7.0.0-7.6.57, 10.0.0-10.4.31 - User Enumeration via Authentication Timing Discrepancy
CVSS 5.3
CVE-2022-37146
MEDIUM
PlexTrac < 1.28.0 - Unauthenticated Username Enumeration via Login Response Timing
CVSS 5.3
CVE-2022-1989
MEDIUM
CODESYS Visualization <V4.2.0.0 - Info Disclosure
CVSS 5.3
CVE-2022-37459
HIGH
Ampere Altra and Altra Max Firmware - Return Address Prediction Hijack via Retbleed Side-Channel
CVSS 7.8
CVE-2022-2612
MEDIUM
Google Chrome <104.0.5112.79 - Info Disclosure
CVSS 6.5
Details
Vulnerabilities
733