CWE-203

Observable Discrepancy

Parent: CWE-200 - Exposure of Sensitive Information to an Unauthorized Actor

The product behaves differently or sends different responses under different circumstances in a way that is observable to an unauthorized actor.

751 vulnerabilities with CWE-203
CVE-2022-20293 MEDIUM
Android 13 - Unauthenticated Local Information Disclosure via LauncherApps Side Channel
CVSS 5.5
CVE-2022-20291 MEDIUM
Android 13 - Unauthenticated App Installation Status Disclosure via AppOpsService Side Channel
CVSS 5.5
CVE-2022-20279 MEDIUM
Android 13 - Unauthenticated Local Information Disclosure via DevicePolicyManager Side Channel
CVSS 5.5
CVE-2022-20277 MEDIUM
Android 13 - Unauthenticated Local Information Disclosure via DevicePolicyManager Side Channel
CVSS 5.5
CVE-2022-20276 MEDIUM
Android 13 - Unauthenticated Local Information Disclosure via DevicePolicyManager Side Channel
CVSS 5.5
CVE-2022-20275 MEDIUM
Android 13 - Unauthenticated Local Information Disclosure via DevicePolicyManager Side Channel
CVSS 5.5
CVE-2022-20252 LOW
Android 13 - Unauthenticated Local Information Disclosure via PackageManager Side Channel
CVSS 3.3
CVE-2022-20251 LOW
Android 13 - Unauthenticated App Presence Disclosure via LocaleManager Side Channel
CVSS 3.3
CVE-2022-20249 LOW
Android 13 - Unauthenticated App Presence Detection via LocaleManager Side Channel
CVSS 3.3
CVE-2022-20242 MEDIUM
Android 13 - Unauthenticated App Presence Detection via Telephony Side Channel
CVSS 5.5
CVE-2022-20866 HIGH
Cisco ASA 9.16.0-9.16.3.19 & FTD 7.0.0-7.0.4 - Unauthenticated RSA Private Key Retrieval via Lenstra Attack
CVSS 7.4
CVE-2022-34704 MEDIUM
Windows Defender Credential Guard - Unauthorized Exposure of Sensitive Information
CVSS 4.7
CVE-2022-24912 HIGH
atlantis < 0.19.7 - Timing Attack via Webhook Secret Validation
CVSS 7.5
CVE-2022-36885 MEDIUM
Jenkins GitHub Plugin < 1.34.4 - Timing Attack via Webhook Signature Comparison
CVSS 5.3
CVE-2022-1146 MEDIUM
Google Chrome < 100.0.4896.60 - Cross-Origin Data Leak via Resource Timing
CVSS 6.5
CVE-2022-1139 MEDIUM
Google Chrome < 100.0.4896.60 - Cross-Origin Data Leak via Background Fetch API
CVSS 6.5
CVE-2022-32425 MEDIUM
Mealie v1.0.0beta-2 - Username Enumeration via Login Timing Discrepancy
CVSS 5.3
CVE-2022-31142 HIGH
@fastify/bearer-auth <7.0.2-8.0.1 - Info Disclosure
CVSS 7.5
CVE-2022-20752 MEDIUM
Cisco Unified Communications Manager 12.5(1) - Observable Timing Discrepancy
CVSS 5.3
CVE-2022-34174 HIGH
Jenkins <2.355-<2.332.3 - Info Disclosure
CVSS 7.5
CVE-2022-24436 MEDIUM
Intel(R) Processors - Info Disclosure
CVSS 6.5
CVE-2022-23823 MEDIUM
AMD Athlon X4/Ryzen Threadripper PRO Firmware Info Disclosure via Timing Attack
CVSS 6.5
CVE-2022-27221 MEDIUM
SINEMA Remote Connect Server < 3.1 - Plaintext Secret Exposure via BREACH Attack
CVSS 5.9
CVE-2022-0823 MEDIUM
Zyxel GS1200 Series Firmware < 2.00 - Timing Side-Channel Password Guessing
CVSS 6.2
CVE-2022-32273 MEDIUM
OPSWAT MetaDefender Core < 5.1.2 - Authenticated Filename Enumeration via Observable Discrepancy
CVSS 4.3
Details
Vulnerabilities 751