CWE-203

Observable Discrepancy

Parent: CWE-200 - Exposure of Sensitive Information to an Unauthorized Actor

The product behaves differently or sends different responses under different circumstances in a way that is observable to an unauthorized actor.

751 vulnerabilities with CWE-203
CVE-2021-46778 MEDIUM
AMD Zen 1/2/3 CPU Firmware - Information Disclosure via Scheduler Queue Contention
CVSS 5.6
CVE-2021-41634 MEDIUM
MELAG FTP Server 2.2.0.4 - User Enumeration via Username Validation
CVSS 5.3
CVE-2021-33149 MEDIUM
Intel(R) Processors - Info Disclosure
CVSS 5.5
CVE-2021-46744 MEDIUM
AMD EPYC 7001/7002/7003 Firmware - Data Inference via Ciphertext Monitoring
CVSS 6.5
CVE-2021-33845 MEDIUM
Splunk 8.1.0-8.1.7 - Username Enumeration via Lockout Error Message
CVSS 5.3
CVE-2021-39791 MEDIUM
Android 12L - Unauthenticated Local Information Disclosure via WallpaperManagerService
CVSS 5.5
CVE-2021-39788 MEDIUM
Android 12L - Local Information Disclosure via TelecomManager Side Channel
CVSS 5.5
CVE-2021-39775 MEDIUM
Android 12L - Unauthenticated App Installation Status Disclosure via Side Channel
CVSS 5.5
CVE-2021-39773 MEDIUM
Android 12L - Local Information Disclosure via VPN Package Side Channel
CVSS 5.5
CVE-2021-39766 MEDIUM
Android - Local Information Disclosure via App Installation Side Channel
CVSS 5.5
CVE-2021-39761 MEDIUM
Android 12L - Unauthenticated App Installation Status Disclosure via Media Side Channel
CVSS 5.5
CVE-2021-39760 MEDIUM
Android 12L - Unauthenticated Local Information Disclosure via AudioService Side Channel
CVSS 5.5
CVE-2021-39756 MEDIUM
Android 12L - Unauthenticated App Installation Status Disclosure via Side Channel
CVSS 5.5
CVE-2021-39755 MEDIUM
Android 12L - Unauthenticated Local Information Disclosure via DevicePolicyManager Side Channel
CVSS 5.5
CVE-2021-39754 MEDIUM
Android - Local Information Disclosure via ContextImpl Side Channel
CVSS 5.5
CVE-2021-39745 MEDIUM
Android 12L - Unauthenticated Local Information Disclosure via DevicePolicyManager Side Channel
CVSS 5.5
CVE-2021-39744 MEDIUM
Android 12L - Unauthenticated App Presence Disclosure via DevicePolicyManager Side Channel
CVSS 5.5
CVE-2021-44421 MEDIUM
Occlum < 0.26.0 - Information Disclosure via Pointer-Validation Side-Channel
CVSS 5.5
CVE-2021-42016 HIGH
Siemens RUGGEDCOM ROS - Observable Timing Discrepancy in Third-Party Component
CVSS 7.5
CVE-2021-0524 MEDIUM
Android 12 - Local Information Disclosure via CarPackageManagerService Side Channel
CVSS 5.5
CVE-2021-45901 MEDIUM
ServiceNow Orlando - Info Disclosure
CVSS 5.3
CVE-2021-39021 MEDIUM
IBM Guardium Data Encryption 5.0.0.2 - Username Enumeration via Observable Discrepancy
CVSS 5.3
CVE-2021-20147 MEDIUM
ManageEngine ADSelfService Plus < 6.0 - Unauthenticated User Enumeration via UMCP ChangePasswordAPI
CVSS 5.3
CVE-2021-20049 HIGH
SonicWall SMA100/SMA200/SMA210/SMA400/SMA410/SMA500v < 10.0.0.0 - Unauthenticated Username Enumeration
CVSS 7.5
CVE-2021-38009 MEDIUM
Google Chrome <96.0.4664.45 - Info Disclosure
CVSS 6.5
Details
Vulnerabilities 751