CWE-203

Observable Discrepancy

Parent: CWE-200 - Exposure of Sensitive Information to an Unauthorized Actor

The product behaves differently or sends different responses under different circumstances in a way that is observable to an unauthorized actor.

733 vulnerabilities with CWE-203
CVE-2021-42016 HIGH
Siemens RUGGEDCOM ROS - Observable Timing Discrepancy in Third-Party Component
CVSS 7.5
CVE-2021-0524 MEDIUM
Android 12 - Local Information Disclosure via CarPackageManagerService Side Channel
CVSS 5.5
CVE-2021-45901 MEDIUM
ServiceNow Orlando - Info Disclosure
CVSS 5.3
CVE-2021-39021 MEDIUM
IBM Guardium Data Encryption 5.0.0.2 - Username Enumeration via Observable Discrepancy
CVSS 5.3
CVE-2021-20147 MEDIUM
ManageEngine ADSelfService Plus < 6.0 - Unauthenticated User Enumeration via UMCP ChangePasswordAPI
CVSS 5.3
CVE-2021-20049 HIGH
SonicWall SMA100/SMA200/SMA210/SMA400/SMA410/SMA500v < 10.0.0.0 - Unauthenticated Username Enumeration
CVSS 7.5
CVE-2021-38009 MEDIUM
Google Chrome <96.0.4664.45 - Info Disclosure
CVSS 6.5
CVE-2021-44876 MEDIUM
Dalmark Systems Systeam 2.22.8 build 1724 - User Enumeration via Tenant Identification Message Discrepancy
CVSS 5.3
CVE-2021-44875 MEDIUM
Dalmark Systems Systeam 2.22.8 build 1724 - User Enumeration via Password Recovery Message Discrepancy
CVSS 5.3
CVE-2021-44554 MEDIUM
Thinfinity VirtualUI < 3.0 - User Enumeration via ChangePassword URI
CVSS 5.3
CVE-2021-1032 LOW
Android - Local Information Disclosure via PackageManagerService MIME Group Query
CVSS 3.3
CVE-2021-1031 LOW
Android - Local Information Disclosure via Notification Listener Side Channel
CVSS 3.3
CVE-2021-1030 MEDIUM
Android 12 - Local Information Disclosure via Notification Side Channel
CVSS 5.5
CVE-2021-1026 MEDIUM
Android 12 - Unauthenticated Local Information Disclosure via RttServiceImpl Side Channel
CVSS 5.5
CVE-2021-1018 LOW
Android 12 - Unauthenticated Local Information Disclosure via AudioService Volume Adjustment
CVSS 3.3
CVE-2021-1015 LOW
Android 12 - Unauthenticated Local Information Disclosure via Side Channel in PhoneInterfaceManager
CVSS 3.3
CVE-2021-1014 MEDIUM
Android - Local Information Disclosure via Side Channel in PhoneInterfaceManager
CVSS 5.5
CVE-2021-1013 MEDIUM
Android 12 - Unauthenticated App Installation Status Disclosure via Permission Check Side Channel
CVSS 5.5
CVE-2021-1012 MEDIUM
Android 12 - Local Information Disclosure via NotificationAccessDetails Side Channel
CVSS 5.5
CVE-2021-1009 MEDIUM
Android 12 - Unauthenticated App Installation Status Disclosure via PackageManagerService Side Channel
CVSS 5.5
CVE-2021-1005 MEDIUM
Android 12 - Unauthenticated Local Information Disclosure via Side Channel in PhoneInterfaceManager
CVSS 5.5
CVE-2021-0995 LOW
Android 12 - Unauthenticated App Installation Status Disclosure via WifiServiceImpl Side Channel
CVSS 3.3
CVE-2021-0990 LOW
Android - Local Information Disclosure via Side Channel in PhoneSubInfoController
CVSS 3.3
CVE-2021-0989 LOW
Android 12 - Local Information Disclosure via TelecomServiceImpl Side Channel
CVSS 3.3
CVE-2021-0988 LOW
Android - Local Information Disclosure via Side Channel in ActivityClientController
CVSS 3.3
Details
Vulnerabilities 733