CWE-203

Observable Discrepancy

Parent: CWE-200 - Exposure of Sensitive Information to an Unauthorized Actor

The product behaves differently or sends different responses under different circumstances in a way that is observable to an unauthorized actor.

751 vulnerabilities with CWE-203
CVE-2021-38562 HIGH
Best Practical Request Tracker 4.2.0-4.2.16, 4.4.0-4.4.4, 5.0.0-5.0.1 - Information Disclosure via Timing Attack
CVSS 7.5
CVE-2021-26318 MEDIUM
AMD Athlon, Athlon Pro, EPYC, Ryzen, and Ryzen Pro Firmware - Observable Timing Discrepancy via PREFETCH Instructions
CVSS 4.7
CVE-2021-24651 HIGH
Poll Maker WordPress Plugin < 3.4.2 - Unauthenticated SQL Injection via ays_finish_poll AJAX Action
CVSS 7.5
CVE-2021-37968 MEDIUM
Google Chrome < 94.0.4606.54 - Cross-Origin Data Leak via Background Fetch API
CVSS 4.3
CVE-2021-20376 MEDIUM
IBM Sterling File Gateway <6.1.1.0 - Info Disclosure
CVSS 4.3
CVE-2021-38153 MEDIUM
Apache Kafka <2.8.1-2.8.0 - Timing Attack
CVSS 5.9
CVE-2021-34576 MEDIUM
Kaden PICOFLUX Air Firmware - Information Exposure via Observable Discrepancy
CVSS 4.3
CVE-2021-39189 MEDIUM
pimcore < 10.1.3 - Username Enumeration via Forgot Password Functionality
CVSS 5.3
CVE-2021-37151 MEDIUM
CyberArk Identity < 21.11.133 - Username Enumeration via Authentication Response Length
CVSS 5.3
CVE-2021-38209 LOW
Linux kernel <5.12.2 - Info Disclosure
CVSS 3.3
CVE-2021-3642 MEDIUM
Wildfly Elytron < 1.10.14 - Timing Attack via ScramServer
CVSS 5.3
CVE-2021-37848 HIGH
barebox < 2021.07.0 - Timing Side-Channel in Password Hash Comparison
CVSS 7.5
CVE-2021-34575 HIGH
mbconnect24 <= 2.8.0 - Unauthenticated User Enumeration via Response Analysis
CVSS 7.5
CVE-2021-34556 MEDIUM
Linux Kernel < 5.13.7 - Information Disclosure via BPF Speculative Store Bypass
CVSS 5.5
CVE-2021-35477 MEDIUM
Linux kernel <5.13.7 - Info Disclosure
CVSS 5.5
CVE-2021-37606 MEDIUM
meow_hash 0.5/calico - Inadequate Encryption Strength via Collision Timing Attack
CVSS 5.3
CVE-2021-20113 MEDIUM
TCExam <= 14.8.1 - Unauthenticated Email Enumeration via Password Reset Error Discrepancy
CVSS 5.3
CVE-2021-24117 MEDIUM
Apache Teaclave SGX SDK 1.1.3 - Side-Channel Information Disclosure via Base64 PEM Decoding
CVSS 4.9
CVE-2021-24119 MEDIUM
Mbed TLS < 2.26.0 - Side-Channel Information Disclosure via Base64 PEM Decoding
CVSS 4.9
CVE-2021-24116 MEDIUM
wolfssl < 4.6.0 - Side-Channel Information Disclosure via Base64 PEM Decoding
CVSS 4.9
CVE-2021-32528 MEDIUM
QSAN Storage Manager < 3.3.1 - Unauthenticated Exposure of Sensitive System Information
CVSS 5.3
CVE-2021-0089 MEDIUM
Debian Linux - Information Disclosure
CVSS 6.5
CVE-2021-0086 MEDIUM
Intel Brand Verification Tool < 11.0.0.1225 - Observable Discrepancy in Floating-Point Operations
CVSS 6.5
CVE-2021-0001 MEDIUM
Intel Integrated Performance Primitives Cryptography - Observable Timing Discrepancy
CVSS 4.7
CVE-2021-26314 MEDIUM
Xen - Observable Timing Discrepancy via Floating Point Value Injection
CVSS 5.5
Details
Vulnerabilities 751