CWE-203

Observable Discrepancy

Parent: CWE-200 - Exposure of Sensitive Information to an Unauthorized Actor

The product behaves differently or sends different responses under different circumstances in a way that is observable to an unauthorized actor.

751 vulnerabilities with CWE-203
CVE-2020-10369 MEDIUM
Cypress/Broadcom Wireless Combo - Info Disclosure
CVSS 5.5
CVE-2020-10367 MEDIUM
Cypress/Broadcom Wireless Combo - Memory Corruption
CVSS 5.5
CVE-2020-35165 MEDIUM
Dell BSAFE <4.1.5-4.6 - Info Disclosure
CVSS 5.1
CVE-2020-12413 MEDIUM
Firefox < 78.0 and Firefox ESR < 68.10.0 - Timing Attack via DHE Ciphersuites
CVSS 5.9
CVE-2020-35473 MEDIUM
Bluetooth Core Specification 4.0-5.2 - Authentication Bypass by Capture-replay via Resolvable Private Addressing
CVSS 4.3
CVE-2020-36517 HIGH
Home Assistant 2022.03 - Information Disclosure via Hardcoded DNS Resolver
CVSS 7.5
CVE-2020-35398 MEDIUM
UTI Mutual Fund Invest Online < 5.4.28 - Username Enumeration via Error Message
CVSS 5.3
CVE-2020-25082 LOW
Nuvoton NPCT75x Firmware 7.2.0-7.2.1 - ECC Private Key Extraction via ECDSA Timing Side-Channel
CVSS 3.8
CVE-2020-36424 MEDIUM
Arm Mbed TLS < 2.24.0 - Private Key Recovery via Side-Channel Attack
CVSS 4.7
CVE-2020-36422 MEDIUM
Arm Mbed TLS < 2.23.0 - ECC Private Key Recovery via Side Channel
CVSS 5.3
CVE-2020-36421 MEDIUM
Arm Mbed TLS < 2.23.0 - RSA Private Key Disclosure via Modular Exponentiation Side Channel
CVSS 5.3
CVE-2020-24512 LOW
Intel(R) Processors - Info Disclosure
CVSS 3.3
CVE-2020-27211 MEDIUM
Nordic Semiconductor nRF52840 - Info Disclosure
CVSS 5.7
CVE-2020-35518 MEDIUM
389 Directory Server < 1.4.3.19 - Unauthenticated LDAP Entry Existence Disclosure
CVSS 5.3
CVE-2020-27170 MEDIUM
Linux kernel <5.11.8 - Info Disclosure
CVSS 4.7
CVE-2020-1926 MEDIUM
Apache Hive <2.3.8 - Info Disclosure
CVSS 5.9
CVE-2020-11287 HIGH
Qualcomm AQT1000 and others - Information Disclosure via RTT Frame MAC Address Linking
CVSS 7.5
CVE-2020-9389 LOW
SquaredUp < 4.6 - Username Enumeration via Login Timing Attack
CVSS 3.7
CVE-2020-28208 MEDIUM
Rocket.Chat <= 3.9.1 - Email Address Enumeration via Password Reset Function
CVSS 5.3
CVE-2020-35624 MEDIUM
MediaWiki < 1.35.1 - Information Disclosure via SecurePoll Vote Timestamp
CVSS 5.3
CVE-2020-35480 MEDIUM
MediaWiki < 1.35.1 - Information Disclosure of Hidden User Accounts
CVSS 5.3
CVE-2020-27026 MEDIUM
Android 11 - Local Information Disclosure via Fingerprint Presence Check
CVSS 5.5
CVE-2020-0464 MEDIUM
Android 10 - Local Information Disclosure via Resolv Cache Lookup
CVSS 5.5
CVE-2020-7962 MEDIUM
One Identity Password Manager 5.8 - Info Disclosure
CVSS 5.3
CVE-2020-12912 MEDIUM
AMD Energy Driver for Linux - Unauthenticated Side Channel Attack via RAPL Interface
CVSS 5.5
Details
Vulnerabilities 751