CWE-203

Observable Discrepancy

Parent: CWE-200 - Exposure of Sensitive Information to an Unauthorized Actor

The product behaves differently or sends different responses under different circumstances in a way that is observable to an unauthorized actor.

735 vulnerabilities with CWE-203
CVE-2019-18886 MEDIUM
Symfony <4.2.11, <4.3.8 - Info Disclosure
CVSS 5.3
CVE-2019-10764 HIGH
elliptic-php < 1.0.6 - Timing Attack Leading to Private Key Recovery
CVSS 7.4
CVE-2019-16863 MEDIUM
STMicroelectronics ST33TPHF2ESPI - Info Disclosure
CVSS 5.9
CVE-2019-18673 MEDIUM
SHIFT BitBox02 - Side-Channel Information Disclosure via OLED Power Consumption
CVSS 4.6
CVE-2019-14360 MEDIUM
Hyundai Pay Kasse HK-1000 - Info Disclosure
CVSS 4.6
CVE-2019-14358 MEDIUM
Archos Safe-T - Information Disclosure via OLED Power Consumption Side Channel
CVSS 4.6
CVE-2019-14356 MEDIUM
Coldcard MK1 and MK2 Firmware < 2.1.2 - Side-Channel Information Disclosure via OLED Power Consumption
CVSS 5.3
CVE-2019-15809 MEDIUM
Atmel Toolbox 00.03.11.05 - Timing Side-Channel in ECDSA Signature Generation
CVSS 4.7
CVE-2019-13629 MEDIUM
MatrixSSL < 4.2.1 - Timing Side-Channel Attack in ECDSA Signature Generation
CVSS 5.9
CVE-2019-13628 MEDIUM
wolfSSL wolfCrypt <4.0.0 - Info Disclosure
CVSS 4.7
CVE-2019-3732 HIGH
RSA BSAFE Crypto-C Micro Edition < 4.0.5.3 and 4.1.x < 4.1.3.3 - Information Exposure Through Timing Discrepancy
CVSS 7.5
CVE-2019-3731 HIGH
RSA BSAFE Crypto-C Micro Edition < 4.1.4 and RSA Micro Edition Suite < 4.4 - Timing Discrepancy Information Exposure
CVSS 7.5
CVE-2019-11743 LOW
Firefox < 69 and Firefox ESR < 60.9, 68.1 - Cross-Origin Information Exposure via Navigation Timing Side-Channel
CVSS 3.7
CVE-2019-6651 MEDIUM
BIG-IP 11.5.1-11.6.4 - Observable Discrepancy in Configuration Utility Login Page
CVSS 5.3
CVE-2019-13627 MEDIUM
libgcrypt20 <1.8.4-5, 1.7.6-2+deb9u3, 1.6.3-2+deb8u4 - Info Disclosure
CVSS 6.3
CVE-2019-16669 MEDIUM
Pagekit 1.0.17 - Account Enumeration via Reset Password Response Discrepancy
CVSS 5.3
CVE-2019-3740 MEDIUM
RSA BSAFE Crypto-J < 6.2.5 - Information Exposure Through Timing Discrepancy During DSA Key Generation
CVSS 6.5
CVE-2019-3739 MEDIUM
RSA BSAFE Crypto-J < 6.2.5 - Information Exposure Through Timing Discrepancy During ECDSA Key Generation
CVSS 6.5
CVE-2019-16394 MEDIUM
SPIP <3.1.11 & <3.2.5 - Info Disclosure
CVSS 5.3
CVE-2019-10071 CRITICAL
Apache Tapestry - Timing Side Channel in HMAC Verification
CVSS 9.8
CVE-2019-1563 LOW
OpenSSL 1.0.2-1.0.2s - Bleichenbacher Padding Oracle Attack via CMS/PKCS7 Decryption
CVSS 3.7
CVE-2019-13599 MEDIUM
CentOS Web Panel <0.9.8.848 - Info Disclosure
CVSS 5.3
CVE-2019-15132 MEDIUM
Zabbix through 4.4.0alpha1 - User Enumeration via Login Response Discrepancy
CVSS 5.3
CVE-2019-13377 MEDIUM
hostapd 2.0-2.8 - Side-Channel Information Disclosure via Brainpool Curve Timing
CVSS 5.9
CVE-2019-13420 MEDIUM
Search Guard <21.0 - Info Disclosure
CVSS 5.9
Details
Vulnerabilities 735