CWE-203

Observable Discrepancy

Parent: CWE-200 - Exposure of Sensitive Information to an Unauthorized Actor

The product behaves differently or sends different responses under different circumstances in a way that is observable to an unauthorized actor.

735 vulnerabilities with CWE-203
CVE-2019-14359 LOW
BC Vault Firmware - Side-Channel Information Disclosure via OLED Power Consumption
CVSS 2.4
CVE-2019-14357 LOW
Mooltipass Mini Firmware - Side-Channel Information Disclosure via OLED Power Consumption
CVSS 2.4
CVE-2019-14355 LOW
ShapeShift KeepKey - Info Disclosure
CVSS 2.4
CVE-2019-14354 LOW
Ledger Nano S/Nano X - Info Disclosure
CVSS 2.4
CVE-2019-14353 MEDIUM
Trezor One <1.8.2 - Info Disclosure
CVSS 4.2
CVE-2019-12743 MEDIUM
HumHub Social Network Kit Enterprise 1.3.13 - User Enumeration via Username Brute-Force
CVSS 5.3
CVE-2019-1020002 HIGH
Pterodactyl <0.7.14 - Info Disclosure
CVSS 7.5
CVE-2019-2818 LOW
Oracle JDK and JRE 11.0.3 and 12.0.1 - Unauthenticated Data Exposure via Multiple Protocols
CVSS 3.1
CVE-2019-9815 HIGH
Thunderbird <60.7-Firefox <67-Firefox ESR <60.7 - Info Disclosure
CVSS 8.1
CVE-2019-13383 MEDIUM
Webpanel - Information Disclosure
CVSS 5.3
CVE-2019-12383 MEDIUM
Tor Browser <8.0.1 - Info Disclosure
CVSS 4.3
CVE-2019-10848 MEDIUM
Computrols CBAS < 19.0.0 - Username Enumeration
CVSS 5.3
CVE-2019-10114 HIGH
GitLab <11.7.8, <11.8.x <11.8.4, <11.9.x <11.9.2 - Info Disclosure
CVSS 7.5
CVE-2019-7217 HIGH
Citrix ShareFile <19.12 - Info Disclosure
CVSS 7.5
CVE-2019-11578 MEDIUM
dhcpcd < 7.2.1 - Observable Discrepancy via Latency Attack
CVSS 5.9
CVE-2019-9495 LOW
hostapd/wpa_supplicant <2.7 - Info Disclosure
CVSS 3.7
CVE-2019-9494 MEDIUM
Hostapd & Wpa_Supplicant <2.7 - Info Disclosure
CVSS 5.9
CVE-2019-6602 HIGH
BIG-IP 11.5.1-11.5.8 and 11.6.1-11.6.3 - Observable Discrepancy in Configuration Utility Login Page
CVSS 7.5
CVE-2019-10233 HIGH
GLPI < 9.4.1.1 - Timing Attack via Cookie
CVSS 8.1
CVE-2019-1559 MEDIUM
OpenSSL 1.0.2-1.0.2q - Padding Oracle via SSL_shutdown Double Call
CVSS 5.9
CVE-2018-9364 HIGH
Android LG LAF Component - Secure Boot Bypass via Special Command
CVSS 7.5
CVE-2018-1000884 CRITICAL
Vesta CP <0.9.8-18 - Info Disclosure
CVSS 9.8
CVE-2018-16869 MEDIUM
nettle < 3.4 - Observable Discrepancy via RSA PKCS#1 v1.5 Padding Oracle
CVSS 5.7
CVE-2018-16868 MEDIUM
GnuTLS < 3.6.4 - Bleichenbacher Padding Oracle Attack via RSA PKCS#1 v1.5 Verification
CVSS 5.6
CVE-2018-5407 MEDIUM
Ubuntu Linux - Exposure of Sensitive Information via SMT Port Contention Timing Attack
CVSS 4.7
Details
Vulnerabilities 735