CWE-203
Observable Discrepancy
The product behaves differently or sends different responses under different circumstances in a way that is observable to an unauthorized actor.
735 vulnerabilities with CWE-203
CVE-2017-8055
MEDIUM
WatchGuard Fireware < 11.2.1 - User Enumeration via XML-RPC Login Handler
CVSS 5.3
CVE-2016-15015
LOW
viafintech Barzahlen Payment Module PHP SDK <2.0.1 - Info Disclosure
CVSS 2.6
CVE-2016-20012
MEDIUM
OpenSSH <= 8.7 - Unauthenticated User Enumeration via Public Key Validation
CVSS 5.3
CVE-2016-0762
MEDIUM
Apache Tomcat <9.0.0.M10, <8.5.5, <8.0.37, <7.0.71, <6.0.46 - Info ...
CVSS 5.9
CVE-2016-6489
HIGH
Nettle - Info Disclosure
CVSS 7.5
CVE-2016-9129
MEDIUM
Revive Adserver <3.2.3 - Info Disclosure
CVSS 5.3
CVE-2016-2178
MEDIUM
OpenSSL - Timing Side-Channel Attack in DSA Signing
CVSS 5.5
CVE-2015-8313
MEDIUM
GnuTLS 2.0.0-2.12.23 - Observable Discrepancy in CBC Padding Validation
CVSS 5.9
CVE-2015-0837
MEDIUM
GnuPG < 1.4.19 and Libgcrypt < 1.6.3 - Information Disclosure via Modular Exponentiation Timing Attack
CVSS 5.9
CVE-2014-4156
MEDIUM
Proxmox Virtual Environment < 3.2 - User Enumeration via AccessControl.pm
CVSS 5.3
CVE-2014-9720
MEDIUM
Tornado < 3.2.2 - Observable Discrepancy via BREACH Attack
CVSS 6.5
CVE-2013-10006
LOW
Ziftr primecoin <0.8.4rc1 - Timing Discrepancy
CVSS 2.6
CVE-2013-1422
MEDIUM
WebCalendar < 1.2.7 - Information Disclosure via Failed Login Error Message
CVSS 5.3
CVE-2013-1620
Mozilla Network Security Services - Timing Side-Channel Attack via CBC Padding
CVE-2010-10006
LOW
michaelliao jopenid - Info Disclosure
CVSS 2.6
CVE-2005-1650
Woppoware PostMaster 4.2.2 build 3.2.5 - Username Enumeration via Error Message Discrepancy
CVE-2005-0918
Adobe SVG Viewer < 3.02 - File Existence Disclosure via NPSVG3.dll ActiveX Control
CVE-2004-1428
ArGoSoft FTP < 1.4.2.1 - Username Enumeration via Error Message
CVE-2004-2150
Nettica Corporation INTELLIPEER Email Server 1.01 - Info Disclosure
CVE-2004-2252
Astaro Security Linux <4.024 - Info Disclosure
CVE-2004-0243
IBM AIX 4.3.3-5.1 - Observable Discrepancy in Remote Login Error Messages
CVE-2004-0294
Yabbforumsoftware Yet Another Bulletin Board - Information Disclosure
CVE-2004-0778
CVS <1.11.17-1.12.9 - Info Disclosure
CVE-2004-1602
ProFTPD 1.2.0-1.2.10 - Username Enumeration via Timing Discrepancy
CVE-2003-0637
Novell iChain <2.2 - Info Disclosure
Details
Vulnerabilities
735