CWE-203

Observable Discrepancy

Parent: CWE-200 - Exposure of Sensitive Information to an Unauthorized Actor

The product behaves differently or sends different responses under different circumstances in a way that is observable to an unauthorized actor.

751 vulnerabilities with CWE-203
CVE-2024-51477 MEDIUM
IBM InfoSphere Information Server 11.7 - Authenticated Sensitive Username Disclosure via Observable Response Discrepancy
CVSS 4.3
CVE-2024-13939 HIGH
String::Compare::ConstantTime < 0.321 - Observable Timing Discrepancy
CVSS 7.5
CVE-2024-41760 LOW
IBM Common Cryptographic Architecture 7.0.0-7.5.51 - Timing Attack During RSA Operations
CVSS 3.7
CVE-2024-41335 HIGH
Draytek Vigor Routers - Information Disclosure via Timing Attack on strcmp/memcmp
CVSS 7.5
CVE-2024-45089 MEDIUM
IBM Sterling B2B Integrator <6.2.0.3 - Info Disclosure
CVSS 4.3
CVE-2024-7881 MEDIUM
ARM C1-Premium Firmware - Unprivileged Data Memory-Dependent Prefetch Engine Information Disclosure
CVSS 5.1
CVE-2024-35114 MEDIUM
IBM Control Center 6.2.1 and 6.3.1 - Username Enumeration via Observable Login Discrepancy
CVSS 5.3
CVE-2024-10929 MEDIUM
Arm Cortex-A57, Cortex-A72 < r1p0, Cortex-A73, Cortex-A75 - Observable Discrepancy via Branch History Control
CVSS 5.1
CVE-2024-43095 HIGH
Google Android - Privilege Escalation
CVSS 7.8
CVE-2024-36510 MEDIUM
FortiClientEMS/FortiSOAR <7.5.0 - Info Disclosure
CVSS 5.3
CVE-2024-42174 LOW
HCL MyXalytics - Username Enumeration via Observable Response Discrepancy
CVSS 3.7
CVE-2024-13198 LOW
Langhsu Mblog Blog System 3.5.0 - Info Disclosure
CVSS 3.7
CVE-2024-54767 HIGH
AVM FRITZ!Box 7530 AX v7.59 - Info Disclosure
CVSS 7.5
CVE-2024-13028 LOW
Antabot White-Jotter <0.2.2 - Info Disclosure
CVSS 3.7
CVE-2024-56738 MEDIUM
GNU GRUB2 < 2.12 - Observable Timing Discrepancy in grub_crypto_memcmp
CVSS 5.3
CVE-2024-54454 MEDIUM
Kurmi Provisioning Suite <7.9.0.35, 7.10.x-7.10.0.18, 7.11.x-7.11.0...
CVSS 5.3
CVE-2024-47150 LOW
Honor MagicOS 8.0-8.0.0.135 - Information Disclosure
CVSS 3.3
CVE-2024-47149 LOW
Honor <version> - Privilege Escalation
CVSS 3.3
CVE-2024-8994 MEDIUM
Honor MagicOS 8.0-8.0.0.159 - Information Disclosure
CVSS 6.2
CVE-2024-8993 MEDIUM
Honor MagicOS 8.0-8.0.0.159 - Information Disclosure
CVSS 6.2
CVE-2024-8992 MEDIUM
Honor MagicOS 8.0-8.0.0.159 - Information Disclosure
CVSS 4.0
CVE-2024-47155 MEDIUM
Honor MagicOS 8.0-8.0.0.135 - Information Disclosure
CVSS 5.5
CVE-2024-47154 MEDIUM
Honor MagicOS 8.0-8.0.0.173 - Information Disclosure
CVSS 5.5
CVE-2024-47153 MEDIUM
Honor MagicOS 8.0-8.0.0.159 - Information Disclosure
CVSS 6.2
CVE-2024-47156 LOW
Honor MagicOS 8.0-8.0.0.135 - Information Disclosure
CVSS 3.3
Details
Vulnerabilities 751