CWE-203

Observable Discrepancy

Parent: CWE-200 - Exposure of Sensitive Information to an Unauthorized Actor

The product behaves differently or sends different responses under different circumstances in a way that is observable to an unauthorized actor.

751 vulnerabilities with CWE-203
CVE-2024-9398 MEDIUM
Firefox < 131 and Firefox ESR < 128.3 - Information Disclosure via Protocol Handler Detection
CVSS 5.3
CVE-2024-47129 MEDIUM
goTenna Pro App < 1.6.1 and < 2.0.3 - Observable Response Discrepancy via Broadcast Frame Length
CVSS 4.3
CVE-2024-41715 MEDIUM
goTenna Pro ATAK Plugin < 2.0.7 - Observable Response Discrepancy via Broadcast Frame Length
CVSS 4.3
CVE-2024-8651 MEDIUM
NetCat CMS <6.4.0.24248 - Info Disclosure
CVSS 5.3
CVE-2024-23984 MEDIUM
Intel(R) Processors - Info Disclosure
CVSS 5.3
CVE-2024-34336 MEDIUM
ORDAT FOSS-Online <2.24.01 - Info Disclosure
CVSS 5.3
CVE-2024-42343 MEDIUM
Loway QueueMetrics 17.06.1-24.05.5 - Observable Response Discrepancy
CVSS 5.3
CVE-2024-45052 MEDIUM
Fides < 2.44.0 - Unauthenticated Timing-Based Username Enumeration via Authentication Response
CVSS 5.3
CVE-2024-39921 HIGH
Fujitsu IPCOM VE2 Series Firmware < V01L06NF0112 - Observable Timing Discrepancy
CVSS 7.5
CVE-2024-45678 MEDIUM
YubiKey 5 Series < 5.7.0 and YubiHSM 2 < 2.4.0 - ECDSA Secret-Key Extraction via Electromagnetic Side Channel
CVSS 4.2
CVE-2024-1543 MEDIUM
wolfssl < 5.6.6 - Observable Timing Discrepancy in T-Table Implementation
CVSS 4.1
CVE-2024-1544 MEDIUM
wolfssl < 5.7.2 - Observable Discrepancy in ECDSA Nonce Generation
CVSS 4.1
CVE-2024-41952 MEDIUM
Zitadel 2.53.0-2.53.8 - Username Enumeration via Error Message Discrepancy
CVSS 5.3
CVE-2024-38431 MEDIUM
Matrix Tafnit < 8.4.202 - Observable Response Discrepancy
CVSS 5.3
CVE-2024-41880 MEDIUM
Veilid < 0.3.4 - Observable Discrepancy via Ping Function Misuse
CVSS 5.3
CVE-2024-39830 HIGH
Mattermost 9.5.0-9.5.5 9.6.0-9.6.2 9.7.0-9.7.4 9.8.0 - Remote Cluster Token Timing Attack via Shared Channels
CVSS 8.1
CVE-2024-39891 MEDIUM KEV
Twilio Authy < 26.1.0 (iOS) and < 25.1.0 (Android) - Unauthenticated Phone Number Enumeration via API Endpoint
CVSS 5.3
CVE-2024-36996 MEDIUM
Splunk Enterprise <9.2.2, <9.1.5, <9.0.10 & Splunk Cloud <9.1.2312.109 User Enumeration via SAML
CVSS 5.3
CVE-2024-38322 MEDIUM
IBM Storage Defender - Resiliency Service <2.0.5 - Info Disclosure
CVSS 5.3
CVE-2024-6129 LOW
spa-cartcms 1.9.0.6 - Observable Behavioral Discrepancy via Email Parameter
CVSS 3.7
CVE-2024-6056 LOW
nasirkhan/laravel_starter < 11.8.0 - Observable Response Discrepancy via Password Reset Email Parameter
CVSS 3.7
CVE-2024-38465 MEDIUM
Shenzhen Guoxin Synthesis <8.3.0 - Info Disclosure
CVSS 5.3
CVE-2024-31870 LOW
IBM Db2 for i <7.6 - Info Disclosure
CVSS 3.3
CVE-2024-32926 MEDIUM
Android - Local Information Disclosure via Side Channel
CVSS 5.5
CVE-2024-5697 MEDIUM
Firefox < 127 - Screenshot Detection via Built-in Screenshot Functionality
CVSS 4.3
Details
Vulnerabilities 751