CWE-203

Observable Discrepancy

Parent: CWE-200 - Exposure of Sensitive Information to an Unauthorized Actor

The product behaves differently or sends different responses under different circumstances in a way that is observable to an unauthorized actor.

733 vulnerabilities with CWE-203
CVE-2023-5388 MEDIUM
Firefox < 124 and ESR < 115.9 - Timing Side-Channel Attack via RSA Decryption
CVSS 6.5
CVE-2023-5410 HIGH
HP PC BIOS - Memory Tampering via System BIOS
CVSS 8.2
CVE-2023-38362 MEDIUM
IBM CICS TX Advanced 10.1 - Info Disclosure
CVSS 5.3
CVE-2023-50306 MEDIUM
IBM Common Licensing 9.0 - Username Enumeration via Observable Response Discrepancy
CVSS 4.0
CVE-2023-6935 MEDIUM
wolfSSL 3.12.2-5.6.3 - Timing Attack via Static RSA Cipher Suites
CVSS 5.9
CVE-2023-51437 HIGH
Apache Pulsar <2.11.3, 3.0.2, 3.1.1 - Code Injection
CVSS 7.4
CVE-2023-50782 HIGH
Python-cryptography - Info Disclosure
CVSS 7.5
CVE-2023-50781 HIGH
Red Hat Enterprise Linux - Observable Discrepancy in RSA Key Exchange
CVSS 7.5
CVE-2023-6240 MEDIUM
Linux Kernel - RSA Decryption Side-Channel Information Disclosure via Marvin Attack
CVSS 6.5
CVE-2023-5992 MEDIUM
OpenSC < 0.25.0 - Side-Channel Information Disclosure via PKCS#1 Padding Removal
CVSS 5.6
CVE-2023-6258 HIGH
pkcs11-provider - Bleichenbacher-like Side-Channel Attack on PKCS#1 1.5 Decryption
CVSS 8.1
CVE-2023-52323 MEDIUM
PyCryptodome and PyCryptodomeX < 3.19.1 - Side-Channel Leakage for OAEP Decryption
CVSS 5.9
CVE-2023-46739 MEDIUM
CubeFS < 3.3.1 - Timing Attack via UserService Password Comparison
CVSS 6.5
CVE-2023-50708 MEDIUM
yii2-authclient < 2.2.15 - Timing Attack via OAuth State and OpenID Connect Nonce Comparison
CVSS 6.1
CVE-2023-41097 MEDIUM
Silabs Gecko Software Development Kit < 4.4.0 - Observable Timing Discrepancy in CBC PKCS7 Padding
CVSS 4.6
CVE-2023-6135 MEDIUM
Firefox < 121.0 - Side-Channel Attack via Minerva on NSS NIST Curves
CVSS 4.3
CVE-2023-23584 MEDIUM
Gallagher Command Centre < 8.50 - Information Disclosure via RESTAPI Response Discrepancy
CVSS 4.3
CVE-2023-50979 MEDIUM
Crypto++ < 8.9.0 - Marvin Side Channel via PKCS#1 v1.5 Padding
CVSS 5.9
CVE-2023-4421 MEDIUM
NSS < 3.61 - Timing Side-Channel Attack via PKCS#1 v1.5 Padding Check
CVSS 6.5
CVE-2023-45287 HIGH
GO < 1.20.0 - Information Disclosure
CVSS 7.5
CVE-2023-40090 MEDIUM
Android - Remote Privilege Escalation via BTM_BleVerifySignature Side Channel
CVSS 6.5
CVE-2023-49092 MEDIUM
RustCrypto RSA - Covert Timing Channel via Non-Constant-Time Implementation
CVSS 5.9
CVE-2023-5981 MEDIUM
GnuTLS - Timing Side-Channel in RSA-PSK ClientKeyExchange
CVSS 5.9
CVE-2023-47102 MEDIUM
UrBackup Server 2.5.31 - User Enumeration via Login Failure Message
CVSS 5.3
CVE-2023-21354 MEDIUM
Android - Local Information Disclosure via Package Manager Service Side Channel
CVSS 5.5
Details
Vulnerabilities 733