CWE-203
751 CVEs • Abstraction: Base
Observable Discrepancy
The product behaves differently or sends different responses under different circumstances in a way that is observable to an unauthorized actor, which exposes security-relevant information about the state of the product, such as whether a particular operation was successful or not.
CVEs (751)
CVE VENDORS PRODUCTS UPDATED PUBLISHED CVSS |
|---|
Observable Response Discrepancy in GitHub repository answerdev/answer prior to 1.0.6. |
Observable Timing Discrepancy in GitHub repository answerdev/answer prior to 1.0.6. |
An issue was discovered in eZ Publish Ibexa Kernel before 7.5.15.1. The /user/sessions endpoint can be abused to determine account existence. |
1Amazon 2Opensearch Opensearch SecurityJun 17, 2026 Mar 2, 2023 N/A· v4 5.3 MEDIUM· v3 N/A· v2 OpenSearch Security is a plugin for OpenSearch that offers encryption, authentication and authorization. There is an observable discrepancy in the authentication response time between calls where the user provided exists...Show more |
vantage6 is a privacy preserving federated learning infrastructure for secure insight exchange. vantage6 does not inform the user of wrong username/password combination if the username actually exists. This is an attempt...Show more |
The Raccoon attack is a timing attack on DHE ciphersuites inherit in the TLS specification. To mitigate this vulnerability, Firefox disabled support for DHE ciphersuites. |
5Debian FedoraprojectGnu+2 more7Active Iq Unified Manager Converged Systems Advisor AgentDebian Linux+4 moreJun 17, 2026 Feb 15, 2023 N/A· v4 7.4 HIGH· v3 N/A· v2 A timing side-channel in the handling of RSA ClientKeyExchange messages was discovered in GnuTLS. This side-channel can be sufficient to recover the key encrypted in the RSA ciphertext across a network in a Bleichenbache...Show more |
2Openssl Stormshield4Endpoint Security OpensslSslvpn+1 moreJun 17, 2026 Feb 8, 2023 N/A· v4 5.9 MEDIUM· v3 N/A· v2 A timing based side channel exists in the OpenSSL RSA Decryption implementation which could be sufficient to recover a plaintext across a network in a Bleichenbacher style attack. To achieve a successful decryption an at...Show more |
Observable Discrepancy in GitHub repository healthchecks/healthchecks prior to v2.6. |
A vulnerability, which was classified as problematic, was found in michaelliao jopenid. Affected is the function getAuthentication of the file JOpenId/src/org/expressme/openid/OpenIdManager.java. The manipulation leads t...Show more |
1Redhat 2Jboss Enterprise Application Platform Wildfly ElytronJun 17, 2026 Jan 13, 2023 N/A· v4 7.4 HIGH· v3 N/A· v2 wildfly-elytron: possible timing attacks via use of unsafe comparator. A flaw was found in Wildfly-elytron. Wildfly-elytron uses java.util.Arrays.equals in several places, which is unsafe and vulnerable to timing attacks...Show more |
NVIDIA BMC contains a vulnerability in IPMI handler, where an unauthorized attacker can use certain oracles to guess a valid BMC username, which may lead to an information disclosure. |
1Tp Link 2Archer C5 Firmware Tl Wr710n FirmwareJun 17, 2026 Jan 11, 2023 N/A· v4 7.5 HIGH· v3 N/A· v2 TP-Link routers, Archer C5 and WR710N-V1, using the latest software, the strcmp function used for checking credentials in httpd, is susceptible to a side-channel attack. By measuring the response time of the httpd proces...Show more |
A flaw named "EntryBleed" was found in the Linux Kernel Page Table Isolation (KPTI). This issue could allow a local attacker to leak KASLR base via prefetch side-channels based on TLB timing for Intel systems. |
In Talend Administration Center 7.3.1.20200219 before TAC-15950, the Forgot Password feature provides different error messages for invalid reset attempts depending on whether the email address is associated with any acco...Show more |
1Arm 10Cortex A53 Firmware Cortex A55 FirmwareCortex A57 Firmware+7 moreJun 17, 2026 Jan 10, 2023 N/A· v4 7.5 HIGH· v3 N/A· v2 The AES instructions on the ARMv8 platform do not have an algorithm that is "intrinsically resistant" to side-channel attacks. NOTE: the vendor reportedly offers the position "while power side channel attacks ... are pos...Show more |
1Paysafe 1Barzahlen Payment Module Php Sdk Nov 21, 2024 Jan 8, 2023 N/A· v4 5.3 MEDIUM· v3 1.4 LOW· v2 A vulnerability, which was classified as problematic, was found in viafintech Barzahlen Payment Module PHP SDK up to 2.0.0. Affected is the function verify of the file src/Webhook.php. The manipulation leads to observabl...Show more |
Inappropriate implementation in Paint in Google Chrome prior to 98.0.4758.80 allowed a remote attacker to leak cross-origin data outside an iframe via a crafted HTML page. (Chrome security severity: Low) |
A vulnerability classified as problematic was found in Ziftr primecoin up to 0.8.4rc1. Affected by this vulnerability is the function HTTPAuthorized of the file src/bitcoinrpc.cpp. The manipulation of the argument strUse...Show more |
lxc-user-nic in lxc through 5.0.1 is installed setuid root, and may allow local users to infer whether any file exists, even within a protected directory tree, because "Failed to open" often indicates that a file does no...Show more |