CWE-203
751 CVEs • Abstraction: Base
Observable Discrepancy
The product behaves differently or sends different responses under different circumstances in a way that is observable to an unauthorized actor, which exposes security-relevant information about the state of the product, such as whether a particular operation was successful or not.
CVEs (751)
CVE VENDORS PRODUCTS UPDATED PUBLISHED CVSS |
|---|
1Adenza 1Axiomsl Controllerview Jun 17, 2026 Jan 30, 2022 N/A· v4 5.3 MEDIUM· v3 5.0 MEDIUM· v2 Adenza AxiomSL ControllerView through 10.8.1 is vulnerable to user enumeration. An attacker can identify valid usernames on the platform because a failed login attempt produces a different error message when the username...Show more |
In Bromite through 78.0.3904.130, there are adblock rules in the release APK; therefore, probing which resources are blocked and which aren't can identify the application version and defeat the User-Agent protection mech...Show more |
2Fedoraproject W1.fi3Fedora HostapdWpa SupplicantJul 14, 2026 Jan 17, 2022 N/A· v4 9.8 CRITICAL· v3 6.8 MEDIUM· v2 The implementations of EAP-pwd in hostapd before 2.10 and wpa_supplicant before 2.10 are vulnerable to side-channel attacks as a result of cache access patterns. NOTE: this issue exists because of an incomplete fix for C...Show more |
2Fedoraproject W1.fi3Fedora HostapdWpa SupplicantJul 14, 2026 Jan 17, 2022 N/A· v4 9.8 CRITICAL· v3 6.8 MEDIUM· v2 The implementations of SAE in hostapd before 2.10 and wpa_supplicant before 2.10 are vulnerable to side channel attacks as a result of cache access patterns. NOTE: this issue exists because of an incomplete fix for CVE-2...Show more |
1Jenkins 1Configuration As Code Jun 17, 2026 Jan 12, 2022 N/A· v4 5.3 MEDIUM· v3 5.0 MEDIUM· v2 Jenkins Configuration as Code Plugin 1.55 and earlier used a non-constant time comparison function when validating an authentication token allowing attackers to use statistical methods to obtain a valid authentication to...Show more |
In NocoDB, versions 0.9 to 0.83.8 are vulnerable to Observable Discrepancy in the password-reset feature. When requesting a password reset for a given email address, the application displays an error message when the ema...Show more |
1Zohocorp 1Manageengine Adselfservice Plus Jun 17, 2026 Jan 3, 2022 N/A· v4 5.3 MEDIUM· v3 5.0 MEDIUM· v2 ManageEngine ADSelfService Plus below build 6116 contains an observable response discrepancy in the UMCP operation of the ChangePasswordAPI. This allows an unauthenticated remote attacker to determine whether a Windows d...Show more |
1Utimf 1Uti Mutual Fund Invest Online Jun 17, 2026 Dec 23, 2021 N/A· v4 5.3 MEDIUM· v3 5.0 MEDIUM· v2 An issue was discovered in UTI Mutual fund Android application 5.4.18 and prior, allows attackers to brute force enumeration of usernames determined by the error message returned after invalid credentials are attempted. |
1Sonicwall 6Sma 100 Firmware Sma 200 FirmwareSma 210 Firmware+3 moreJun 17, 2026 Dec 23, 2021 N/A· v4 7.5 HIGH· v3 5.0 MEDIUM· v2 A vulnerability in SonicWall SMA100 password change API allows a remote unauthenticated attacker to perform SMA100 username enumeration based on the server responses. This vulnerability impacts 10.2.1.2-24sv, 10.2.0.8-37...Show more |
3Debian FedoraprojectGoogle3Chrome Debian LinuxFedoraJun 17, 2026 Dec 23, 2021 N/A· v4 6.5 MEDIUM· v3 4.3 MEDIUM· v2 Inappropriate implementation in cache in Google Chrome prior to 96.0.4664.45 allowed a remote attacker to leak cross-origin data via a crafted HTML page. |
1Dalmark 1Systeam Enterprise Resource Planning Jun 17, 2026 Dec 21, 2021 N/A· v4 5.3 MEDIUM· v3 5.0 MEDIUM· v2 Dalmark Systems Systeam 2.22.8 build 1724 is vulnerable to User enumeration. The Systeam application is an ERP system that uses a mixed architecture based on SaaS tenant and user management, and on-premise database and w...Show more |
1Dalmark 1Systeam Enterprise Resource Planning Jun 17, 2026 Dec 21, 2021 N/A· v4 5.3 MEDIUM· v3 5.0 MEDIUM· v2 Dalmark Systems Systeam 2.22.8 build 1724 is vulnerable to User enumeration. The Systeam application is an ERP system that uses a mixed architecture based on SaaS tenant and user management, and on-premise database and w...Show more |
1Cybelesoft 1Thinfinity Virtualui Jun 17, 2026 Dec 20, 2021 N/A· v4 5.3 MEDIUM· v3 5.0 MEDIUM· v2 Thinfinity VirtualUI before 3.0 allows a malicious actor to enumerate users registered in the OS (Windows) through the /changePassword URI. By accessing the vector, an attacker can determine if a username exists thanks t...Show more |
In getMimeGroup of PackageManagerService.java, there is a possible way to determine whether an app is installed, without query permissions, due to side channel information disclosure. This could lead to local information...Show more |
In cancelNotificationsFromListener of NotificationManagerService.java, there is a possible way to determine whether an app is installed, without query permissions, due to side channel information disclosure. This could l...Show more |
In setNotificationsShownFromListener of NotificationManagerService.java, there is a possible way to determine whether an app is installed, without query permissions, due to side channel information disclosure. This could...Show more |
In startRanging of RttServiceImpl.java, there is a possible way to determine whether an app is installed, without query permissions, due to side channel information disclosure. This could lead to local information disclo...Show more |
In adjustStreamVolume of AudioService.java, there is a possible way to determine whether an app is installed, without query permissions, due to side channel information disclosure. This could lead to local information di...Show more |
In getMeidForSlot of PhoneInterfaceManager.java, there is a possible way to determine whether an app is installed, without query permissions, due to side channel information disclosure. This could lead to local informati...Show more |
In getNetworkTypeForSubscriber of PhoneInterfaceManager.java, there is a possible way to determine whether an app is installed, without query permissions, due to side channel information disclosure. This could lead to lo...Show more |