CWE-203
751 CVEs • Abstraction: Base
Observable Discrepancy
The product behaves differently or sends different responses under different circumstances in a way that is observable to an unauthorized actor, which exposes security-relevant information about the state of the product, such as whether a particular operation was successful or not.
CVEs (751)
CVE VENDORS PRODUCTS UPDATED PUBLISHED CVSS |
|---|
Observable behavioral discrepancy vulnerability in QSAN Storage Manager allows remote attackers to obtain the system information without permissions. Suggest contacting with QSAN and refer to recommendations in QSAN Docu...Show more |
3Debian FedoraprojectIntel7Celeron Processors Firmware Core Processors FirmwareDebian Linux+4 moreJun 17, 2026 Jun 9, 2021 N/A· v4 6.5 MEDIUM· v3 2.1 LOW· v2 Observable response discrepancy in some Intel(R) Processors may allow an authorized user to potentially enable information disclosure via local access. |
2Fedoraproject Intel7Brand Verification Tool Celeron Processors FirmwareCore Processors Firmware+4 moreJun 17, 2026 Jun 9, 2021 N/A· v4 6.5 MEDIUM· v3 2.1 LOW· v2 Observable response discrepancy in floating-point operations for some Intel(R) Processors may allow an authorized user to potentially enable information disclosure via local access. |
1Intel 4Integrated Performance Primitives Cryptography Sgx DcapSgx Psw+1 moreJun 17, 2026 Jun 9, 2021 N/A· v4 4.7 MEDIUM· v3 2.1 LOW· v2 Observable timing discrepancy in Intel(R) IPP before version 2020 update 1 may allow authorized user to potentially enable information disclosure via local access. |
3Debian IntelNetapp5Debian Linux Fas/aff BiosHci Compute Node Bios+2 moreJun 17, 2026 Jun 9, 2021 N/A· v4 3.3 LOW· v3 2.1 LOW· v2 Observable timing discrepancy in some Intel(R) Processors may allow an authenticated user to potentially enable information disclosure via local access. |
5Arm BroadcomFedoraproject+2 more8Bcm2711 Core I7 10700kCore I7 7700k+5 moreJun 17, 2026 Jun 9, 2021 N/A· v4 5.5 MEDIUM· v3 2.1 LOW· v2 Potential floating point value injection in all supported CPU products, in conjunction with software vulnerabilities relating to speculative execution with incorrect floating point results, may cause the use of incorrect...Show more |
5Arm BroadcomDebian+2 more8Bcm2711 Core I7 10700kCore I7 7700k+5 moreJun 17, 2026 Jun 9, 2021 N/A· v4 5.5 MEDIUM· v3 2.1 LOW· v2 Potential speculative code store bypass in all supported CPU products, in conjunction with software vulnerabilities relating to speculative execution of overwritten instructions, may cause an incorrect speculation and co...Show more |
4Debian FedoraprojectGnupg+1 more8Communications Cloud Native Core Binding Support Function Communications Cloud Native Core Network Function Cloud Native EnvironmentCommunications Cloud Native Core Network Repository Function+5 moreJun 17, 2026 Jun 8, 2021 N/A· v4 7.5 HIGH· v3 5.0 MEDIUM· v2 Libgcrypt before 1.8.8 and 1.9.x before 1.9.3 mishandles ElGamal encryption because it lacks exponent blinding to address a side-channel attack against mpi_powm, and the window size is not chosen appropriately. This, for...Show more |
2Apache Dpgaspar2Airflow Flask AppbuilderJun 17, 2026 Jun 7, 2021 N/A· v4 5.3 MEDIUM· v3 5.0 MEDIUM· v2 Flask-AppBuilder is a development framework, built on top of Flask. User enumeration in database authentication in Flask-AppBuilder <= 3.2.3. Allows for a non authenticated user to enumerate existing accounts by timing t...Show more |
2Oracle Websockets Project5Communications Cloud Native Core Policy Communications Cloud Native Core Security Edge Protection ProxyCommunications Cloud Native Core Service Communication Proxy+2 moreJun 17, 2026 Jun 6, 2021 N/A· v4 5.9 MEDIUM· v3 2.6 LOW· v2 The aaugustin websockets library before 9.1 for Python has an Observable Timing Discrepancy on servers when HTTP Basic Authentication is enabled with basic_auth_protocol_factory(credentials=...). An attacker may be able...Show more |
Luca through 1.7.4 on Android allows remote attackers to obtain sensitive information about COVID-19 tracking because requests related to Check-In State occur shortly after requests for Phone Number Registration. |
An information disclosure vulnerability exists in the Rocket.Chat server fixed v3.13, v3.12.2 & v3.11.3 that allowed email addresses to be disclosed by enumeration and validation checks. |
Nordic Semiconductor nRF52840 devices through 2020-10-19 have improper protection against physical side channels. The flash read-out protection (APPROTECT) can be bypassed by injecting a fault during the boot phase. |
The elliptic curve cryptography (ECC) hardware accelerator, part of the ARM® TrustZone® CryptoCell 310, contained in the NordicSemiconductor nRF52840 through 2021-03-29 has a non-constant time ECDSA implemenation. This a...Show more |
1Ibm 1Security Identity Manager Jun 17, 2026 May 20, 2021 N/A· v4 5.3 MEDIUM· v3 5.0 MEDIUM· v2 IBM Security Identity Manager 7.0.2 could allow a remote user to enumerate usernames due to a difference of responses from valid and invalid login attempts. IBM X-Force ID: 200018 |
An authentication brute-force protection mechanism bypass in telnetd in D-Link Router model DIR-842 firmware version 3.0.2 allows a remote attacker to circumvent the anti-brute-force cool-down delay period via a timing-b...Show more |
2Fedoraproject Sensiolabs2Fedora SymfonyJun 17, 2026 May 13, 2021 N/A· v4 5.3 MEDIUM· v3 5.0 MEDIUM· v2 Symfony is a PHP framework for web and console applications and a set of reusable PHP components. The ability to enumerate users was possible without relevant permissions due to different handling depending on whether th...Show more |
1Cisco 2Catalyst Sd Wan Manager Sd Wan VmanageJun 17, 2026 May 6, 2021 N/A· v4 5.3 MEDIUM· v3 5.0 MEDIUM· v2 A vulnerability in Cisco SD-WAN vManage Software could allow an unauthenticated, remote attacker to enumerate user accounts. This vulnerability is due to the improper handling of HTTP headers. An attacker could exploit t...Show more |
2Debian Redmine2Debian Linux RedmineJun 17, 2026 Apr 28, 2021 N/A· v4 5.3 MEDIUM· v3 5.0 MEDIUM· v2 Redmine before 4.0.9 and 4.1.x before 4.1.3 allows an attacker to learn the values of internal authentication keys by observing timing differences in string comparison operations within SysController and MailHandlerContr...Show more |
Non-constant-time comparison of CSRF tokens in endpoint request handler in com.vaadin:flow-server versions 3.0.0 through 5.0.3 (Vaadin 15.0.0 through 18.0.6), and com.vaadin:fusion-endpoint version 6.0.0 (Vaadin 19.0.0)...Show more |