CWE-203
751 CVEs • Abstraction: Base
Observable Discrepancy
The product behaves differently or sends different responses under different circumstances in a way that is observable to an unauthorized actor, which exposes security-relevant information about the state of the product, such as whether a particular operation was successful or not.
CVEs (751)
CVE VENDORS PRODUCTS UPDATED PUBLISHED CVSS |
|---|
Non-constant-time comparison of CSRF tokens in UIDL request handler in com.vaadin:flow-server versions 1.0.0 through 1.0.13 (Vaadin 10.0.0 through 10.0.16), 1.1.0 prior to 2.0.0 (Vaadin 11 prior to 14), 2.0.0 through 2.4...Show more |
Non-constant-time comparison of CSRF tokens in UIDL request handler in com.vaadin:vaadin-server versions 7.0.0 through 7.7.23 (Vaadin 7.0.0 through 7.7.23), and 8.0.0 through 8.12.2 (Vaadin 8.0.0 through 8.12.2) allows a...Show more |
1Jose Node Cjs Runtime Project 1Jose Node Cjs Runtime Jun 17, 2026 Apr 16, 2021 N/A· v4 5.9 MEDIUM· v3 4.3 MEDIUM· v2 jose-node-cjs-runtime is an npm package which provides a number of cryptographic functions. In versions prior to 3.11.4 the AES_CBC_HMAC_SHA2 Algorithm (A128CBC-HS256, A192CBC-HS384, A256CBC-HS512) decryption would alway...Show more |
1Jose Node Cjs Runtime Project 1Jose Node Cjs Runtime Jun 17, 2026 Apr 16, 2021 N/A· v4 5.9 MEDIUM· v3 4.3 MEDIUM· v2 jose-node-esm-runtime is an npm package which provides a number of cryptographic functions. In versions prior to 3.11.4 the AES_CBC_HMAC_SHA2 Algorithm (A128CBC-HS256, A192CBC-HS384, A256CBC-HS512) decryption would alway...Show more |
1Jose Node Cjs Runtime Project 1Jose Node Cjs Runtime Jun 17, 2026 Apr 16, 2021 N/A· v4 5.9 MEDIUM· v3 4.3 MEDIUM· v2 jose-browser-runtime is an npm package which provides a number of cryptographic functions. In versions prior to 3.11.4 the AES_CBC_HMAC_SHA2 Algorithm (A128CBC-HS256, A192CBC-HS384, A256CBC-HS512) decryption would always...Show more |
2Jose Project Panva2Jose JoseJun 22, 2026 Apr 16, 2021 N/A· v4 5.9 MEDIUM· v3 4.3 MEDIUM· v2 jose is an npm library providing a number of cryptographic operations. In vulnerable versions AES_CBC_HMAC_SHA2 Algorithm (A128CBC-HS256, A192CBC-HS384, A256CBC-HS512) decryption would always execute both HMAC tag verifi...Show more |
1Redhat 3389 Directory Server Directory ServerEnterprise LinuxJun 17, 2026 Mar 26, 2021 N/A· v4 5.3 MEDIUM· v3 5.0 MEDIUM· v2 When binding against a DN during authentication, the reply from 389-ds-base will be different whether the DN exists or not. This can be used by an unauthenticated attacker to check the existence of an entry in the LDAP d...Show more |
4Canonical DebianFedoraproject+1 more4Debian Linux FedoraLinux Kernel+1 moreJun 17, 2026 Mar 20, 2021 N/A· v4 4.7 MEDIUM· v3 1.9 LOW· v2 An issue was discovered in the Linux kernel before 5.11.8. kernel/bpf/verifier.c performs undesirable out-of-bounds speculation on pointer arithmetic, leading to side-channel attacks that defeat Spectre mitigations and o...Show more |
Apache Hive cookie signature verification used a non constant time comparison which is known to be vulnerable to timing attacks. This could allow recovery of another users cookie signature. The issue was addressed in Apa...Show more |
3Debian FedoraprojectGoogle3Chrome Debian LinuxFedoraJun 17, 2026 Mar 9, 2021 N/A· v4 6.5 MEDIUM· v3 4.3 MEDIUM· v2 Side-channel information leakage in autofill in Google Chrome prior to 89.0.4389.72 allowed a remote attacker to obtain potentially sensitive information from process memory via a crafted HTML page. |
3Debian FedoraprojectGoogle3Chrome Debian LinuxFedoraJun 17, 2026 Mar 9, 2021 N/A· v4 6.5 MEDIUM· v3 4.3 MEDIUM· v2 Side-channel information leakage in Network Internals in Google Chrome prior to 89.0.4389.72 allowed a remote attacker to leak cross-origin data via a crafted HTML page. |
In Directus 8.x through 8.8.1, an attacker can discover whether a user is present in the database through the password reset feature. NOTE: This vulnerability only affects products that are no longer supported by the mai...Show more |
1Qualcomm 329Aqt1000 Ar8031Ar8035+326 moreJun 17, 2026 Feb 22, 2021 N/A· v4 7.5 HIGH· v3 5.0 MEDIUM· v2 Allowing RTT frames to be linked with non randomized MAC address by comparing the sequence numbers can lead to information disclosure. in Snapdragon Auto, Snapdragon Compute, Snapdragon Connectivity, Snapdragon Consumer...Show more |
A username enumeration issue was discovered in SquaredUp before version 4.6.0. The login functionality was implemented in a way that would enable a malicious user to guess valid username due to a different response time...Show more |
In enforceDumpPermissionForPackage of ActivityManagerService.java, there is a possible way to determine if a package is installed due to side channel information disclosure. This could lead to local information disclosur...Show more |
An email address enumeration vulnerability exists in the password reset function of Rocket.Chat through 3.9.1. |
1Dropbear Ssh Project 1Dropbear Ssh Jun 17, 2026 Dec 30, 2020 N/A· v4 5.3 MEDIUM· v3 5.0 MEDIUM· v2 Dropbear 2011.54 through 2018.76 has an inconsistent failure delay that may lead to revealing valid usernames, a different issue than CVE-2018-15599. |
An issue was discovered in the SecurePoll extension for MediaWiki through 1.35.1. The non-admin vote list contains a full vote timestamp, which may provide unintended clues about how a voting process unfolded. |
3Debian FedoraprojectMediawiki3Debian Linux FedoraMediawikiJun 17, 2026 Dec 18, 2020 N/A· v4 5.3 MEDIUM· v3 5.0 MEDIUM· v2 An issue was discovered in MediaWiki before 1.35.1. Missing users (accounts that don't exist) and hidden users (accounts that have been explicitly hidden due to being abusive, or similar) that the viewer cannot see are h...Show more |
During boot, the device unlock interface behaves differently depending on if a fingerprint registered to the device is present. This could lead to local information disclosure with no additional execution privileges need...Show more |