CWE-203
751 CVEs • Abstraction: Base
Observable Discrepancy
The product behaves differently or sends different responses under different circumstances in a way that is observable to an unauthorized actor, which exposes security-relevant information about the state of the product, such as whether a particular operation was successful or not.
CVEs (751)
CVE VENDORS PRODUCTS UPDATED PUBLISHED CVSS |
|---|
3Arm DebianFedoraproject3Debian Linux FedoraMbed TlsJun 17, 2026 Sep 2, 2020 N/A· v4 5.5 MEDIUM· v3 2.1 LOW· v2 A Lucky 13 timing side channel in mbedtls_ssl_decrypt_buf in library/ssl_msg.c in Trusted Firmware Mbed TLS through 2.23.0 allows an attacker to recover secret key information. This affects CBC mode because of a computed...Show more |
An issue was discovered on LG mobile devices with Android OS 4.4, 5.0, 5.1, 6.0, 7.0, 7.1, 8.0, 8.1, 9.0, and 10 software. Key logging may occur because of an obsolete API. The LG ID is LVE-SMP-170010 (August 2020). |
Umanni RH 1.0 has a user enumeration vulnerability. This issue occurs during password recovery, where a difference in messages could allow an attacker to determine if the user is valid or not, enabling a brute force atta...Show more |
2Magento Openmage2Magento Openmage Long Term SupportJun 17, 2026 Aug 20, 2020 N/A· v4 8.0 HIGH· v3 4.0 MEDIUM· v2 OpenMage LTS before versions 19.4.6 and 20.0.2 allows attackers to circumvent the `fromkey protection` in the Admin Interface and increases the attack surface for Cross Site Request Forgery attacks. This issue is related...Show more |
An information disclosure vulnerability exists on ARM implementations that use speculative execution in control flow via a side-channel analysis, aka "straight-line speculation." To exploit this vulnerability,...Show more |
1P5 Crypt Perl Project 1P5 Crypt Perl Jun 17, 2026 Aug 10, 2020 N/A· v4 7.5 HIGH· v3 5.0 MEDIUM· v2 ECDSA/EC/Point.pm in Crypt::Perl before 0.33 does not properly consider timing attacks against the EC point multiplication algorithm. |
Magento versions 2.3.5-p1 and earlier, and 2.3.5-p1 and earlier have an observable timing discrepancy vulnerability. Successful exploitation could lead to signature verification bypass. |
1Avertx 2Hd438 Firmware Hd838 FirmwareJun 17, 2026 Jul 23, 2020 N/A· v4 5.3 MEDIUM· v3 5.0 MEDIUM· v2 An issue was discovered in AvertX Auto focus Night Vision HD Indoor/Outdoor IP Dome Camera HD838 and Night Vision HD Indoor/Outdoor Mini IP Bullet Camera HD438. Failed web UI login attempts elicit different responses dep...Show more |
4Debian FedoraprojectGoogle+1 more5Backports Sle ChromeDebian Linux+2 moreJun 17, 2026 Jul 22, 2020 N/A· v4 4.3 MEDIUM· v3 4.3 MEDIUM· v2 Side-channel information leakage in scroll to text in Google Chrome prior to 84.0.4147.89 allowed a remote attacker to leak cross-origin data via a crafted HTML page. |
2Linux Redhat2Enterprise Linux Linux KernelJun 17, 2026 Jul 13, 2020 N/A· v4 5.5 MEDIUM· v3 2.1 LOW· v2 A flaw was found in the fix for CVE-2019-11135, in the Linux upstream kernel versions before 5.5 where, the way Intel CPUs handle speculative execution of instructions when a TSX Asynchronous Abort (TAA) error occurs. Wh...Show more |
4Debian FedoraprojectMozilla+1 more4Debian Linux FedoraFirefox+1 moreJun 17, 2026 Jul 9, 2020 N/A· v4 4.4 MEDIUM· v3 1.2 LOW· v2 During RSA key generation, bignum implementations used a variation of the Binary Extended Euclidean Algorithm which entailed significantly input-dependent flow. This allowed an attacker able to perform electromagnetic-ba...Show more |
2Debian Mozilla4Debian Linux FirefoxFirefox Esr+1 moreJun 17, 2026 Jul 9, 2020 N/A· v4 4.4 MEDIUM· v3 1.2 LOW· v2 NSS has shown timing differences when performing DSA signatures, which was exploitable and could eventually leak private keys. This vulnerability affects Thunderbird < 68.9.0, Firefox < 77, and Firefox ESR < 68.9. |
A user enumeration vulnerability flaw was found in Venki Supravizio BPM 10.1.2. This issue occurs during password recovery, where a difference in error messages could allow an attacker to determine if a username is valid...Show more |
2Netapp Openbsd9Active Iq Unified Manager Aff A700s FirmwareHci Compute Node+6 moreJun 17, 2026 Jun 29, 2020 N/A· v4 5.9 MEDIUM· v3 4.3 MEDIUM· v2 The client side in OpenSSH 5.7 through 8.4 has an Observable Discrepancy leading to an information leak in the algorithm negotiation. This allows man-in-the-middle attackers to target initial connection attempts (where n...Show more |
3Fedoraproject NetappPutty3Fedora Oncommand Unified Manager Core PackagePuttyJun 17, 2026 Jun 29, 2020 N/A· v4 5.9 MEDIUM· v3 4.3 MEDIUM· v2 PuTTY 0.68 through 0.73 has an Observable Discrepancy leading to an information leak in the algorithm negotiation. This allows man-in-the-middle attackers to target initial connection attempts (where no host key for the...Show more |
Magento versions 2.3.4 and earlier, 2.2.11 and earlier (see note), 1.14.4.4 and earlier, and 1.9.4.4 and earlier have an observable timing discrepancy vulnerability. Successful exploitation could lead to signature verifi...Show more |
The private-key operations in ecc.c in wolfSSL before 4.4.0 do not use a constant-time modular inverse when mapping to affine coordinates, aka a "projective coordinates leak." |
1Atlassian 2Jira Jira Software Data CenterJun 17, 2026 Jun 23, 2020 N/A· v4 5.3 MEDIUM· v3 5.0 MEDIUM· v2 Versions before 8.9.1, Various resources in Jira responded with a 404 instead of redirecting unauthenticated users to the login page, in some situations this may have allowed unauthorised attackers to determine if certai...Show more |
Citrix XenApp 6.5, when 2FA is enabled, allows a remote unauthenticated attacker to ascertain whether a user exists on the server, because the 2FA error page only occurs after a valid username is entered. NOTE: This vuln...Show more |
2Arm Opensuse8Cortex A32 Firmware Cortex A34 FirmwareCortex A35 Firmware+5 moreJun 17, 2026 Jun 8, 2020 N/A· v4 5.5 MEDIUM· v3 2.1 LOW· v2 Arm Armv8-A core implementations utilizing speculative execution past unconditional changes in control flow may allow unauthorized disclosure of information to an attacker with local user access via a side-channel analys...Show more |