CWE-203
751 CVEs • Abstraction: Base
Observable Discrepancy
The product behaves differently or sends different responses under different circumstances in a way that is observable to an unauthorized actor, which exposes security-relevant information about the state of the product, such as whether a particular operation was successful or not.
CVEs (751)
CVE VENDORS PRODUCTS UPDATED PUBLISHED CVSS |
|---|
1Qualcomm 54Apq8009 Firmware Apq8017 FirmwareApq8053 Firmware+51 moreJun 17, 2026 Jun 2, 2020 N/A· v4 5.5 MEDIUM· v3 2.1 LOW· v2 Using non-time-constant functions like memcmp to compare sensitive data can lead to information leakage through timing side channel issue. in Snapdragon Auto, Snapdragon Compute, Snapdragon Connectivity, Snapdragon Consu...Show more |
1Aviatrix 2Controller Vpn ClientJun 17, 2026 May 22, 2020 N/A· v4 5.3 MEDIUM· v3 5.0 MEDIUM· v2 An issue was discovered in Aviatrix Controller before 5.4.1204. There is a Observable Response Discrepancy from the API, which makes it easier to perform user enumeration via brute force. |
4Debian FedoraprojectGoogle+1 more5Backports Sle ChromeDebian Linux+2 moreJun 17, 2026 May 21, 2020 N/A· v4 6.5 MEDIUM· v3 4.3 MEDIUM· v2 Insufficient policy enforcement in Blink in Google Chrome prior to 83.0.4103.61 allowed a remote attacker to obtain potentially sensitive information from process memory via a crafted HTML page. |
In TYPO3 CMS versions 10.4.0 and 10.4.1, it has been discovered that time-based attacks can be used with the password reset functionality for backend users. This allows an attacker to mount user enumeration based on emai...Show more |
1Qualcomm 49Apq8009 Firmware Apq8017 FirmwareApq8053 Firmware+46 moreJun 17, 2026 Apr 16, 2020 N/A· v4 5.5 MEDIUM· v3 4.9 MEDIUM· v2 Due to the use of non-time-constant comparison functions there is issue in timing side channels which can be used as a potential side channel for SUI corruption in Snapdragon Auto, Snapdragon Compute, Snapdragon Connecti...Show more |
1Qualcomm 52Apq8009 Firmware Apq8016 FirmwareApq8017 Firmware+49 moreJun 17, 2026 Apr 16, 2020 N/A· v4 5.5 MEDIUM· v3 2.1 LOW· v2 Side channel issue in QTEE due to usage of non-time-constant comparison function such as memcmp or strcmp in Snapdragon Auto, Snapdragon Compute, Snapdragon Connectivity, Snapdragon Consumer Electronics Connectivity, Sna...Show more |
4Arm DebianFedoraproject+1 more4Debian Linux FedoraMbed Tls+1 moreJun 17, 2026 Apr 15, 2020 N/A· v4 4.7 MEDIUM· v3 1.9 LOW· v2 An issue was discovered in Arm Mbed TLS before 2.16.6 and 2.7.x before 2.7.15. An attacker that can get precise enough side-channel measurements can recover the long-term ECDSA private key by (1) reconstructing the proje...Show more |
wolfSSL 4.3.0 has mulmod code in wc_ecc_mulmod_ex in ecc.c that does not properly resist timing side-channel attacks. |
Fixed in v1.5.1, Argo version v1.5.0 was vulnerable to a user-enumeration vulnerability which allowed attackers to determine the usernames of valid (non-SSO) accounts because /api/v1/session returned 401 for an existing...Show more |
An issue was discovered in Zammad 3.0 through 3.2. The Forgot Password functionality is implemented in a way that would enable an anonymous user to guess valid user emails. In the current implementation, the application...Show more |
LabVantage LIMS 8.3 does not properly maintain the confidentiality of database names. For example, the web application exposes the database name. An attacker might be able to enumerate database names by providing his own...Show more |
In the Voatz application 2020-01-01 for Android, the amount of data transmitted during a single voter's vote depends on the different lengths of the metadata across the available voting choices, which makes it easier for...Show more |
6Debian FedoraprojectGoogle+3 more8Backports Sle ChromeDebian Linux+5 moreJun 17, 2026 Feb 11, 2020 N/A· v4 6.5 MEDIUM· v3 4.3 MEDIUM· v2 Inappropriate implementation in CORS in Google Chrome prior to 80.0.3987.87 allowed a remote attacker to leak cross-origin data via a crafted HTML page. |
1Webcalendar Project 1Webcalendar Nov 21, 2024 Feb 4, 2020 N/A· v4 5.3 MEDIUM· v3 5.0 MEDIUM· v2 webcalendar before 1.2.7 shows the reason for a failed login (e.g., "no such user"). |
Jenkins 2.218 and earlier, LTS 2.204.1 and earlier used a non-constant time comparison function when validating an HMAC. |
Jenkins 2.218 and earlier, LTS 2.204.1 and earlier did not use a constant-time comparison function for validating connection secrets, which could potentially allow an attacker to use a timing attack to obtain this secret...Show more |
1Proxmox 1Virtual Environment Nov 21, 2024 Jan 27, 2020 N/A· v4 5.3 MEDIUM· v3 5.0 MEDIUM· v2 Proxmox VE prior to 3.2: 'AccessControl.pm' User Enumeration Vulnerability |
Tornado before 3.2.2 sends arbitrary responses that contain a fixed CSRF token and may be sent with HTTP compression, which makes it easier for remote attackers to conduct a BREACH attack and determine this token via a s...Show more |
An issue was discovered in ConnectWise Control (formerly known as ScreenConnect) 19.3.25270.7185. There is a user enumeration vulnerability, allowing an unauthenticated attacker to determine with certainty if an account...Show more |
3Arm DebianFedoraproject4Debian Linux FedoraMbed Crypto+1 moreJun 17, 2026 Jan 23, 2020 N/A· v4 4.7 MEDIUM· v3 1.9 LOW· v2 The ECDSA signature implementation in ecdsa.c in Arm Mbed Crypto 2.1 and Mbed TLS through 2.19.1 does not reduce the blinded scalar before computing the inverse, which allows a local attacker to recover the private key v...Show more |