CWE-203
751 CVEs • Abstraction: Base
Observable Discrepancy
The product behaves differently or sends different responses under different circumstances in a way that is observable to an unauthorized actor, which exposes security-relevant information about the state of the product, such as whether a particular operation was successful or not.
CVEs (751)
CVE VENDORS PRODUCTS UPDATED PUBLISHED CVSS |
|---|
2Debian Erlang2Debian Linux Erlang/otpMay 13, 2026 Dec 12, 2017 N/A· v4 5.9 MEDIUM· v3 4.3 MEDIUM· v2 The Erlang otp TLS server answers with different TLS alerts to different error types in the RSA PKCS #1 1.5 padding. This allows an attacker to decrypt content or sign messages with the server's private key (this is a va...Show more |
1F5 9Big Ip Afm Big Ip AnalyticsBig Ip Apm+6 moreMay 13, 2026 Nov 17, 2017 N/A· v4 7.4 HIGH· v3 4.3 MEDIUM· v2 On BIG-IP versions 11.6.0-11.6.2 (fixed in 11.6.2 HF1), 12.0.0-12.1.2 HF1 (fixed in 12.1.2 HF2), or 13.0.0-13.0.0 HF2 (fixed in 13.0.0 HF3) a virtual server configured with a Client SSL profile may be vulnerable to an Ad...Show more |
2Google Redhat4Chrome Enterprise Linux DesktopEnterprise Linux Server+1 moreMay 13, 2026 Oct 27, 2017 N/A· v4 5.3 MEDIUM· v3 2.6 LOW· v2 A timing attack in SVG rendering in Google Chrome prior to 60.0.3112.78 for Linux, Windows, and Mac allowed a remote attacker to extract pixel values from a cross-origin page being iframe'd via a crafted HTML page. |
6Apache CanonicalDebian+3 more15Communications Diameter Signaling Router Debian LinuxEnterprise Linux Desktop+12 moreMay 13, 2026 Aug 10, 2017 N/A· v4 5.9 MEDIUM· v3 4.3 MEDIUM· v2 The Realm implementations in Apache Tomcat versions 9.0.0.M1 to 9.0.0.M9, 8.5.0 to 8.5.4, 8.0.0.RC1 to 8.0.36, 7.0.0 to 7.0.70 and 6.0.0 to 6.0.45 did not process the supplied password if the supplied user name did not e...Show more |
1Apple 4Iphone Os SafariTvos+1 moreMay 13, 2026 Jul 20, 2017 N/A· v4 5.3 MEDIUM· v3 2.6 LOW· v2 An issue was discovered in certain Apple products. iOS before 10.3.3 is affected. Safari before 10.1.2 is affected. tvOS before 10.2.2 is affected. The issue involves the "WebKit" component. It allows remote attackers to...Show more |
3Debian EclipseOracle7Communications Cloud Native Core Policy Debian LinuxEnterprise Manager Base Platform+4 moreMay 13, 2026 Jun 16, 2017 N/A· v4 7.5 HIGH· v3 5.0 MEDIUM· v2 Jetty through 9.4.x is prone to a timing channel in util/security/Password.java, which makes it easier for remote attackers to obtain access by observing elapsed times before rejection of incorrect passwords. |
WatchGuard Fireware allows user enumeration, e.g., in the Firebox XML-RPC login handler. A login request that contains a blank password sent to the XML-RPC agent in Fireware v11.12.1 and earlier returns different respons...Show more |
3Canonical Nettle ProjectRedhat6Enterprise Linux Desktop Enterprise Linux Hpc NodeEnterprise Linux Server+3 moreMay 13, 2026 Apr 14, 2017 N/A· v4 7.5 HIGH· v3 5.0 MEDIUM· v2 The RSA and DSA decryption code in Nettle makes it easier for attackers to discover private keys via a cache side channel attack. |
1Revive Adserver 1Revive Adserver May 13, 2026 Mar 28, 2017 N/A· v4 5.3 MEDIUM· v3 5.0 MEDIUM· v2 Revive Adserver before 3.2.3 suffers from Information Exposure Through Discrepancy. It is possible to check whether or not an email address was associated to one or more user accounts on a target Revive Adserver instance...Show more |
6Canonical DebianNodejs+3 more7Debian Linux LinuxLinux Enterprise+4 moreMay 6, 2026 Jun 20, 2016 N/A· v4 5.5 MEDIUM· v3 2.1 LOW· v2 The dsa_sign_setup function in crypto/dsa/dsa_ossl.c in OpenSSL through 1.0.2h does not properly ensure the use of constant-time operations, which makes it easier for local users to discover a DSA private key via a timin...Show more |
4Canonical MozillaOracle+1 more15Enterprise Linux Desktop Enterprise Linux EusEnterprise Linux Server+12 moreApr 29, 2026 Feb 8, 2013 N/A· v4 N/A· v3 4.3 MEDIUM· v2 The TLS implementation in Mozilla Network Security Services (NSS) does not properly consider timing side-channel attacks on a noncompliant MAC check operation during the processing of malformed CBC padding, which allows...Show more |
The web mail service in Woppoware PostMaster 4.2.2 (build 3.2.5) generates different error messages depending on whether a user exists or not, which allows remote attackers to determine valid usernames. |
The NPSVG3.dll ActiveX control for Adobe SVG Viewer 3.02 and earlier, when running on Internet Explorer, allows remote attackers to determine the existence of arbitrary files by setting the src property to the target fil...Show more |
The firewall in Astaro Security Linux before 4.024 sends responses to SYN-FIN packets, which makes it easier for remote attackers to obtain information about the system and construct specialized attacks. |
Nettica Corporation INTELLIPEER Email Server 1.01 displays different error messages for valid and invalid account names, which allows remote attackers to determine valid account names. |
ArGoSoft FTP before 1.4.2.1 generates an error message if the user name does not exist instead of prompting for a password, which allows remote attackers to determine valid usernames. |
1Yabbforumsoftware 1Yet Another Bulletin Board Apr 16, 2026 Nov 23, 2004 N/A· v4 N/A· v3 5.0 MEDIUM· v2 YaBB 1 SP 1.3.1 displays different error messages when a user exists or not, which makes it easier for remote attackers to identify valid users and conduct a brute force password guessing attack. |
AIX 4.3.3 through AIX 5.1, when direct remote login is disabled, displays a different message if the password is correct, which allows remote attackers to guess the password via brute force methods. |
CVS 1.11.x before 1.11.17, and 1.12.x before 1.12.9, allows remote attackers to determine the existence of arbitrary files and directories via the -X command for an alternate history file, which causes different error me...Show more |
ProFTPD 1.2.x, including 1.2.8 and 1.2.10, responds in a different amount of time when a given username exists, which allows remote attackers to identify valid usernames by timing the server response. |