CWE-203
781 CVEs • Abstraction: Base
Observable Discrepancy
The product behaves differently or sends different responses under different circumstances in a way that is observable to an unauthorized actor, which exposes security-relevant information about the state of the product, such as whether a particular operation was successful or not.
CVEs (781)
CVE VENDORS PRODUCTS UPDATED PUBLISHED CVSS |
|---|
1Broadcom 1Ssl Visibility Appliance Nov 21, 2024 May 17, 2018 N/A· v4 5.9 MEDIUM· v3 4.3 MEDIUM· v2 Symantec SSL Visibility (SSLV) 3.8.4FC, 3.10 prior to 3.10.4.1, 3.11, and 3.12 prior to 3.12.2.1 are vulnerable to the Return of the Bleichenbacher Oracle Threat (ROBOT) attack. All affected SSLV versions act as weak ora...Show more |
1Synacor 1Zimbra Collaboration Suite Nov 21, 2024 May 10, 2018 N/A· v4 5.3 MEDIUM· v3 5.0 MEDIUM· v2 mailboxd in Zimbra Collaboration Suite 8.8 before 8.8.8; 8.7 before 8.7.11.Patch3; and 8.6 allows Account Enumeration by leveraging a Discrepancy between the "HTTP 404 - account is not active" and "HTTP 401 - must authen...Show more |
1Sinatrarb 1Rack Protection Nov 21, 2024 Mar 7, 2018 N/A· v4 5.9 MEDIUM· v3 4.3 MEDIUM· v2 Sinatra rack-protection versions 1.5.4 and 2.0.0.rc3 and earlier contains a timing attack vulnerability in the CSRF token checking that can result in signatures can be exposed. This attack appear to be exploitable via ne...Show more |
1Cisco 1Mobility Services Engine Nov 21, 2024 Feb 8, 2018 N/A· v4 5.3 MEDIUM· v3 5.0 MEDIUM· v2 A vulnerability in the RADIUS authentication module of Cisco Policy Suite could allow an unauthenticated, remote attacker to determine whether a subscriber username is valid. The vulnerability occurs because the Cisco Po...Show more |
13Arm CanonicalDebian+10 more308Atom C Atom EAtom X3+305 moreMay 28, 2026 Jan 4, 2018 N/A· v4 5.6 MEDIUM· v3 4.7 MEDIUM· v2 Systems with microprocessors utilizing speculative execution and branch prediction may allow unauthorized disclosure of information to an attacker with local user access via a side-channel analysis. |
7Arm CanonicalDebian+4 more220Atom C Atom EAtom X3+217 moreMay 6, 2025 Jan 4, 2018 N/A· v4 5.6 MEDIUM· v3 1.9 LOW· v2 Systems with microprocessors utilizing speculative execution and indirect branch prediction may allow unauthorized disclosure of information to an attacker with local user access via a side-channel analysis. |
1Cisco 5Adaptive Security Appliance 5505 Firmware Adaptive Security Appliance 5510 FirmwareAdaptive Security Appliance 5520 Firmware+2 moreMay 13, 2026 Dec 15, 2017 N/A· v4 5.9 MEDIUM· v3 4.3 MEDIUM· v2 A vulnerability in the TLS protocol implementation of legacy Cisco ASA 5500 Series (ASA 5505, 5510, 5520, 5540, and 5550) devices could allow an unauthenticated, remote attacker to access sensitive information, aka a Ret...Show more |
Radware Alteon devices with a firmware version between 31.0.0.0-31.0.3.0 are vulnerable to an adaptive-chosen ciphertext attack ("Bleichenbacher attack"). This allows an attacker to decrypt observed traffic that has been...Show more |
3Arubanetworks SiemensWolfssl3Instant Scalance W1750d FirmwareWolfsslMay 13, 2026 Dec 13, 2017 N/A· v4 5.9 MEDIUM· v3 4.3 MEDIUM· v2 wolfSSL prior to version 3.12.2 provides a weak Bleichenbacher oracle when any TLS cipher suite using RSA key exchange is negotiated. An attacker can recover the private key from a vulnerable wolfSSL application. This vu...Show more |
BouncyCastle TLS prior to version 1.0.3, when configured to use the JCE (Java Cryptography Extension) for cryptographic functions, provides a weak Bleichenbacher oracle when any TLS cipher suite using RSA key exchange is...Show more |
2Debian Erlang2Debian Linux Erlang/otpMay 13, 2026 Dec 12, 2017 N/A· v4 5.9 MEDIUM· v3 4.3 MEDIUM· v2 The Erlang otp TLS server answers with different TLS alerts to different error types in the RSA PKCS #1 1.5 padding. This allows an attacker to decrypt content or sign messages with the server's private key (this is a va...Show more |
1F5 9Big Ip Afm Big Ip AnalyticsBig Ip Apm+6 moreMay 13, 2026 Nov 17, 2017 N/A· v4 7.4 HIGH· v3 4.3 MEDIUM· v2 On BIG-IP versions 11.6.0-11.6.2 (fixed in 11.6.2 HF1), 12.0.0-12.1.2 HF1 (fixed in 12.1.2 HF2), or 13.0.0-13.0.0 HF2 (fixed in 13.0.0 HF3) a virtual server configured with a Client SSL profile may be vulnerable to an Ad...Show more |
2Google Redhat4Chrome Enterprise Linux DesktopEnterprise Linux Server+1 moreMay 13, 2026 Oct 27, 2017 N/A· v4 5.3 MEDIUM· v3 2.6 LOW· v2 A timing attack in SVG rendering in Google Chrome prior to 60.0.3112.78 for Linux, Windows, and Mac allowed a remote attacker to extract pixel values from a cross-origin page being iframe'd via a crafted HTML page. |
6Apache CanonicalDebian+3 more15Communications Diameter Signaling Router Debian LinuxEnterprise Linux Desktop+12 moreMay 13, 2026 Aug 10, 2017 N/A· v4 5.9 MEDIUM· v3 4.3 MEDIUM· v2 The Realm implementations in Apache Tomcat versions 9.0.0.M1 to 9.0.0.M9, 8.5.0 to 8.5.4, 8.0.0.RC1 to 8.0.36, 7.0.0 to 7.0.70 and 6.0.0 to 6.0.45 did not process the supplied password if the supplied user name did not e...Show more |
1Apple 4Iphone Os SafariTvos+1 moreMay 13, 2026 Jul 20, 2017 N/A· v4 5.3 MEDIUM· v3 2.6 LOW· v2 An issue was discovered in certain Apple products. iOS before 10.3.3 is affected. Safari before 10.1.2 is affected. tvOS before 10.2.2 is affected. The issue involves the "WebKit" component. It allows remote attackers to...Show more |
3Debian EclipseOracle7Communications Cloud Native Core Policy Debian LinuxEnterprise Manager Base Platform+4 moreMay 13, 2026 Jun 16, 2017 N/A· v4 7.5 HIGH· v3 5.0 MEDIUM· v2 Jetty through 9.4.x is prone to a timing channel in util/security/Password.java, which makes it easier for remote attackers to obtain access by observing elapsed times before rejection of incorrect passwords. |
WatchGuard Fireware allows user enumeration, e.g., in the Firebox XML-RPC login handler. A login request that contains a blank password sent to the XML-RPC agent in Fireware v11.12.1 and earlier returns different respons...Show more |
3Canonical Nettle ProjectRedhat6Enterprise Linux Desktop Enterprise Linux Hpc NodeEnterprise Linux Server+3 moreMay 13, 2026 Apr 14, 2017 N/A· v4 7.5 HIGH· v3 5.0 MEDIUM· v2 The RSA and DSA decryption code in Nettle makes it easier for attackers to discover private keys via a cache side channel attack. |
1Revive Adserver 1Revive Adserver May 13, 2026 Mar 28, 2017 N/A· v4 5.3 MEDIUM· v3 5.0 MEDIUM· v2 Revive Adserver before 3.2.3 suffers from Information Exposure Through Discrepancy. It is possible to check whether or not an email address was associated to one or more user accounts on a target Revive Adserver instance...Show more |
6Canonical DebianNodejs+3 more7Debian Linux LinuxLinux Enterprise+4 moreMay 6, 2026 Jun 20, 2016 N/A· v4 5.5 MEDIUM· v3 2.1 LOW· v2 The dsa_sign_setup function in crypto/dsa/dsa_ossl.c in OpenSSL through 1.0.2h does not properly ensure the use of constant-time operations, which makes it easier for local users to discover a DSA private key via a timin...Show more |