CWE-203— Observable Discrepancy (Information Exposure via Side Channel)
The product behaves differently or sends different responses under different circumstances in a way that is observable to an unauthorized actor.— MITRE CWE catalog
832 active CVEs classified under this weakness category. Sourced from NVD, GHSA, and vendor advisories. Full definition on MITRE →
CVEs classified under CWE-203page 16 of 17
- CVE-2024-13198LOWCVSS 3.7EG 3.72025-01-09
A vulnerability classified as problematic has been found in langhsu Mblog Blog System 3.5.0. Affected is an unknown function of the file /login. The manipulation leads to observable response discrepancy. It is possible to launch the attack…
- CVE-2024-13028LOWCVSS 3.7EG 3.72024-12-29
A vulnerability, which was classified as problematic, has been found in Antabot White-Jotter up to 0.2.2. This issue affects some unknown processing of the file /login. The manipulation of the argument username leads to observable response…
- CVE-2024-12663LOWCVSS 3.7EG 3.72024-12-16
A vulnerability classified as problematic was found in funnyzpc Mee-Admin up to 1.6. This vulnerability affects unknown code of the file /mee/login of the component Login. The manipulation of the argument username leads to observable respo…
- CVE-2024-21210LOWCVSS 3.7EG 3.72024-10-15
Vulnerability in Oracle Java SE (component: Hotspot). Supported versions that are affected are Oracle Java SE: 8u421, 8u421-perf, 11.0.24, 17.0.12, 21.0.4 and 23. Difficult to exploit vulnerability allows unauthenticated attacker with ne…
- CVE-2024-21208LOWCVSS 3.7EG 3.72024-10-15
Vulnerability in the Oracle Java SE, Oracle GraalVM for JDK, Oracle GraalVM Enterprise Edition product of Oracle Java SE (component: Networking). Supported versions that are affected are Oracle Java SE: 8u421, 8u421-perf, 11.0.24, 17.0.12…
- CVE-2024-47869LOWCVSS 3.7EG 3.72024-10-10
Gradio is an open-source Python package designed for quick prototyping. This vulnerability involves a **timing attack** in the way Gradio compares hashes for the `analytics_dashboard` function. Since the comparison is not done in constant …
- CVE-2023-36325LOWCVSS 3.7EG 3.72024-10-09
i2p before 2.3.0 (Java) allows de-anonymizing the public IPv4 and IPv6 addresses of i2p hidden services (aka eepsites) via a correlation attack across the IPv4 and IPv6 addresses that occurs when a tunneled, replayed message has a behavior…
- CVE-2024-9513LOWCVSS 3.7EG 3.72024-10-04
A vulnerability was found in Netadmin Software NetAdmin IAM up to 3.5 and classified as problematic. Affected by this issue is some unknown functionality of the file /controller/api/Answer/ReturnUserQuestionsFilled of the component HTTP PO…
- CVE-2024-6129LOWCVSS 3.7EG 3.72024-06-18
A vulnerability, which was classified as problematic, was found in spa-cartcms 1.9.0.6. Affected is an unknown function of the file /login of the component Username Handler. The manipulation of the argument email leads to observable behavi…
- CVE-2024-6056LOWCVSS 3.7EG 3.72024-06-17
A vulnerability was found in nasirkhan Laravel Starter up to 11.8.0. It has been rated as problematic. Affected by this issue is some unknown functionality of the file /forgot-password of the component Password Reset Handler. The manipulat…
- CVE-2024-28868LOWCVSS 3.7EG 3.72024-03-20
Umbraco is an ASP.NET content management system. Umbraco 10 prior to 10.8.4 with access to the native login screen is vulnerable to a possible user enumeration attack. This issue was fixed in version 10.8.5. As a workaround, one may disabl…
- CVE-2024-21671LOWCVSS 3.7EG 3.72024-01-30
The vantage6 technology enables to manage and deploy privacy enhancing technologies like Federated Learning (FL) and Multi-Party Computation (MPC). It is possible to find out usernames from the response time of login requests. This could …
- CVE-2022-41914LOWCVSS 3.7EG 3.72022-11-16
Zulip is an open-source team collaboration tool. For organizations with System for Cross-domain Identity Management(SCIM) account management enabled, Zulip Server 5.0 through 5.6 checked the SCIM bearer token using a comparator that did no…
- CVE-2022-24784LOWCVSS 3.7EG 3.72022-03-25
Statamic is a Laravel and Git powered CMS. Before versions 3.2.39 and 3.3.2, it is possible to confirm a single character of a user's password hash using a specially crafted regular expression filter in the users endpoint of the REST API. …
- CVE-2020-9389LOWCVSS 3.7EG 3.72021-02-03
A username enumeration issue was discovered in SquaredUp before version 4.6.0. The login functionality was implemented in a way that would enable a malicious user to guess valid username due to a different response time from invalid userna…
- CVE-2020-3585LOWCVSS 3.7EG 3.72020-10-21
A vulnerability in the TLS handler of Cisco Adaptive Security Appliance (ASA) Software and Cisco Firepower Threat Defense (FTD) Software for Cisco Firepower 1000 Series firewalls could allow an unauthenticated, remote attacker to gain acce…
- CVE-2020-1968LOWCVSS 3.7EG 3.72020-09-09
The Raccoon attack exploits a flaw in the TLS specification which can lead to an attacker being able to compute the pre-master secret in connections which have used a Diffie-Hellman (DH) based ciphersuite. In such a case this would result …
- CVE-2020-11063LOWCVSS 3.7EG 3.72020-05-13
In TYPO3 CMS versions 10.4.0 and 10.4.1, it has been discovered that time-based attacks can be used with the password reset functionality for backend users. This allows an attacker to mount user enumeration based on email addresses assigne…
- CVE-2019-11743LOWCVSS 3.7EG 3.72019-09-27
Navigation events were not fully adhering to the W3C's "Navigation-Timing Level 2" draft specification in some instances for the unload event, which restricts access to detailed timing attributes to only be same-origin. This resulted in po…
- CVE-2019-1563LOWCVSS 3.7EG 3.72019-09-10
In situations where an attacker receives automated notification of the success or failure of a decryption attempt an attacker, after sending a very large number of messages to be decrypted, can recover a CMS/PKCS7 transported encryption ke…
- CVE-2019-9495LOWCVSS 3.7EG 3.72019-04-17
The implementations of EAP-PWD in hostapd and wpa_supplicant are vulnerable to side-channel attacks as a result of cache access patterns. All versions of hostapd and wpa_supplicant with EAP-PWD support are vulnerable. The ability to instal…
- CVE-2025-46804LOWCVSS 3.3EG 3.32025-05-26
A minor information leak when running Screen with setuid-root privileges allows unprivileged users to deduce information about a path that would otherwise not be available. Affected are older Screen versions, as well as version 5.0.0.
- CVE-2024-47150LOWCVSS 3.3EG 3.32024-12-26
Some Honor products are affected by information leak vulnerability, successful exploitation could cause the information leak.
- CVE-2024-47149LOWCVSS 3.3EG 3.32024-12-26
Some Honor products are affected by incorrect privilege assignment vulnerability, successful exploitation could cause device service exceptions.
- CVE-2024-47156LOWCVSS 3.3EG 3.32024-12-26
Some Honor products are affected by information leak vulnerability, successful exploitation could cause the information leak.
- CVE-2024-31870LOWCVSS 3.3EG 3.32024-06-15
IBM Db2 for i 7.2, 7.3, 7.4, and 7.5 supplies user defined table function is vulnerable to user enumeration by a local authenticated attacker, without having authority to the related *USRPRF objects. This can be used by a malicious actor …
- CVE-2023-21349LOWCVSS 3.3EG 3.32023-10-30
In Package Manager, there is a possible way to determine whether an app is installed, without query permissions, due to side channel information disclosure. This could lead to local information disclosure with no additional execution privi…
- CVE-2023-21348LOWCVSS 3.3EG 3.32023-10-30
In Window Manager, there is a possible way to determine whether an app is installed, without query permissions, due to side channel information disclosure. This could lead to local information disclosure with no additional execution privil…
- CVE-2023-21346LOWCVSS 3.3EG 3.32023-10-30
In the Device Idle Controller, there is a possible way to determine whether an app is installed, without query permissions, due to side channel information disclosure. This could lead to local information disclosure with no additional exec…
- CVE-2023-21345LOWCVSS 3.3EG 3.32023-10-30
In Game Manager Service, there is a possible way to determine whether an app is installed, without query permissions, due to side channel information disclosure. This could lead to local information disclosure with no additional execution …
- CVE-2022-47952LOWCVSS 3.3EG 3.32023-01-01
lxc-user-nic in lxc through 5.0.1 is installed setuid root, and may allow local users to infer whether any file exists, even within a protected directory tree, because "Failed to open" often indicates that a file does not exist, whereas "d…
- CVE-2022-20559LOWCVSS 3.3EG 3.32022-12-16
In revokeOwnPermissionsOnKill of PermissionManager.java, there is a possible way to determine whether an app is installed, without query permissions, due to side channel information disclosure. This could lead to local information disclosu…
- CVE-2022-20535LOWCVSS 3.3EG 3.32022-12-16
In registerLocalOnlyHotspotSoftApCallback of WifiManager.java, there is a possible way to determine whether an app is installed, without query permissions, due to side channel information disclosure. This could lead to local information di…
- CVE-2022-20320LOWCVSS 3.3EG 3.32022-08-12
In ActivityManager, there is a possible way to determine whether an app is installed, without query permissions, due to side channel information disclosure. This could lead to local information disclosure with no additional execution privi…
- CVE-2022-20318LOWCVSS 3.3EG 3.32022-08-12
In PackageInstaller, there is a possible way to determine whether an app is installed, without query permissions, due to side channel information disclosure. This could lead to local information disclosure with no additional execution priv…
- CVE-2022-20316LOWCVSS 3.3EG 3.32022-08-12
In ContentResolver, there is a possible way to determine whether an app is installed, without query permissions, due to side channel information disclosure. This could lead to local information disclosure with no additional execution privi…
- CVE-2022-20309LOWCVSS 3.3EG 3.32022-08-12
In PackageInstaller, there is a possible way to determine whether an app is installed, without query permissions, due to side channel information disclosure. This could lead to local information disclosure with no additional execution priv…
- CVE-2022-20307LOWCVSS 3.3EG 3.32022-08-12
In AlarmManagerService, there is a possible way to determine whether an app is installed, without query permissions, due to side channel information disclosure. This could lead to local information disclosure with no additional execution p…
- CVE-2022-20252LOWCVSS 3.3EG 3.32022-08-11
In PackageManager, there is a possible way to determine whether an app is installed, without query permissions, due to side channel information disclosure. This could lead to local information disclosure with no additional execution privil…
- CVE-2022-20251LOWCVSS 3.3EG 3.32022-08-11
In LocaleManager, there is a possible way to determine whether an app is installed, without query permissions, due to side channel information disclosure. This could lead to local information disclosure with no additional execution privile…
- CVE-2022-20249LOWCVSS 3.3EG 3.32022-08-11
In LocaleManager, there is a possible way to determine whether an app is installed, without query permissions, due to side channel information disclosure. This could lead to local information disclosure with no additional execution privile…
- CVE-2022-32296LOWCVSS 3.3EG 3.32022-06-05
The Linux kernel before 5.17.9 allows TCP servers to identify clients by observing what source ports are used. This occurs because of use of Algorithm 4 ("Double-Hash Port Selection Algorithm") of RFC 6056.
- CVE-2022-27814LOWCVSS 3.3EG 3.32022-04-14
SWHKD 1.1.5 allows arbitrary file-existence tests via the -c option.
- CVE-2021-1032LOWCVSS 3.3EG 3.32021-12-15
In getMimeGroup of PackageManagerService.java, there is a possible way to determine whether an app is installed, without query permissions, due to side channel information disclosure. This could lead to local information disclosure with no…
- CVE-2021-1031LOWCVSS 3.3EG 3.32021-12-15
In cancelNotificationsFromListener of NotificationManagerService.java, there is a possible way to determine whether an app is installed, without query permissions, due to side channel information disclosure. This could lead to local inform…
- CVE-2021-1018LOWCVSS 3.3EG 3.32021-12-15
In adjustStreamVolume of AudioService.java, there is a possible way to determine whether an app is installed, without query permissions, due to side channel information disclosure. This could lead to local information disclosure with no ad…
- CVE-2021-1015LOWCVSS 3.3EG 3.32021-12-15
In getMeidForSlot of PhoneInterfaceManager.java, there is a possible way to determine whether an app is installed, without query permissions, due to side channel information disclosure. This could lead to local information disclosure with …
- CVE-2021-0995LOWCVSS 3.3EG 3.32021-12-15
In registerSuggestionConnectionStatusListener of WifiServiceImpl.java, there is a possible way to determine whether an app is installed, without query permissions, due to side channel information disclosure. This could lead to local inform…
- CVE-2021-0990LOWCVSS 3.3EG 3.32021-12-15
In getDeviceId of PhoneSubInfoController.java, there is a possible way to determine whether an app is installed, without query permissions, due to side channel information disclosure. This could lead to local information disclosure with no…
- CVE-2021-0989LOWCVSS 3.3EG 3.32021-12-15
In hasManageOngoingCallsPermission of TelecomServiceImpl.java, there is a possible way to determine whether an app is installed, without query permissions, due to side channel information disclosure. This could lead to local information di…
Map vulnerabilities like CWE-203 to your infrastructure
EchelonGraph correlates every CVE — across CWE-203 and 150+ other weakness categories — against the assets you actually run. See blast radius, fix versions, and remediation steps in one graph.
Book a Demo →