CWE-203— Observable Discrepancy (Information Exposure via Side Channel)
The product behaves differently or sends different responses under different circumstances in a way that is observable to an unauthorized actor.— MITRE CWE catalog
832 active CVEs classified under this weakness category. Sourced from NVD, GHSA, and vendor advisories. Full definition on MITRE →
CVEs classified under CWE-203page 17 of 17
- CVE-2021-0988LOWCVSS 3.3EG 3.32021-12-15
In getLaunchedFromUid and getLaunchedFromPackage of ActivityClientController.java, there is a possible way to determine whether an app is installed, without query permissions, due to side channel information disclosure. This could lead to …
- CVE-2021-0987LOWCVSS 3.3EG 3.32021-12-15
In getNeighboringCellInfo of PhoneInterfaceManager.java, there is a possible way to determine whether an app is installed, without query permissions, due to side channel information disclosure. This could lead to local information disclosu…
- CVE-2021-38209LOWCVSS 3.3EG 3.32021-08-08
net/netfilter/nf_conntrack_standalone.c in the Linux kernel before 5.12.2 allows observation of changes in any net namespace because these changes are leaked into all other net namespaces. This is related to the NF_SYSCTL_CT_MAX, NF_SYSCTL…
- CVE-2020-24512LOWCVSS 3.3EG 3.32021-06-09
Observable timing discrepancy in some Intel(R) Processors may allow an authenticated user to potentially enable information disclosure via local access.
- CVE-2026-106210LOWCVSS 3.1EG 3.12026-10-06
Observable discrepancy in Scroll in Google Chrome prior to 155.0.8059.39 allowed a remote attacker to obtain cross-origin data via a crafted Chrome extension. (Chromium security severity: Medium)
- CVE-2026-106180LOWCVSS 3.1EG 3.12026-10-06
Observable discrepancy in Animation in Google Chrome prior to 155.0.8059.39 allowed a remote attacker to potentially obtain cross-origin data via a crafted HTML page. (Chromium security severity: Medium)
- CVE-2026-105652LOWCVSS 3.1EG 3.12026-10-05
Ghost is a Node.js content management system. From 0.7.2 until 6.64.0, any staff-level user was able to determine the relative ordering of other staff users' hashed passwords. This does not directly disclose password hashes, and does not p…
- CVE-2026-104415LOWCVSS 3.1EG 3.12026-10-02
Ghost from 0.7.2 before 6.64.0 contains an information disclosure vulnerability in the Admin API that allows staff-level users to determine the relative ordering of other staff users' password hashes. Authenticated staff users can query th…
- CVE-2026-87539LOWCVSS 3.1EG 3.12026-09-09
Observable discrepancy in Network in Google Chrome prior to 153.0.8010.36 allowed a remote attacker to obtain cross-origin data via a crafted HTML page. (Chromium security severity: Medium)
- CVE-2025-46720LOWCVSS 3.1EG 3.12025-05-05
Keystone is a content management system for Node.js. Prior to version 6.5.0, `{field}.isFilterable` access control can be bypassed in `update` and `delete` mutations by adding additional unique filters. These filters can be used as an orac…
- CVE-2025-32789LOWCVSS 3.1EG 3.12025-04-16
EspoCRM is an Open Source Customer Relationship Management software. Prior to version 9.0.7, users can be sorted by their password hash. This flaw allows an attacker to make assumptions about the hash values of other users stored in the pa…
- CVE-2024-21251LOWCVSS 3.1EG 3.12024-10-15
Vulnerability in the Java VM component of Oracle Database Server. Supported versions that are affected are 19.3-19.24, 21.3-21.15 and 23.4-23.5. Difficult to exploit vulnerability allows low privileged attacker having Create Session, Cre…
- CVE-2019-2818LOWCVSS 3.1EG 3.12019-07-23
Vulnerability in the Java SE component of Oracle Java SE (subcomponent: Security). Supported versions that are affected are Java SE: 11.0.3 and 12.0.1. Difficult to exploit vulnerability allows unauthenticated attacker with network access …
- CVE-2026-78949LOWCVSS 2.9EG 2.92026-08-25
Observable discrepancy in CustomTabs in Google Chrome on on Android prior to 152.0.7977.65 allowed a local attacker to obtain cross-origin data via a co-installed app. (Chromium security severity: Medium)
- CVE-2026-78936LOWCVSS 2.9EG 2.92026-08-25
Observable discrepancy in CustomTabs in Google Chrome on on Android prior to 152.0.7977.65 allowed a local attacker to obtain cross-origin data via a co-installed app. (Chromium security severity: Medium)
- CVE-2025-65185LOWCVSS 2.8EG 2.82025-12-17
There is a username enumeration via local user login in Entrinsik Informer v5.10.1 which allows malicious users to enumerate users by entering an OTP code and new password then reviewing application responses.
- CVE-2026-58445LOWCVSS 2.7EG 2.72026-07-21
Cross-repository label-ID enumeration oracle via unscoped DeleteIssueLabel API
- CVE-2025-68164LOWCVSS 2.7EG 2.72025-12-16
In JetBrains TeamCity before 2025.11 port enumeration was possible via the Perforce connection test
- CVE-2026-47011LOWCVSS 2.6EG 2.62026-07-21
Vulnerability in the Siebel CRM Deployment product of Oracle Siebel CRM (component: Application Interface). Supported versions that are affected are 17.0-26.4. Difficult to exploit vulnerability allows low privileged attacker with network…
- CVE-2025-46570LOWCVSS 2.6EG 2.62025-05-29
vLLM is an inference and serving engine for large language models (LLMs). Prior to version 0.9.0, when a new prompt is processed, if the PageAttention mechanism finds a matching prefix chunk, the prefill process speeds up, which is reflect…
- CVE-2010-10006LOWCVSS 2.6EG 2.62023-01-18
A vulnerability, which was classified as problematic, was found in michaelliao jopenid. Affected is the function getAuthentication of the file JOpenId/src/org/expressme/openid/OpenIdManager.java. The manipulation leads to observable timing…
- CVE-2016-15015LOWCVSS 2.6EG 2.62023-01-08
A vulnerability, which was classified as problematic, was found in viafintech Barzahlen Payment Module PHP SDK up to 2.0.0. Affected is the function verify of the file src/Webhook.php. The manipulation leads to observable timing discrepanc…
- CVE-2021-4294LOWCVSS 2.6EG 2.62022-12-28
A vulnerability was found in OpenShift OSIN. It has been classified as problematic. This affects the function ClientSecretMatches/CheckClientSecret. The manipulation of the argument secret leads to observable timing discrepancy. The name o…
- CVE-2021-4286LOWCVSS 2.6EG 2.62022-12-27
A vulnerability, which was classified as problematic, has been found in cocagne pysrp up to 1.0.16. This issue affects the function calculate_x of the file srp/_ctsrp.py. The manipulation leads to information exposure through discrepancy. …
- CVE-2022-46724LOWCVSS 2.4EG 2.42023-08-14
This issue was addressed by restricting options offered on a locked device. This issue is fixed in iOS 16.4 and iPadOS 16.4. A person with physical access to an iOS device may be able to view the last image used in Magnifier from the lock …
- CVE-2019-14359LOWCVSS 2.4EG 2.42019-08-12
On BC Vault devices, a side channel for the row-based SSD1309 OLED display was found. The power consumption of each row-based display cycle depends on the number of illuminated pixels, allowing a partial recovery of display contents. For e…
- CVE-2019-14357LOWCVSS 2.4EG 2.42019-08-10
On Mooltipass Mini devices, a side channel for the row-based OLED display was found. The power consumption of each row-based display cycle depends on the number of illuminated pixels, allowing a partial recovery of display contents. For ex…
- CVE-2019-14355LOWCVSS 2.4EG 2.42019-08-10
On ShapeShift KeepKey devices, a side channel for the row-based OLED display was found. The power consumption of each row-based display cycle depends on the number of illuminated pixels, allowing a partial recovery of display contents. For…
- CVE-2019-14354LOWCVSS 2.4EG 2.42019-08-10
On Ledger Nano S and Nano X devices, a side channel for the row-based OLED display was found. The power consumption of each row-based display cycle depends on the number of illuminated pixels, allowing a partial recovery of display content…
- CVE-2020-29480LOWCVSS 2.3EG 2.32020-12-15
An issue was discovered in Xen through 4.14.x. Neither xenstore implementation does any permission checks when reporting a xenstore watch event. A guest administrator can watch the root xenstored node, which will cause notifications for ev…
- CVE-2001-1387LOWCVSS v2 2.1EG 2.12001-11-05
iptables-save in iptables before 1.2.4 records the "--reject-with icmp-host-prohibited" rule as "--reject-with tcp-reset," which causes iptables to generate different responses than specified by the administrator, possibly leading to an in…
- CVE-2025-13912LOWCVSS 1.0EG 1.02025-12-11
Multiple constant-time implementations in wolfSSL before version 5.8.4 may be transformed into non-constant-time binary by LLVM optimizations, which can potentially result in observable timing discrepancies and lead to information disclosu…
Map vulnerabilities like CWE-203 to your infrastructure
EchelonGraph correlates every CVE — across CWE-203 and 150+ other weakness categories — against the assets you actually run. See blast radius, fix versions, and remediation steps in one graph.
Book a Demo →