CWE-203— Observable Discrepancy (Information Exposure via Side Channel)
The product behaves differently or sends different responses under different circumstances in a way that is observable to an unauthorized actor.— MITRE CWE catalog
832 active CVEs classified under this weakness category. Sourced from NVD, GHSA, and vendor advisories. Full definition on MITRE →
CVEs classified under CWE-203page 8 of 17
- CVE-2022-20242MEDIUMCVSS 5.5EG 5.52022-08-11
In Telephony, there is a possible way to determine whether an app is installed, without query permissions, due to side channel information disclosure. This could lead to local information disclosure with no additional execution privileges …
- CVE-2021-0975MEDIUMCVSS 5.5EG 5.52022-08-11
In USB Manager, there is a possible way to determine whether an app is installed, without query permissions, due to side channel information disclosure. This could lead to local information disclosure of installed packages with no addition…
- CVE-2021-33149MEDIUMCVSS 5.5EG 5.52022-05-12
Observable behavioral discrepancy in some Intel(R) Processors may allow an authorized user to potentially enable information disclosure via local access.
- CVE-2021-39791MEDIUMCVSS 5.5EG 5.52022-03-30
In WallpaperManagerService, there is a possible way to determine whether an app is installed, without query permissions, due to side channel information disclosure. This could lead to local information disclosure with no additional executi…
- CVE-2021-39788MEDIUMCVSS 5.5EG 5.52022-03-30
In TelecomManager, there is a possible way to check if a particular self managed phone account was registered on the device due to side channel information disclosure. This could lead to local information disclosure with no additional exec…
- CVE-2021-39775MEDIUMCVSS 5.5EG 5.52022-03-30
In People, there is a possible way to determine whether an app is installed, without query permissions, due to side channel information disclosure. This could lead to local information disclosure with no additional execution privileges nee…
- CVE-2021-39773MEDIUMCVSS 5.5EG 5.52022-03-30
In VpnManagerService, there is a possible disclosure of installed VPN packages due to side channel information disclosure. This could lead to local information disclosure with no additional execution privileges needed. User interaction is …
- CVE-2021-39766MEDIUMCVSS 5.5EG 5.52022-03-30
In Settings, there is a possible way to determine whether an app is installed, without query permissions, due to side channel information disclosure. This could lead to local information disclosure with no additional execution privileges n…
- CVE-2021-39761MEDIUMCVSS 5.5EG 5.52022-03-30
In Media, there is a possible way to determine whether an app is installed, without query permissions, due to side channel information disclosure. This could lead to local information disclosure with no additional execution privileges need…
- CVE-2021-39760MEDIUMCVSS 5.5EG 5.52022-03-30
In AudioService, there is a possible way to determine whether an app is installed, without query permissions, due to side channel information disclosure. This could lead to local information disclosure with no additional execution privileg…
- CVE-2021-39756MEDIUMCVSS 5.5EG 5.52022-03-30
In Framework, there is a possible way to determine whether an app is installed, without query permissions, due to side channel information disclosure. This could lead to local information disclosure with no additional execution privileges …
- CVE-2021-39755MEDIUMCVSS 5.5EG 5.52022-03-30
In DevicePolicyManager, there is a possible way to reveal the existence of an installed package without proper query permissions due to side channel information disclosure. This could lead to local information disclosure with no additional…
- CVE-2021-39754MEDIUMCVSS 5.5EG 5.52022-03-30
In ContextImpl, there is a possible way to determine whether an app is installed, without query permissions, due to side channel information disclosure. This could lead to local information disclosure with no additional execution privilege…
- CVE-2021-39745MEDIUMCVSS 5.5EG 5.52022-03-30
In DevicePolicyManager, there is a possible way to determine whether an app is installed, without query permissions, due to side channel information disclosure. This could lead to local information disclosure with no additional execution p…
- CVE-2021-39744MEDIUMCVSS 5.5EG 5.52022-03-30
In DevicePolicyManager, there is a possible way to determine whether an app is installed, without query permissions, due to side channel information disclosure. This could lead to local information disclosure with no additional execution p…
- CVE-2021-44421MEDIUMCVSS 5.5EG 5.52022-03-10
The pointer-validation logic in util/mem_util.rs in Occlum before 0.26.0 for Intel SGX acts as a confused deputy that allows a local attacker to access unauthorized information via side-channel analysis.
- CVE-2021-0524MEDIUMCVSS 5.5EG 5.52022-02-11
In isServiceDistractionOptimized of CarPackageManagerService.java, there is a possible disclosure of installed packages due to side channel information disclosure. This could lead to local information disclosure with no additional executio…
- CVE-2021-1030MEDIUMCVSS 5.5EG 5.52021-12-15
In setNotificationsShownFromListener of NotificationManagerService.java, there is a possible way to determine whether an app is installed, without query permissions, due to side channel information disclosure. This could lead to local info…
- CVE-2021-1026MEDIUMCVSS 5.5EG 5.52021-12-15
In startRanging of RttServiceImpl.java, there is a possible way to determine whether an app is installed, without query permissions, due to side channel information disclosure. This could lead to local information disclosure with no additi…
- CVE-2021-1014MEDIUMCVSS 5.5EG 5.52021-12-15
In getNetworkTypeForSubscriber of PhoneInterfaceManager.java, there is a possible way to determine whether an app is installed, without query permissions, due to side channel information disclosure. This could lead to local information dis…
- CVE-2021-1013MEDIUMCVSS 5.5EG 5.52021-12-15
In checkExistsAndEnforceCannotModifyImmutablyRestrictedPermission of PermissionManagerService.java, there is a possible way to determine whether an app is installed, without query permissions, due to side channel information disclosure. Th…
- CVE-2021-1012MEDIUMCVSS 5.5EG 5.52021-12-15
In onResume of NotificationAccessDetails.java, there is a possible way to determine whether an app is installed, without query permissions, due to side channel information disclosure. This could lead to local information disclosure with no…
- CVE-2021-1009MEDIUMCVSS 5.5EG 5.52021-12-15
In setApplicationCategoryHint of PackageManagerService.java, there is a possible way to determine whether an app is installed, without query permissions, due to side channel information disclosure. This could lead to local information disc…
- CVE-2021-1005MEDIUMCVSS 5.5EG 5.52021-12-15
In getDeviceIdWithFeature of PhoneInterfaceManager.java, there is a possible way to determine whether an app is installed, without query permissions, due to side channel information disclosure. This could lead to local information disclosu…
- CVE-2021-34556MEDIUMCVSS 5.5EG 5.52021-08-02
In the Linux kernel through 5.13.7, an unprivileged BPF program can obtain sensitive information from kernel memory via a Speculative Store Bypass side-channel attack because the protection mechanism neglects the possibility of uninitializ…
- CVE-2021-35477MEDIUMCVSS 5.5EG 5.52021-08-02
In the Linux kernel through 5.13.7, an unprivileged BPF program can obtain sensitive information from kernel memory via a Speculative Store Bypass side-channel attack because a certain preempting store operation does not necessarily occur …
- CVE-2021-26314MEDIUMCVSS 5.5EG 5.52021-06-09
Potential floating point value injection in all supported CPU products, in conjunction with software vulnerabilities relating to speculative execution with incorrect floating point results, may cause the use of incorrect data from FPVI and…
- CVE-2021-26313MEDIUMCVSS 5.5EG 5.52021-06-09
Potential speculative code store bypass in all supported CPU products, in conjunction with software vulnerabilities relating to speculative execution of overwritten instructions, may cause an incorrect speculation and could result in data …
- CVE-2021-29415MEDIUMCVSS 5.5EG 5.52021-05-21
The elliptic curve cryptography (ECC) hardware accelerator, part of the ARM® TrustZone® CryptoCell 310, contained in the NordicSemiconductor nRF52840 through 2021-03-29 has a non-constant time ECDSA implemenation. This allows an adversar…
- CVE-2021-0321MEDIUMCVSS 5.5EG 5.52021-01-11
In enforceDumpPermissionForPackage of ActivityManagerService.java, there is a possible way to determine if a package is installed due to side channel information disclosure. This could lead to local information disclosure with no additiona…
- CVE-2020-27026MEDIUMCVSS 5.5EG 5.52020-12-15
During boot, the device unlock interface behaves differently depending on if a fingerprint registered to the device is present. This could lead to local information disclosure with no additional execution privileges needed. User interactio…
- CVE-2020-0464MEDIUMCVSS 5.5EG 5.52020-12-14
In resolv_cache_lookup of res_cache.cpp, there is a possible side channel information disclosure. This could lead to local information disclosure of accessed web resources with no additional execution privileges needed. User interaction is…
- CVE-2020-12912MEDIUMCVSS 5.5EG 5.52020-11-12
A potential vulnerability in the AMD extension to Linux "hwmon" service may allow an attacker to use the Linux-based Running Average Power Limit (RAPL) interface to show various side channel attacks. In line with industry partners, AMD has…
- CVE-2020-8695MEDIUMCVSS 5.5EG 5.52020-11-12
Observable discrepancy in the RAPL interface for some Intel(R) Processors may allow a privileged user to potentially enable information disclosure via local access.
- CVE-2020-16150MEDIUMCVSS 5.5EG 5.52020-09-02
A Lucky 13 timing side channel in mbedtls_ssl_decrypt_buf in library/ssl_msg.c in Trusted Firmware Mbed TLS through 2.23.0 allows an attacker to recover secret key information. This affects CBC mode because of a computed time difference ba…
- CVE-2019-19338MEDIUMCVSS 5.5EG 5.52020-07-13
A flaw was found in the fix for CVE-2019-11135, in the Linux upstream kernel versions before 5.5 where, the way Intel CPUs handle speculative execution of instructions when a TSX Asynchronous Abort (TAA) error occurs. When a guest is runni…
- CVE-2020-13844MEDIUMCVSS 5.5EG 5.52020-06-08
Arm Armv8-A core implementations utilizing speculative execution past unconditional changes in control flow may allow unauthorized disclosure of information to an attacker with local user access via a side-channel analysis, aka "straight-l…
- CVE-2019-14067MEDIUMCVSS 5.5EG 5.52020-06-02
Using non-time-constant functions like memcmp to compare sensitive data can lead to information leakage through timing side channel issue. in Snapdragon Auto, Snapdragon Compute, Snapdragon Connectivity, Snapdragon Consumer IOT, Snapdragon…
- CVE-2019-14007MEDIUMCVSS 5.5EG 5.52020-04-16
Due to the use of non-time-constant comparison functions there is issue in timing side channels which can be used as a potential side channel for SUI corruption in Snapdragon Auto, Snapdragon Compute, Snapdragon Connectivity, Snapdragon Co…
- CVE-2019-10483MEDIUMCVSS 5.5EG 5.52020-04-16
Side channel issue in QTEE due to usage of non-time-constant comparison function such as memcmp or strcmp in Snapdragon Auto, Snapdragon Compute, Snapdragon Connectivity, Snapdragon Consumer Electronics Connectivity, Snapdragon Consumer IO…
- CVE-2019-9472MEDIUMCVSS 5.5EG 5.52020-01-06
In DCRYPTO_equals of compare.c, there is a possible timing attack due to improperly used crypto. This could lead to local information disclosure with no additional execution privileges needed. User interaction is not needed for exploitatio…
- CVE-2016-2178MEDIUMCVSS 5.5EG 5.52016-06-20
The dsa_sign_setup function in crypto/dsa/dsa_ossl.c in OpenSSL through 1.0.2h does not properly ensure the use of constant-time operations, which makes it easier for local users to discover a DSA private key via a timing side-channel atta…
- CVE-2022-34704MEDIUMCVSS 4.7EG 5.52022-08-09
Windows Defender Credential Guard Information Disclosure Vulnerability
- CVE-2020-10932MEDIUMCVSS 4.7EG 5.52020-04-15
An issue was discovered in Arm Mbed TLS before 2.16.6 and 2.7.x before 2.7.15. An attacker that can get precise enough side-channel measurements can recover the long-term ECDSA private key by (1) reconstructing the projective coordinate of…
- CVE-2024-27839MEDIUMCVSS 3.3EG 5.52024-05-14
A privacy issue was addressed by moving sensitive data to a more secure location. This issue is fixed in iOS 17.5 and iPadOS 17.5. A malicious application may be able to determine a user's current location.
- CVE-2026-106506MEDIUMCVSS 5.3EG 5.32026-10-06
Backstage is an open framework for building developer portals. Prior to 4.1.0, the @backstage/plugin-scaffolder-backend package is affected by improper input validation in scaffolder task list ordering. An authenticated Backstage user with…
- CVE-2026-106351MEDIUMCVSS 5.3EG 5.32026-10-06
Observable discrepancy in Safebrowsing in Google Chrome on on iOS prior to 155.0.8059.39 allowed a remote attacker who had compromised the renderer process to obtain sensitive information via a crafted HTML page. (Chromium security severit…
- CVE-2026-106303MEDIUMCVSS 5.3EG 5.32026-10-06
Observable discrepancy in Autofill AI in Google Chrome prior to 155.0.8059.39 allowed a remote attacker who had compromised the renderer process and leveraged social engineering to obtain sensitive information via a crafted HTML page. (Chr…
- CVE-2026-11795MEDIUMCVSS 5.3EG 5.32026-10-02
Observable discrepancy vulnerability in Softtr Informatics Trading Limited Company E-Commerce Pack allows Account Footprinting. This issue affects E-Commerce Pack: before 5.03.01.54.
- CVE-2026-91725MEDIUMCVSS 5.3EG 5.32026-09-15
Observable discrepancy in CSS in Google Chrome prior to 153.0.8010.47 allowed a remote attacker to leak sensitive information via a crafted HTML page. (Chromium security severity: Medium)
Map vulnerabilities like CWE-203 to your infrastructure
EchelonGraph correlates every CVE — across CWE-203 and 150+ other weakness categories — against the assets you actually run. See blast radius, fix versions, and remediation steps in one graph.
Book a Demo →