CWE-208
72 active CVEs classified under this weakness category. Sourced from NVD, GHSA, and vendor advisories. Full definition on MITRE →
CVEs classified under CWE-208page 1 of 2
- CVE-2010-10006LOWCVSS 2.6EG 2.62023-01-18
A vulnerability, which was classified as problematic, was found in michaelliao jopenid. Affected is the function getAuthentication of the file JOpenId/src/org/expressme/openid/OpenIdManager.java. The manipulation leads to observable timing…
- CVE-2013-10006LOWCVSS 2.6EG 7.52023-01-01
A vulnerability classified as problematic was found in Ziftr primecoin up to 0.8.4rc1. Affected by this vulnerability is the function HTTPAuthorized of the file src/bitcoinrpc.cpp. The manipulation of the argument strUserPass/strRPCUserCol…
- CVE-2014-125055LOWCVSS 2.6EG 2.62023-01-07
A vulnerability, which was classified as problematic, was found in agnivade easy-scrypt. Affected is the function VerifyPassphrase of the file scrypt.go. The manipulation leads to observable timing discrepancy. The complexity of an attack …
- CVE-2014-125056LOWCVSS 2.6EG 5.32023-01-07
A vulnerability was found in Pylons horus and classified as problematic. Affected by this issue is some unknown functionality of the file horus/flows/local/services.py. The manipulation leads to observable timing discrepancy. The complexit…
- CVE-2016-10535MEDIUMCVSS 5.92018-05-31
csrf-lite is a cross-site request forgery protection library for framework-less node sites. csrf-lite uses `===`, a fail first string comparison, instead of a time constant string comparison This enables an attacker to guess the secret in …
- CVE-2016-15015LOWCVSS 2.6EG 2.62023-01-08
A vulnerability, which was classified as problematic, was found in viafintech Barzahlen Payment Module PHP SDK up to 2.0.0. Affected is the function verify of the file src/Webhook.php. The manipulation leads to observable timing discrepanc…
- CVE-2019-13420MEDIUMCVSS 5.9EG 5.92019-08-13
Search Guard versions before 21.0 had an timing side channel issue when using the internal user database.
- CVE-2019-16782MEDIUMCVSS 6.3EG 6.32019-12-18
There's a possible information leak / session hijack vulnerability in Rack (RubyGem rack). This vulnerability is patched in versions 1.6.12 and 2.0.8. Attackers may be able to find and hijack sessions by using timing attacks targeting the …
- CVE-2019-9494MEDIUMCVSS 5.92019-04-17
The implementations of SAE in hostapd and wpa_supplicant are vulnerable to side channel attacks as a result of observable timing differences and cache access patterns. An attacker may be able to gain leaked information from a side channel …
- CVE-2020-11037MEDIUMCVSS 6.1EG 6.12020-04-30
In Wagtail before versions 2.7.3 and 2.8.2, a potential timing attack exists on pages or documents that have been protected with a shared password through Wagtail's "Privacy" controls. This password check is performed through a character-b…
- CVE-2020-15237MEDIUMCVSS 5.9EG 5.92020-10-05
In Shrine before version 3.3.0, when using the `derivation_endpoint` plugin, it's possible for the attacker to use a timing attack to guess the signature of the derivation URL. The problem has been fixed by comparing sent and calculated si…
- CVE-2020-1926MEDIUMCVSS 5.9EG 5.92021-03-16
Apache Hive cookie signature verification used a non constant time comparison which is known to be vulnerable to timing attacks. This could allow recovery of another users cookie signature. The issue was addressed in Apache Hive 2.3.8
- CVE-2020-35165MEDIUMCVSS 5.1EG 5.12024-05-22
Dell BSAFE Crypto-C Micro Edition, versions before 4.1.5, and Dell BSAFE Micro Edition Suite, versions before 4.6, contain an Observable Timing Discrepancy Vulnerability.
- CVE-2020-4071LOWCVSS 2.2EG 2.22020-06-24
In django-basic-auth-ip-whitelist before 0.3.4, a potential timing attack exists on websites where the basic authentication is used or configured, i.e. BASIC_AUTH_LOGIN and BASIC_AUTH_PASSWORD is set. Currently the string comparison betwee…
- CVE-2021-21575MEDIUMCVSS 5.9EG 5.92024-02-02
Dell BSAFE Micro Edition Suite, versions before 4.5.2, contain an Observable Timing Discrepancy Vulnerability.
- CVE-2021-26313MEDIUMCVSS 5.5EG 5.52021-06-09
Potential speculative code store bypass in all supported CPU products, in conjunction with software vulnerabilities relating to speculative execution of overwritten instructions, may cause an incorrect speculation and could result in data …
- CVE-2021-26314MEDIUMCVSS 5.5EG 5.52021-06-09
Potential floating point value injection in all supported CPU products, in conjunction with software vulnerabilities relating to speculative execution with incorrect floating point results, may cause the use of incorrect data from FPVI and…
- CVE-2021-26318MEDIUMCVSS 4.7EG 4.72021-10-13
A timing and power-based side channel attack leveraging the x86 PREFETCH instructions on some AMD CPUs could potentially result in leaked kernel address space information.
- CVE-2021-31403MEDIUMCVSS 4.0EG 4.02021-04-23
Non-constant-time comparison of CSRF tokens in UIDL request handler in com.vaadin:vaadin-server versions 7.0.0 through 7.7.23 (Vaadin 7.0.0 through 7.7.23), and 8.0.0 through 8.12.2 (Vaadin 8.0.0 through 8.12.2) allows attacker to guess a …
- CVE-2021-31404MEDIUMCVSS 4.0EG 4.02021-04-23
Non-constant-time comparison of CSRF tokens in UIDL request handler in com.vaadin:flow-server versions 1.0.0 through 1.0.13 (Vaadin 10.0.0 through 10.0.16), 1.1.0 prior to 2.0.0 (Vaadin 11 prior to 14), 2.0.0 through 2.4.6 (Vaadin 14.0.0 t…
- CVE-2021-31406MEDIUMCVSS 4.0EG 4.02021-04-23
Non-constant-time comparison of CSRF tokens in endpoint request handler in com.vaadin:flow-server versions 3.0.0 through 5.0.3 (Vaadin 15.0.0 through 18.0.6), and com.vaadin:fusion-endpoint version 6.0.0 (Vaadin 19.0.0) allows attacker to …
- CVE-2021-34337MEDIUMCVSS 6.3EG 6.32023-04-15
An issue was discovered in Mailman Core before 3.3.5. An attacker with access to the REST API could use timing attacks to determine the value of the configured REST API password and then make arbitrary REST API calls. The REST API is bound…
- CVE-2021-42016HIGHCVSS 7.5EG 7.52022-03-08
A vulnerability has been identified in RUGGEDCOM i800, RUGGEDCOM i801, RUGGEDCOM i802, RUGGEDCOM i803, RUGGEDCOM M2100, RUGGEDCOM M2100F, RUGGEDCOM M2200, RUGGEDCOM M2200F, RUGGEDCOM M969, RUGGEDCOM M969F, RUGGEDCOM RMC30, RUGGEDCOM RMC838…
- CVE-2021-4294LOWCVSS 2.6EG 2.62022-12-28
A vulnerability was found in OpenShift OSIN. It has been classified as problematic. This affects the function ClientSecretMatches/CheckClientSecret. The manipulation of the argument secret leads to observable timing discrepancy. The name o…
- CVE-2021-43298CRITICALCVSS 9.8EG 9.82022-01-25
The code that performs password matching when using 'Basic' HTTP authentication does not use a constant-time memcmp and has no rate-limiting. This means that an unauthenticated network attacker can brute-force the HTTP basic password, byte…
- CVE-2022-20752MEDIUMCVSS 5.3EG 5.32022-07-06
A vulnerability in Cisco Unified Communications Manager (Unified CM), Cisco Unified Communications Manager Session Management Edition (Unified CM SME), and Cisco Unity Connection could allow an unauthenticated, remote attacker to perform a…
- CVE-2022-25332MEDIUMCVSS 4.4EG 4.42023-10-19
The AES implementation in the Texas Instruments OMAP L138 (secure variants), present in mask ROM, suffers from a timing side channel which can be exploited by an adversary with non-secure supervisor privileges by managing cache contents an…
- CVE-2022-29185MEDIUMCVSS 4.2EG 4.22022-05-20
totp-rs is a Rust library that permits the creation of 2FA authentification tokens per time-based one-time password (TOTP). Prior to version 1.1.0, token comparison was not constant time, and could theorically be used to guess value of an …
- CVE-2022-31142HIGHCVSS 7.5EG 7.52022-07-14
@fastify/bearer-auth is a Fastify plugin to require bearer Authorization headers. @fastify/bearer-auth prior to versions 7.0.2 and 8.0.1 does not securely use crypto.timingSafeEqual. A malicious attacker could estimate the length of one va…
- CVE-2022-39308MEDIUMCVSS 6.5EG 6.52022-10-14
GoCD is a continuous delivery server. GoCD helps you automate and streamline the build-test-release cycle for continuous delivery of your product. GoCD versions from 19.2.0 to 19.10.0 (inclusive) are subject to a timing attack in validatio…
- CVE-2022-42288MEDIUMCVSS 5.3EG 5.32023-01-13
NVIDIA BMC contains a vulnerability in IPMI handler, where an unauthorized attacker can use certain oracles to guess a valid BMC username, which may lead to an information disclosure.
- CVE-2022-4823LOWCVSS 3.1EG 5.92022-12-28
A vulnerability, which was classified as problematic, was found in InSTEDD Nuntium. Affected is an unknown function of the file app/controllers/geopoll_controller.rb. The manipulation of the argument signature leads to observable timing di…
- CVE-2023-1538MEDIUMCVSS 5.3EG 5.32023-03-21
Observable Timing Discrepancy in GitHub repository answerdev/answer prior to 1.0.6.
- CVE-2023-25000MEDIUMCVSS 5.0EG 5.02023-03-30
HashiCorp Vault's implementation of Shamir's secret sharing used precomputed table lookups, and was vulnerable to cache-timing attacks. An attacker with access to, and the ability to observe a large number of unseal operations on the host …
- CVE-2023-25529HIGHCVSS 8.0EG 8.02023-09-20
NVIDIA DGX H100 BMC and DGX A100 BMC contains a vulnerability in the host KVM daemon, where an unauthenticated attacker may cause a leak of another user’s session token by observing timing discrepancies between server responses. A succes…
- CVE-2023-25806MEDIUMCVSS 5.3EG 5.32023-03-02
OpenSearch Security is a plugin for OpenSearch that offers encryption, authentication and authorization. There is an observable discrepancy in the authentication response time between calls where the user provided exists and calls where it…
- CVE-2023-32694MEDIUMCVSS 4.8EG 4.82023-05-25
Saleor Core is a composable, headless commerce API. Saleor's `validate_hmac_signature` function is vulnerable to timing attacks. Malicious users could abuse this vulnerability on Saleor deployments having the Adyen plugin enabled in order …
- CVE-2023-40021MEDIUMCVSS 5.3EG 5.32023-08-16
Oppia is an online learning platform. When comparing a received CSRF token against the expected token, Oppia uses the string equality operator (`==`), which is not safe against timing attacks. By repeatedly submitting invalid tokens, an at…
- CVE-2023-40182LOWCVSS 3.7EG 3.72023-08-25
Silverware Games is a premium social network where people can play games online. When using the Recovery form, a noticeably different amount of time passes depending of whether the specified email address presents in our database or not. T…
- CVE-2023-41097MEDIUMCVSS 4.6EG 4.62023-12-21
An Observable Timing Discrepancy, Covert Timing Channel vulnerability in Silabs GSDK on ARM potentially allows Padding Oracle Crypto Attack on CBC PKCS7.This issue affects GSDK: through 4.4.0.
- CVE-2023-41313CRITICALCVSS 9.8EG 9.82024-03-12
The authentication method in Apache Doris versions before 2.0.0 was vulnerable to timing attacks. Users are recommended to upgrade to version 2.0.0 + or 1.2.8, which fixes this issue.
- CVE-2023-46656MEDIUMCVSS 5.3EG 3.72023-10-25
Jenkins Multibranch Scan Webhook Trigger Plugin 1.0.9 and earlier uses a non-constant time comparison function when checking whether the provided and expected webhook token are equal, potentially allowing attackers to use statistical metho…
- CVE-2023-46657MEDIUMCVSS 5.3EG 3.72023-10-25
Jenkins Gogs Plugin 1.0.15 and earlier uses a non-constant time comparison function when checking whether the provided and expected webhook token are equal, potentially allowing attackers to use statistical methods to obtain a valid webhoo…
- CVE-2023-46658MEDIUMCVSS 5.3EG 3.72023-10-25
Jenkins MSTeams Webhook Trigger Plugin 0.1.1 and earlier uses a non-constant time comparison function when checking whether the provided and expected webhook token are equal, potentially allowing attackers to use statistical methods to obt…
- CVE-2023-46660MEDIUMCVSS 5.3EG 3.72023-10-25
Jenkins Zanata Plugin 0.6 and earlier uses a non-constant time comparison function when checking whether the provided and expected webhook token hashes are equal, potentially allowing attackers to use statistical methods to obtain a valid …
- CVE-2023-5981MEDIUMCVSS 5.9EG 7.42023-11-28
A vulnerability was found that the response times to malformed ciphertexts in RSA-PSK ClientKeyExchange differ from response times of ciphertexts with correct PKCS#1 v1.5 padding.
- CVE-2024-0202MEDIUMCVSS 5.9EG 5.92024-02-05
A security vulnerability has been identified in the cryptlib cryptographic library when cryptlib is compiled with the support for RSA key exchange ciphersuites in TLS (by setting the USE_RSA_SUITES define), it will be vulnerable to the tim…
- CVE-2024-1543MEDIUMCVSS 4.1EG 4.12024-08-29
The side-channel protected T-Table implementation in wolfSSL up to version 5.6.5 protects against a side-channel attacker with cache-line resolution. In a controlled environment such as Intel SGX, an attacker can gain a per instruction sub…
- CVE-2024-21671LOWCVSS 3.7EG 3.72024-01-30
The vantage6 technology enables to manage and deploy privacy enhancing technologies like Federated Learning (FL) and Multi-Party Computation (MPC). It is possible to find out usernames from the response time of login requests. This could …
- CVE-2024-23342HIGHCVSS 7.4EG 7.42024-01-23
The `ecdsa` PyPI package is a pure Python implementation of ECC (Elliptic Curve Cryptography) with support for ECDSA (Elliptic Curve Digital Signature Algorithm), EdDSA (Edwards-curve Digital Signature Algorithm) and ECDH (Elliptic Curve D…
Map vulnerabilities like CWE-208 to your infrastructure
EchelonGraph correlates every CVE — across CWE-208 and 150+ other weakness categories — against the assets you actually run. See blast radius, fix versions, and remediation steps in one graph.
Start Free Scan →