VYPR

CWE-203

Observable Discrepancy

BaseIncomplete

Description

The product behaves differently or sends different responses under different circumstances in a way that is observable to an unauthorized actor.

Hierarchy (View 1000)

Related attack patterns (CAPEC)

CAPEC-189

CVEs mapped to this weakness (798)

page 21 of 40
  • CVE-2017-7006MedJul 20, 2017
    risk 0.35cvss 5.3epss 0.01

    An issue was discovered in certain Apple products. iOS before 10.3.3 is affected. Safari before 10.1.2 is affected. tvOS before 10.2.2 is affected. The issue involves the "WebKit" component. It allows remote attackers to conduct a timing side-channel attack to bypass the Same…

  • CVE-2017-8055MedApr 22, 2017
    risk 0.35cvss 5.3epss 0.02

    WatchGuard Fireware allows user enumeration, e.g., in the Firebox XML-RPC login handler. A login request that contains a blank password sent to the XML-RPC agent in Fireware v11.12.1 and earlier returns different responses for valid and invalid usernames. An attacker could…

  • CVE-2016-9129MedMar 28, 2017
    risk 0.35cvss 5.3epss 0.01

    Revive Adserver before 3.2.3 suffers from Information Exposure Through Discrepancy. It is possible to check whether or not an email address was associated to one or more user accounts on a target Revive Adserver instance by examining the message printed by the password recovery…

  • CVE-2026-91725MedSep 15, 2026
    risk 0.34cvss 5.3epss 0.00

    Observable discrepancy in CSS in Google Chrome prior to 153.0.8010.47 allowed a remote attacker to leak sensitive information via a crafted HTML page. (Chromium security severity: Medium)

  • CVE-2026-91714MedSep 15, 2026
    risk 0.34cvss 5.3epss 0.00

    Observable discrepancy in Fonts in Google Chrome prior to 153.0.8010.47 allowed a remote attacker leveraging social engineering to leak sensitive information via a crafted HTML page. (Chromium security severity: Medium)

  • CVE-2026-87566MedSep 9, 2026
    risk 0.34cvss 5.3epss 0.00

    Observable discrepancy in Layout in Google Chrome prior to 153.0.8010.36 allowed a remote attacker to leak sensitive information via a crafted HTML page. (Chromium security severity: Medium)

  • CVE-2026-87518MedSep 9, 2026
    risk 0.34cvss 5.3epss 0.00

    Observable discrepancy in Safebrowsing in Google Chrome on on iOS prior to 153.0.8010.36 allowed a remote attacker who had compromised the renderer process to potentially obtain sensitive information via a crafted HTML page. (Chromium security severity: Medium)

  • CVE-2026-11754MedAug 27, 2026
    risk 0.34cvss 5.3epss 0.00

    Observable discrepancy vulnerability in Seres Software syWEB allows Account Footprinting. This issue affects syWEB: through 27082026. NOTE: The vendor was contacted and it was learned that the product is not supported.

  • CVE-2026-79287MedAug 25, 2026
    risk 0.34cvss 5.3epss 0.00

    Observable discrepancy in Forms in Google Chrome prior to 152.0.7977.65 allowed a remote attacker to obtain sensitive information via a crafted HTML page. (Chromium security severity: Medium)

  • CVE-2026-79242MedAug 25, 2026
    risk 0.34cvss 5.3epss 0.00

    Observable discrepancy in HTML in Google Chrome prior to 152.0.7977.65 allowed a remote attacker to obtain sensitive information via a crafted HTML page. (Chromium security severity: Medium)

  • CVE-2026-79181MedAug 25, 2026
    risk 0.34cvss 5.3epss 0.00

    Observable discrepancy in Glic in Google Chrome prior to 152.0.7977.65 allowed a remote attacker to obtain sensitive information via a crafted HTML page. (Chromium security severity: Low)

  • CVE-2026-79030MedAug 25, 2026
    risk 0.34cvss 5.3epss 0.00

    Observable discrepancy in Autofill in Google Chrome prior to 152.0.7977.65 allowed a remote attacker to obtain sensitive information via a crafted HTML page. (Chromium security severity: Medium)

  • CVE-2026-79028MedAug 25, 2026
    risk 0.34cvss 5.3epss 0.00

    Observable discrepancy in Network in Google Chrome prior to 152.0.7977.65 allowed a remote attacker to obtain sensitive information via a crafted HTML page. (Chromium security severity: Medium)

  • CVE-2026-23931MedAug 18, 2026
    risk 0.34cvss —epss 0.00

    The frontend validatate.api.exists action can be exploited by authenticated users to extract plaintext user macro values leading to potential loss of confidentiality.

  • CVE-2026-59502MedAug 13, 2026
    risk 0.34cvss 5.3epss 0.00

    : Observable Discrepancy vulnerability in Priority Portal Generator addon to Priority ERP (developed by Soft Solutions). This issue affects Portal Generator addon to Priority ERP (developed by Soft Solutions): All versions without Priwall v3.

  • CVE-2026-14112MedJun 30, 2026
    risk 0.34cvss 5.3epss 0.00

    Inappropriate implementation in Enterprise in Google Chrome prior to 150.0.7871.47 allowed a remote attacker who convinced a user to engage in specific UI gestures to obtain potentially sensitive information from process memory via a crafted HTML page. (Chromium security…

  • CVE-2026-56316MedJun 21, 2026
    risk 0.34cvss 5.3epss 0.00

    Cap-go before 12.128.2 contains an information disclosure vulnerability in the OPTIONS /build/upload/:jobId/* endpoint that allows unauthenticated attackers to enumerate valid builder job IDs through observable response discrepancies. Attackers can probe the endpoint without…

  • CVE-2024-55374MedJan 2, 2026
    risk 0.34cvss 5.3epss 0.00

    REDCap 14.3.13 allows an attacker to enumerate usernames due to an observable discrepancy between login attempts.

  • CVE-2023-53943MedDec 18, 2025
    risk 0.34cvss 5.3epss 0.00

    GLPI 9.5.7 contains a username enumeration vulnerability in the lost password recovery mechanism that allows attackers to validate email addresses. Attackers can systematically test email addresses by submitting requests to the password reset endpoint and analyzing response…

  • CVE-2020-36888MedDec 10, 2025
    risk 0.34cvss 5.3epss 0.00

    SpinetiX Fusion Digital Signage 3.4.8 contains a username enumeration vulnerability in its login script that allows attackers to identify valid user accounts. Attackers can send crafted login requests with different usernames to distinguish between existing and non-existing…