VYPR

CWE-203

Observable Discrepancy

BaseIncomplete

Description

The product behaves differently or sends different responses under different circumstances in a way that is observable to an unauthorized actor.

Hierarchy (View 1000)

Related attack patterns (CAPEC)

CAPEC-189

CVEs mapped to this weakness (798)

page 28 of 40
  • CVE-2024-41952MedJul 31, 2024
    risk 0.28cvss 5.3epss 0.01

    Zitadel is an open source identity management system. ZITADEL administrators can enable a setting called "Ignoring unknown usernames" which helps mitigate attacks that try to guess/enumerate usernames. If enabled, ZITADEL will show the password prompt even if the user doesn't…

  • CVE-2024-5697MedJun 11, 2024
    risk 0.28cvss 4.3epss 0.00

    A website was able to detect when a user took a screenshot of a page using the built-in Screenshot functionality in Firefox. This vulnerability affects Firefox < 127.

  • CVE-2024-5690MedJun 11, 2024
    risk 0.28cvss 4.3epss 0.01

    By monitoring the time certain operations take, an attacker could have guessed which external protocol handlers were functional on a user's system. This vulnerability affects Firefox < 127, Firefox ESR < 115.12, and Thunderbird < 115.12.

  • CVE-2023-6135MedDec 19, 2023
    risk 0.28cvss 4.3epss 0.01

    Multiple NSS NIST curves were susceptible to a side-channel attack known as "Minerva". This attack could potentially allow an attacker to recover the private key. This vulnerability affects Firefox < 121.

  • CVE-2023-23584MedDec 18, 2023
    risk 0.28cvss 4.3epss 0.01

    An observable response discrepancy in the Gallagher Command Centre RESTAPI allows an insufficiently-privileged user to infer the presence of items that would not otherwise be viewable. This issue affects: Gallagher Command Centre 8.70 prior to vEL8.70.1787 (MR2), 8.60 prior…

  • CVE-2023-38871MedSep 28, 2023
    risk 0.28cvss 5.3epss 0.01

    The commit 3730880 (April 2023) and v.0.9-beta1 of gugoan Economizzer has a user enumeration vulnerability in the login and forgot password functionalities. The app reacts differently when a user or email address is valid, and when it's not. This may allow an attacker to…

  • CVE-2023-22359MedJun 26, 2023
    risk 0.28cvss 4.3epss 0.01

    User enumeration in Checkmk <=2.2.0p4 allows an authenticated attacker to enumerate usernames.

  • CVE-2022-24695MedJun 2, 2023
    risk 0.28cvss 4.3epss 0.00

    Bluetooth Classic in Bluetooth Core Specification through 5.3 does not properly conceal device information for Bluetooth transceivers in Non-Discoverable mode. By conducting an efficient over-the-air attack, an attacker can fully extract the permanent, unique Bluetooth MAC…

  • CVE-2023-24598MedMay 29, 2023
    risk 0.28cvss 4.3epss 0.01

    OX App Suite before backend 7.10.6-rev37 has an information leak in the handling of distribution lists, e.g., partial disclosure of the private contacts of another user.

  • CVE-2023-1540MedMar 21, 2023
    risk 0.28cvss 5.3epss 0.01

    Observable Response Discrepancy in GitHub repository answerdev/answer prior to 1.0.6.

  • CVE-2023-1538MedMar 21, 2023
    risk 0.28cvss 5.3epss 0.01

    Observable Timing Discrepancy in GitHub repository answerdev/answer prior to 1.0.6.

  • CVE-2022-4025MedJan 2, 2023
    risk 0.28cvss 4.3epss 0.00

    Inappropriate implementation in Paint in Google Chrome prior to 98.0.4758.80 allowed a remote attacker to leak cross-origin data outside an iframe via a crafted HTML page. (Chrome security severity: Low)

  • CVE-2022-26382MedDec 22, 2022
    risk 0.28cvss 4.3epss 0.00

    While the text displayed in Autofill tooltips cannot be directly read by JavaScript, the text was rendered using page fonts. Side-channel attacks on the text by using specially crafted fonts could have lead to this text being inferred by the webpage. This vulnerability affects…

  • CVE-2020-35473MedNov 8, 2022
    risk 0.28cvss 4.3epss 0.00

    An information leakage vulnerability in the Bluetooth Low Energy advertisement scan response in Bluetooth Core Specifications 4.0 through 5.2, and extended scan response in Bluetooth Core Specifications 5.0 through 5.2, may be used to identify devices using Resolvable Private…

  • CVE-2022-43411MedOct 19, 2022
    risk 0.28cvss 5.3epss 0.01

    Jenkins GitLab Plugin 1.5.35 and earlier uses a non-constant time comparison function when checking whether the provided and expected webhook token are equal, potentially allowing attackers to use statistical methods to obtain a valid webhook token.

  • CVE-2021-36201MedOct 11, 2022
    risk 0.28cvss 4.3epss 0.01

    Under certain circumstances a CCURE Portal user could enumerate user accounts in CCURE 9000 version 2.90 and prior versions.

  • CVE-2022-32218MedSep 23, 2022
    risk 0.28cvss 4.3epss 0.01

    An information disclosure vulnerability exists in Rocket.Chat <v5, <v4.8.2 and <v4.7.5 due to the actionLinkHandler method was found to allow Message ID Enumeration with Regex MongoDB queries.

  • CVE-2022-36105MedSep 13, 2022
    risk 0.28cvss 5.3epss 0.01

    TYPO3 is an open source PHP based web content management system released under the GNU GPL. It has been discovered that observing response time during user authentication (backend and frontend) can be used to distinguish between existing and non-existing user accounts. Extension…

  • CVE-2022-36885MedJul 27, 2022
    risk 0.28cvss 5.3epss 0.01

    Jenkins GitHub Plugin 1.34.4 and earlier uses a non-constant time comparison function when checking whether the provided and computed webhook signatures are equal, allowing attackers to use statistical methods to obtain a valid webhook signature.

  • CVE-2022-32273MedJun 8, 2022
    risk 0.28cvss 4.3epss 0.01

    As a result of an observable discrepancy in returned messages, OPSWAT MetaDefender Core (MDCore) before 5.1.2 could allow an authenticated user to enumerate filenames on the server.