VYPR

CWE-203

Observable Discrepancy

BaseIncomplete

Description

The product behaves differently or sends different responses under different circumstances in a way that is observable to an unauthorized actor.

Hierarchy (View 1000)

Related attack patterns (CAPEC)

CAPEC-189

CVEs mapped to this weakness (762)

page 32 of 39
  • CVE-2024-47156LowDec 26, 2024
    risk 0.21cvss 3.3epss 0.00

    Some Honor products are affected by information leak vulnerability, successful exploitation could cause the information leak.

  • CVE-2024-31870LowJun 15, 2024
    risk 0.21cvss 3.3epss 0.00

    IBM Db2 for i 7.2, 7.3, 7.4, and 7.5 supplies user defined table function is vulnerable to user enumeration by a local authenticated attacker, without having authority to the related *USRPRF objects. This can be used by a malicious actor to gather information about users that…

  • CVE-2024-27839LowMay 14, 2024
    risk 0.21cvss 3.3epss 0.00

    A privacy issue was addressed by moving sensitive data to a more secure location. This issue is fixed in iOS 17.5 and iPadOS 17.5. A malicious application may be able to determine a user's current location.

  • CVE-2023-21349LowOct 30, 2023
    risk 0.21cvss 3.3epss 0.00

    In Package Manager, there is a possible way to determine whether an app is installed, without query permissions, due to side channel information disclosure. This could lead to local information disclosure with no additional execution privileges needed. User interaction is not…

  • CVE-2023-21348LowOct 30, 2023
    risk 0.21cvss 3.3epss 0.00

    In Window Manager, there is a possible way to determine whether an app is installed, without query permissions, due to side channel information disclosure. This could lead to local information disclosure with no additional execution privileges needed. User interaction is not…

  • CVE-2023-21346LowOct 30, 2023
    risk 0.21cvss 3.3epss 0.00

    In the Device Idle Controller, there is a possible way to determine whether an app is installed, without query permissions, due to side channel information disclosure. This could lead to local information disclosure with no additional execution privileges needed. User…

  • CVE-2023-21345LowOct 30, 2023
    risk 0.21cvss 3.3epss 0.00

    In Game Manager Service, there is a possible way to determine whether an app is installed, without query permissions, due to side channel information disclosure. This could lead to local information disclosure with no additional execution privileges needed. User interaction is…

  • CVE-2022-41354MedMar 27, 2023
    risk 0.21cvss 4.3epss 0.01

    An access control issue in Argo CD v2.4.12 and below allows unauthenticated attackers to enumerate existing applications.

  • CVE-2022-20559LowDec 16, 2022
    risk 0.21cvss 3.3epss 0.00

    In revokeOwnPermissionsOnKill of PermissionManager.java, there is a possible way to determine whether an app is installed, without query permissions, due to side channel information disclosure. This could lead to local information disclosure with no additional execution…

  • CVE-2022-20535LowDec 16, 2022
    risk 0.21cvss 3.3epss 0.00

    In registerLocalOnlyHotspotSoftApCallback of WifiManager.java, there is a possible way to determine whether an app is installed, without query permissions, due to side channel information disclosure. This could lead to local information disclosure with no additional execution…

  • CVE-2022-20320LowAug 12, 2022
    risk 0.21cvss 3.3epss 0.00

    In ActivityManager, there is a possible way to determine whether an app is installed, without query permissions, due to side channel information disclosure. This could lead to local information disclosure with no additional execution privileges needed. User interaction is not…

  • CVE-2022-20318LowAug 12, 2022
    risk 0.21cvss 3.3epss 0.00

    In PackageInstaller, there is a possible way to determine whether an app is installed, without query permissions, due to side channel information disclosure. This could lead to local information disclosure with no additional execution privileges needed. User interaction is not…

  • CVE-2022-20316LowAug 12, 2022
    risk 0.21cvss 3.3epss 0.00

    In ContentResolver, there is a possible way to determine whether an app is installed, without query permissions, due to side channel information disclosure. This could lead to local information disclosure with no additional execution privileges needed. User interaction is not…

  • CVE-2022-20309LowAug 12, 2022
    risk 0.21cvss 3.3epss 0.00

    In PackageInstaller, there is a possible way to determine whether an app is installed, without query permissions, due to side channel information disclosure. This could lead to local information disclosure with no additional execution privileges needed. User interaction is not…

  • CVE-2022-20307LowAug 12, 2022
    risk 0.21cvss 3.3epss 0.00

    In AlarmManagerService, there is a possible way to determine whether an app is installed, without query permissions, due to side channel information disclosure. This could lead to local information disclosure with no additional execution privileges needed. User interaction is…

  • CVE-2022-20252LowAug 11, 2022
    risk 0.21cvss 3.3epss 0.00

    In PackageManager, there is a possible way to determine whether an app is installed, without query permissions, due to side channel information disclosure. This could lead to local information disclosure with no additional execution privileges needed. User interaction is not…

  • CVE-2022-20251LowAug 11, 2022
    risk 0.21cvss 3.3epss 0.00

    In LocaleManager, there is a possible way to determine whether an app is installed, without query permissions, due to side channel information disclosure. This could lead to local information disclosure with no additional execution privileges needed. User interaction is not…

  • CVE-2022-20249LowAug 11, 2022
    risk 0.21cvss 3.3epss 0.00

    In LocaleManager, there is a possible way to determine whether an app is installed, without query permissions, due to side channel information disclosure. This could lead to local information disclosure with no additional execution privileges needed. User interaction is not…

  • CVE-2022-27814LowApr 14, 2022
    risk 0.21cvss 3.3epss 0.00

    SWHKD 1.1.5 allows arbitrary file-existence tests via the -c option.

  • CVE-2021-1032LowDec 15, 2021
    risk 0.21cvss 3.3epss 0.00

    In getMimeGroup of PackageManagerService.java, there is a possible way to determine whether an app is installed, without query permissions, due to side channel information disclosure. This could lead to local information disclosure with no additional execution privileges needed.…