VYPR

CWE-203

Observable Discrepancy

BaseIncomplete

Description

The product behaves differently or sends different responses under different circumstances in a way that is observable to an unauthorized actor.

Hierarchy (View 1000)

Related attack patterns (CAPEC)

CAPEC-189

CVEs mapped to this weakness (798)

page 33 of 40
  • CVE-2018-0495MedJun 13, 2018
    risk 0.24cvss 4.7epss 0.01

    Libgcrypt before 1.7.10 and 1.8.x before 1.8.3 allows a memory-cache side-channel attack on ECDSA signatures that can be mitigated through the use of blinding during the signing process in the _gcry_ecc_ecdsa_sign function in cipher/ecc-ecdsa.c, aka the Return Of the Hidden…

  • CVE-2022-47952LowJan 1, 2023
    risk 0.22cvss 3.3epss 0.01

    lxc-user-nic in lxc through 5.0.1 is installed setuid root, and may allow local users to infer whether any file exists, even within a protected directory tree, because "Failed to open" often indicates that a file does not exist, whereas "does not refer to a network namespace…

  • CVE-2026-55227MedAug 26, 2026
    risk 0.21cvss 4.3epss 0.00

    Weblate is a web-based localization tool. In versions prior to 2026.7, several endpoints look up objects in a globally scoped manner rather than restricting the lookup to projects the user can access, so they return HTTP 403 (Forbidden) instead of 404 (Not Found) when a user…

  • CVE-2026-44263MedMay 7, 2026
    risk 0.21cvss 4.3epss 0.00

    Weblate is a web based localization tool. Prior to version 5.17.1, the screenshots, tasks, and component link API allowed for the enumeration of translations in a project inaccessible to the user. This issue has been patched in version 5.17.1.

  • CVE-2026-21386MedMar 16, 2026
    risk 0.21cvss 4.3epss 0.00

    Mattermost versions 11.3.x <= 11.3.0, 11.2.x <= 11.2.2, 10.11.x <= 10.11.10 fail to use consistent error responses when handling the /mute command which allows an authenticated team member to enumerate private channels they are not authorized to know about via differing error…

  • CVE-2025-64749MedNov 13, 2025
    risk 0.21cvss 4.3epss 0.00

    Directus is a real-time API and App dashboard for managing SQL database content. An observable difference in error messaging was found in the Directus REST API in versions of Directus prior to version 11.13.0. The `/items/{collection}` API returns different error messages for…

  • CVE-2025-43743MedAug 19, 2025
    risk 0.21cvss 4.3epss 0.00

    Liferay Portal 7.4.0 through 7.4.3.132, and Liferay DXP 2025.Q1.0 through 2025.Q1.5, 2024.Q4.0 through 2024.Q4.7, 2024.Q3.1 through 2024.Q3.13, 2024.Q2.0 through 2024.Q2.13, 2024.Q1.1 through 2024.Q1.15 and 7.4 GA through update 92 allows any authenticated remote user to view…

  • CVE-2025-43739MedAug 19, 2025
    risk 0.21cvss 4.3epss 0.00

    Liferay Portal 7.4.0 through 7.4.3.132, and Liferay DXP 2025.Q1.0 through 2025.Q1.6, 2024.Q4.0 through 2024.Q4.7, 2024.Q3.1 through 2024.Q3.13, 2024.Q2.0 through 2024.Q2.13, 2024.Q1.1 through 2024.Q1.16 and 7.4 GA through update 92 allow any authenticated user to modify the…

  • CVE-2025-46804LowMay 26, 2025
    risk 0.21cvss 3.3epss 0.00

    A minor information leak when running Screen with setuid-root privileges allows unprivileged users to deduce information about a path that would otherwise not be available. Affected are older Screen versions, as well as version 5.0.0.

  • CVE-2024-47150LowDec 26, 2024
    risk 0.21cvss 3.3epss 0.00

    Some Honor products are affected by information leak vulnerability, successful exploitation could cause the information leak.

  • CVE-2024-47149LowDec 26, 2024
    risk 0.21cvss 3.3epss 0.00

    Some Honor products are affected by incorrect privilege assignment vulnerability, successful exploitation could cause device service exceptions.

  • CVE-2024-47156LowDec 26, 2024
    risk 0.21cvss 3.3epss 0.00

    Some Honor products are affected by information leak vulnerability, successful exploitation could cause the information leak.

  • CVE-2024-31870LowJun 15, 2024
    risk 0.21cvss 3.3epss 0.00

    IBM Db2 for i 7.2, 7.3, 7.4, and 7.5 supplies user defined table function is vulnerable to user enumeration by a local authenticated attacker, without having authority to the related *USRPRF objects. This can be used by a malicious actor to gather information about users that…

  • CVE-2024-27839LowMay 14, 2024
    risk 0.21cvss 3.3epss 0.00

    A privacy issue was addressed by moving sensitive data to a more secure location. This issue is fixed in iOS 17.5 and iPadOS 17.5. A malicious application may be able to determine a user's current location.

  • CVE-2023-21349LowOct 30, 2023
    risk 0.21cvss 3.3epss 0.00

    In Package Manager, there is a possible way to determine whether an app is installed, without query permissions, due to side channel information disclosure. This could lead to local information disclosure with no additional execution privileges needed. User interaction is not…

  • CVE-2023-21348LowOct 30, 2023
    risk 0.21cvss 3.3epss 0.00

    In Window Manager, there is a possible way to determine whether an app is installed, without query permissions, due to side channel information disclosure. This could lead to local information disclosure with no additional execution privileges needed. User interaction is not…

  • CVE-2023-21346LowOct 30, 2023
    risk 0.21cvss 3.3epss 0.00

    In the Device Idle Controller, there is a possible way to determine whether an app is installed, without query permissions, due to side channel information disclosure. This could lead to local information disclosure with no additional execution privileges needed. User…

  • CVE-2023-21345LowOct 30, 2023
    risk 0.21cvss 3.3epss 0.00

    In Game Manager Service, there is a possible way to determine whether an app is installed, without query permissions, due to side channel information disclosure. This could lead to local information disclosure with no additional execution privileges needed. User interaction is…

  • CVE-2022-41354MedMar 27, 2023
    risk 0.21cvss 4.3epss 0.01

    An access control issue in Argo CD v2.4.12 and below allows unauthenticated attackers to enumerate existing applications.

  • CVE-2022-20559LowDec 16, 2022
    risk 0.21cvss 3.3epss 0.00

    In revokeOwnPermissionsOnKill of PermissionManager.java, there is a possible way to determine whether an app is installed, without query permissions, due to side channel information disclosure. This could lead to local information disclosure with no additional execution…