VYPR

CWE-203

Observable Discrepancy

BaseIncomplete

Description

The product behaves differently or sends different responses under different circumstances in a way that is observable to an unauthorized actor.

Hierarchy (View 1000)

Related attack patterns (CAPEC)

CAPEC-189

CVEs mapped to this weakness (798)

page 34 of 40
  • CVE-2022-20535LowDec 16, 2022
    risk 0.21cvss 3.3epss 0.00

    In registerLocalOnlyHotspotSoftApCallback of WifiManager.java, there is a possible way to determine whether an app is installed, without query permissions, due to side channel information disclosure. This could lead to local information disclosure with no additional execution…

  • CVE-2022-20320LowAug 12, 2022
    risk 0.21cvss 3.3epss 0.00

    In ActivityManager, there is a possible way to determine whether an app is installed, without query permissions, due to side channel information disclosure. This could lead to local information disclosure with no additional execution privileges needed. User interaction is not…

  • CVE-2022-20318LowAug 12, 2022
    risk 0.21cvss 3.3epss 0.00

    In PackageInstaller, there is a possible way to determine whether an app is installed, without query permissions, due to side channel information disclosure. This could lead to local information disclosure with no additional execution privileges needed. User interaction is not…

  • CVE-2022-20316LowAug 12, 2022
    risk 0.21cvss 3.3epss 0.00

    In ContentResolver, there is a possible way to determine whether an app is installed, without query permissions, due to side channel information disclosure. This could lead to local information disclosure with no additional execution privileges needed. User interaction is not…

  • CVE-2022-20309LowAug 12, 2022
    risk 0.21cvss 3.3epss 0.00

    In PackageInstaller, there is a possible way to determine whether an app is installed, without query permissions, due to side channel information disclosure. This could lead to local information disclosure with no additional execution privileges needed. User interaction is not…

  • CVE-2022-20307LowAug 12, 2022
    risk 0.21cvss 3.3epss 0.00

    In AlarmManagerService, there is a possible way to determine whether an app is installed, without query permissions, due to side channel information disclosure. This could lead to local information disclosure with no additional execution privileges needed. User interaction is…

  • CVE-2022-20252LowAug 11, 2022
    risk 0.21cvss 3.3epss 0.00

    In PackageManager, there is a possible way to determine whether an app is installed, without query permissions, due to side channel information disclosure. This could lead to local information disclosure with no additional execution privileges needed. User interaction is not…

  • CVE-2022-20251LowAug 11, 2022
    risk 0.21cvss 3.3epss 0.00

    In LocaleManager, there is a possible way to determine whether an app is installed, without query permissions, due to side channel information disclosure. This could lead to local information disclosure with no additional execution privileges needed. User interaction is not…

  • CVE-2022-20249LowAug 11, 2022
    risk 0.21cvss 3.3epss 0.00

    In LocaleManager, there is a possible way to determine whether an app is installed, without query permissions, due to side channel information disclosure. This could lead to local information disclosure with no additional execution privileges needed. User interaction is not…

  • CVE-2022-27814LowApr 14, 2022
    risk 0.21cvss 3.3epss 0.00

    SWHKD 1.1.5 allows arbitrary file-existence tests via the -c option.

  • CVE-2021-1032LowDec 15, 2021
    risk 0.21cvss 3.3epss 0.00

    In getMimeGroup of PackageManagerService.java, there is a possible way to determine whether an app is installed, without query permissions, due to side channel information disclosure. This could lead to local information disclosure with no additional execution privileges needed.…

  • CVE-2021-1031LowDec 15, 2021
    risk 0.21cvss 3.3epss 0.00

    In cancelNotificationsFromListener of NotificationManagerService.java, there is a possible way to determine whether an app is installed, without query permissions, due to side channel information disclosure. This could lead to local information disclosure with no additional…

  • CVE-2021-1018LowDec 15, 2021
    risk 0.21cvss 3.3epss 0.00

    In adjustStreamVolume of AudioService.java, there is a possible way to determine whether an app is installed, without query permissions, due to side channel information disclosure. This could lead to local information disclosure with no additional execution privileges needed.…

  • CVE-2021-1015LowDec 15, 2021
    risk 0.21cvss 3.3epss 0.00

    In getMeidForSlot of PhoneInterfaceManager.java, there is a possible way to determine whether an app is installed, without query permissions, due to side channel information disclosure. This could lead to local information disclosure with no additional execution privileges…

  • CVE-2021-0995LowDec 15, 2021
    risk 0.21cvss 3.3epss 0.00

    In registerSuggestionConnectionStatusListener of WifiServiceImpl.java, there is a possible way to determine whether an app is installed, without query permissions, due to side channel information disclosure. This could lead to local information disclosure with no additional…

  • CVE-2021-0990LowDec 15, 2021
    risk 0.21cvss 3.3epss 0.00

    In getDeviceId of PhoneSubInfoController.java, there is a possible way to determine whether an app is installed, without query permissions, due to side channel information disclosure. This could lead to local information disclosure with no additional execution privileges needed.…

  • CVE-2021-0989LowDec 15, 2021
    risk 0.21cvss 3.3epss 0.00

    In hasManageOngoingCallsPermission of TelecomServiceImpl.java, there is a possible way to determine whether an app is installed, without query permissions, due to side channel information disclosure. This could lead to local information disclosure with no additional execution…

  • CVE-2021-0988LowDec 15, 2021
    risk 0.21cvss 3.3epss 0.00

    In getLaunchedFromUid and getLaunchedFromPackage of ActivityClientController.java, there is a possible way to determine whether an app is installed, without query permissions, due to side channel information disclosure. This could lead to local information disclosure with no…

  • CVE-2021-0987LowDec 15, 2021
    risk 0.21cvss 3.3epss 0.00

    In getNeighboringCellInfo of PhoneInterfaceManager.java, there is a possible way to determine whether an app is installed, without query permissions, due to side channel information disclosure. This could lead to local information disclosure with no additional execution…

  • CVE-2020-24512LowJun 9, 2021
    risk 0.21cvss 3.3epss 0.00

    Observable timing discrepancy in some Intel(R) Processors may allow an authenticated user to potentially enable information disclosure via local access.