VYPR

CWE-203

Observable Discrepancy

BaseIncomplete

Description

The product behaves differently or sends different responses under different circumstances in a way that is observable to an unauthorized actor.

Hierarchy (View 1000)

Related attack patterns (CAPEC)

CAPEC-189

CVEs mapped to this weakness (798)

page 7 of 40
  • CVE-2026-23937MedAug 18, 2026
    risk 0.42cvss 6.5epss 0.00

    The Zabbix API host.get action can be exploited by authenticated users to extract a host's PSK key leading to potential loss of data integrity.

  • CVE-2026-55555HigJul 28, 2026
    risk 0.42cvss 7.5epss 0.01

    Dompdf is an HTML to PDF converter for PHP. Versions 3.15 and prior are vulnerable to a File Existence Oracle attack through the manipulation of the CSS @font-face directive. By providing malicious HTML that references local files via the file:// protocol repeatedly, an attacker…

  • CVE-2026-14071MedJun 30, 2026
    risk 0.42cvss 6.5epss 0.00

    Side-channel information leakage in WebAudio in Google Chrome prior to 150.0.7871.47 allowed a remote attacker to leak cross-origin data via a crafted HTML page. (Chromium security severity: Low)

  • CVE-2026-11289MedJun 5, 2026
    risk 0.42cvss 6.5epss 0.00

    Side-channel information leakage in Paint in Google Chrome prior to 149.0.7827.53 allowed a remote attacker to leak cross-origin data via a crafted HTML page. (Chromium security severity: Low)

  • CVE-2026-11284MedJun 5, 2026
    risk 0.42cvss 6.5epss 0.00

    Side-channel information leakage in PerformanceAPIs in Google Chrome prior to 149.0.7827.53 allowed a remote attacker to leak cross-origin data via a crafted HTML page. (Chromium security severity: Low)

  • CVE-2026-26315HigFeb 19, 2026
    risk 0.42cvss 7.5epss 0.01

    go-ethereum (Geth) is a golang execution layer implementation of the Ethereum protocol. Prior to version 1.16.9, through a flaw in the ECIES cryptography implementation, an attacker may be able to extract bits of the p2p node key. The issue is resolved in the v1.16.9 and v1.17.0…

  • CVE-2025-6386HigJul 7, 2025
    risk 0.42cvss 7.5epss 0.00

    The parisneo/lollms repository is affected by a timing attack vulnerability in the `authenticate_user` function within the `lollms_authentication.py` file. This vulnerability allows attackers to enumerate valid usernames and guess passwords incrementally by analyzing response…

  • CVE-2024-10463MedOct 29, 2024
    risk 0.42cvss 6.5epss 0.01

    Video frames could have been leaked between origins in some situations. This vulnerability affects Firefox < 132, Firefox ESR < 128.4, Firefox ESR < 115.17, Thunderbird < 128.4, and Thunderbird < 132.

  • CVE-2023-30308MedMay 28, 2024
    risk 0.42cvss 6.5epss 0.00

    An issue discovered in Ruijie EG210G-P, Ruijie EG105G-V2, Ruijie NBR, and Ruijie EG105G routers allows attackers to hijack TCP sessions which could lead to a denial of service.

  • CVE-2023-5388MedMar 19, 2024
    risk 0.42cvss 6.5epss 0.01

    NSS was susceptible to a timing side-channel attack when performing RSA decryption. This attack could potentially allow an attacker to recover the private data. This vulnerability affects Firefox < 124, Firefox ESR < 115.9, and Thunderbird < 115.9.

  • CVE-2022-48220MedFeb 14, 2024
    risk 0.42cvss 6.4epss 0.00

    Potential vulnerabilities have been identified in certain HP Desktop PC products using the HP TamperLock feature, which might allow intrusion detection bypass via a physical attack. HP is releasing firmware and guidance to mitigate these potential vulnerabilities.

  • CVE-2023-6240MedFeb 4, 2024
    risk 0.42cvss 6.5epss 0.01

    A Marvin vulnerability side-channel leakage was found in the RSA decryption operation in the Linux Kernel. This issue may allow a network attacker to decrypt ciphertexts or forge signatures, limiting the services that use that private key.

  • CVE-2024-21484HigJan 22, 2024
    risk 0.42cvss 7.5epss 0.01

    Versions of the package jsrsasign before 11.0.0 are vulnerable to Observable Discrepancy via the RSA PKCS1.5 or RSAOAEP decryption process. An attacker can decrypt ciphertexts by exploiting the Marvin security flaw. Exploiting this vulnerability requires the attacker to have…

  • CVE-2023-4421MedDec 12, 2023
    risk 0.42cvss 6.5epss 0.01

    The NSS code used for checking PKCS#1 v1.5 was leaking information useful in mounting Bleichenbacher-like attacks. Both the overall correctness of the padding as well as the length of the encrypted message was leaking through timing side-channel. By sending large number of…

  • CVE-2023-40090MedDec 4, 2023
    risk 0.42cvss 6.5epss 0.01

    In BTM_BleVerifySignature of btm_ble.cc, there is a possible way to bypass signature validation due to side channel information disclosure. This could lead to remote escalation of privilege with no additional execution privileges needed. User interaction is not needed for…

  • CVE-2023-20575MedJul 11, 2023
    risk 0.42cvss 6.5epss 0.01

    A potential power side-channel vulnerability in some AMD processors may allow an authenticated attacker to use the power reporting functionality to monitor a program’s execution inside an AMD SEV VM potentially resulting in a leak of sensitive information.

  • CVE-2023-25741MedJun 2, 2023
    risk 0.42cvss 6.5epss 0.01

    When dragging and dropping an image cross-origin, the image's size could potentially be leaked. This behavior was shipped in 109 and caused web compatibility problems as well as this security concern, so the behavior was disabled until further review. This vulnerability affects…

  • CVE-2023-25728MedJun 2, 2023
    risk 0.42cvss 6.5epss 0.01

    The Content-Security-Policy-Report-Only header could allow an attacker to leak a child iframe's unredacted URI when interaction with that iframe triggers a redirect. This vulnerability affects Firefox < 110, Thunderbird < 102.8, and Firefox ESR < 102.8.

  • CVE-2023-26560MedApr 26, 2023
    risk 0.42cvss 6.5epss 0.01

    Northern.tech CFEngine Enterprise before 3.21.1 allows a subset of authenticated users to leverage the Scheduled Reports feature to read arbitrary files and potentially discover credentials.

  • CVE-2023-28840HigApr 4, 2023
    risk 0.42cvss 7.5epss 0.03

    Moby is an open source container framework developed by Docker Inc. that is distributed as Docker, Mirantis Container Runtime, and various other downstream projects/products. The Moby daemon component (`dockerd`), which is developed as moby/moby, is commonly referred to as…