CWE-203 · 662 записей
Observable Discrepancy
CVE этого класса
662 записей
| Срочность | CVE | Уязвимость | Критичность | KEV | EPSS | Опубликовано |
|---|---|---|---|---|---|---|
52В плане | CVE-2024-39891Готовый эксплойт | In the Twilio Authy API, accessed by Authy Android before 25.1.0 and Authy iOS before 26.1.0, an unauthenticated endpoint provided access totwilio · authy · CWE-203 | Средняя5,3 | KEV | 1,7 % | 2 июл. 2024 г. |
50В плане | CVE-2017-5753Proof of concept | Systems with microprocessors utilizing speculative execution and branch prediction may allow unauthorized disclosure of information to an atintel · atom c · CWE-203 | Средняя5,6 | — | 93,8 % | 4 янв. 2018 г. |
44В плане | CVE-2017-5715Proof of concept | Systems with microprocessors utilizing speculative execution and indirect branch prediction may allow unauthorized disclosure of informationintel · atom c · CWE-203 | Средняя5,6 | — | 74,0 % | 4 янв. 2018 г. |
43В плане | CVE-2003-0190Готовый эксплойт | OpenSSH-portable (OpenSSH) 3.6.1p1 and earlier with PAM support enabled immediately sends an error message when a user does not exist, whichopenbsd · openssh · CWE-203 | Средняя5,0 | — | 76,8 % | 12 мая 2003 г. |
42В плане | CVE-2019-10071Эксплойта нет | The code which checks HMAC in form submissions used String.equals() for comparisons, which results in a timing side channel for the comparisapache · tapestry · CWE-203 | Критическая9,8 | — | 8,8 % | 16 сент. 2019 г. |
40В плане | CVE-2018-3639Proof of concept | Systems with microprocessors utilizing speculative execution and speculative execution of memory reads before the addresses of all prior memintel · atom c · CWE-203 | Средняя5,5 | — | 60,6 % | 22 мая 2018 г. |
40В плане | CVE-2022-23303Proof of concept | The implementations of SAE in hostapd before 2.10 and wpa_supplicant before 2.10 are vulnerable to side channel attacks as a result of cachew1.fi · hostapd · CWE-203 | Критическая9,8 | — | 3,1 % | 16 янв. 2022 г. |
40В плане | CVE-2022-23304Эксплойта нет | The implementations of EAP-pwd in hostapd before 2.10 and wpa_supplicant before 2.10 are vulnerable to side-channel attacks as a result of cw1.fi · hostapd · CWE-203 | Критическая9,8 | — | 1,9 % | 16 янв. 2022 г. |
39Наблюдать | CVE-2018-1000884Эксплойта нет | Vesta CP version Prior to commit f6f6f9cfbbf2979e301956d1c6ab5c44386822c0 -- any release prior to 0.9.8-18 contains a CWE-208 / Information vestacp · vesta control panel · CWE-203 | Критическая9,8 | — | 1,3 % | 20 дек. 2018 г. |
39Наблюдать | CVE-2024-23771Эксплойта нет | darkhttpd before 1.15 uses strcmp (which is not constant time) to verify authentication, which makes it easier for remote attackers to bypasunix4lyfe · darkhttpd · CWE-203 | Критическая9,8 | — | 1,1 % | 22 янв. 2024 г. |
39Наблюдать | CVE-2024-25189Эксплойта нет | libjwt 1.15.3 uses strcmp (which is not constant time) to verify authentication, which makes it easier to bypass authentication via a timinglibjwt · libjwt · CWE-203 | Критическая9,8 | — | 1,0 % | 8 февр. 2024 г. |
39Наблюдать | CVE-2024-25190Эксплойта нет | l8w8jwt 2.2.1 uses memcmp (which is not constant time) to verify authentication, which makes it easier to bypass authentication via a timingglitchedpolygons · l8w8jwt · CWE-203 | Критическая9,8 | — | 0,9 % | 8 февр. 2024 г. |
39Наблюдать | CVE-2023-40756Эксплойта нет | User enumeration is found in PHPJabbers Callback Widget v1.0.phpjabbers · callback widget · CWE-203 | Критическая9,8 | — | 0,9 % | 28 авг. 2023 г. |
39Наблюдать | CVE-2024-25191Эксплойта нет | php-jwt 1.0.0 uses strcmp (which is not constant time) to verify authentication, which makes it easier to bypass authentication via a timingzihanggao · php-jwt · CWE-203 | Критическая9,8 | — | 0,9 % | 8 февр. 2024 г. |
39Наблюдать | CVE-2024-25714Эксплойта нет | In Rhonabwy through 1.1.13, HMAC signature verification uses a strcmp function that is vulnerable to side-channel attacks, because it stops rhonabwy project · rhonabwy · CWE-203 | Критическая9,8 | — | 0,8 % | 10 февр. 2024 г. |
39Наблюдать | CVE-2023-50708Эксплойта нет | yii2-authclient vulnerable to possible timing attack on string comparison in OAuth1, OAuth2 and OpenID Connect implementationyiiframework · yii2-authclient · CWE-203 | Критическая9,8 | — | 0,7 % | 22 дек. 2023 г. |
39Наблюдать | CVE-2025-27667Эксплойта нет | Vasion Print (formerly PrinterLogic) before Virtual Appliance Host 22.0.843 Application 20.0.1923 allows Administrative User Email Enumeratiprinterlogic · vasion print · CWE-203 | Критическая9,8 | — | 0,7 % | 5 мар. 2025 г. |
37Наблюдать | CVE-2022-40895Эксплойта нет | In certain Nedi products, a vulnerability in the web UI of NeDi login & Community login could allow an unauthenticated, remote attacker to anedi · nedi · CWE-203 | Критическая9,1 | — | 1,8 % | 6 окт. 2022 г. |
37Наблюдать | CVE-2026-72699Эксплойта нет | Grav Login Plugin before 3.9.1 Email Enumeration via Registrationgetgrav · grav-plugin-login · CWE-203 | Критическая9,3 | — | 0,3 % | 24 авг. 2026 г. |
36Наблюдать | CVE-2023-26556Эксплойта нет | io.finnet tss-lib before 2.0.0 can leak a secret key via a timing side-channel attack because it relies on the scalar-multiplication implemeiofinnet · tss-lib · CWE-203 | Критическая9,1 | — | 0,9 % | 21 апр. 2023 г. |
36Наблюдать | CVE-2026-74961Эксплойта нет | Side-channel in the Web Audio componentmozilla · firefox · CWE-203 | Критическая9,1 | — | 0,4 % | 18 авг. 2026 г. |
36Наблюдать | GHSA-346h-749j-r28wЭксплойта нет | PHPECC vulnerable to multiple cryptographic side-channel attacksPackagist · mdanter/ecc · CWE-203 | Критическая9,1 | — | — | 25 апр. 2024 г. |
35Наблюдать | CVE-2017-6168Готовый эксплойт | On BIG-IP versions 11.6.0-11.6.2 (fixed in 11.6.2 HF1), 12.0.0-12.1.2 HF1 (fixed in 12.1.2 HF2), or 13.0.0-13.0.0 HF2 (fixed in 13.0.0 HF3) f5 · big-ip ltm · CWE-203 | Высокая7,4 | — | 19,6 % | 17 нояб. 2017 г. |
35Наблюдать | CVE-2022-20866Proof of concept | Cisco Adaptive Security Appliance Software and Firepower Threat Defense Software RSA Private Key Leak Vulnerabilitycisco · adaptive security appliance software · CWE-203 | Высокая7,5 | — | 17,4 % | 10 авг. 2022 г. |
35Наблюдать | CVE-2024-6420Proof of concept | Hide My WP Ghost < 5.2.02 - Hidden Login Page Disclosurewpplugins · hide my wp ghost · CWE-203 | Высокая8,6 | — | 1,8 % | 23 июл. 2024 г. |
- CVE-2024-3989152В плане
In the Twilio Authy API, accessed by Authy Android before 25.1.0 and Authy iOS before 26.1.0, an unauthenticated endpoint provided access to
СредняяCVSS 5,3KEVГотовый эксплойтEPSS 2 %twilio · authy2 июл. 2024 г.
- CVE-2017-575350В плане
Systems with microprocessors utilizing speculative execution and branch prediction may allow unauthorized disclosure of information to an at
СредняяCVSS 5,6Proof of conceptEPSS 94 %intel · atom c4 янв. 2018 г.
- CVE-2017-571544В плане
Systems with microprocessors utilizing speculative execution and indirect branch prediction may allow unauthorized disclosure of information
СредняяCVSS 5,6Proof of conceptEPSS 74 %intel · atom c4 янв. 2018 г.
- CVE-2003-019043В плане
OpenSSH-portable (OpenSSH) 3.6.1p1 and earlier with PAM support enabled immediately sends an error message when a user does not exist, which
СредняяCVSS 5,0Готовый эксплойтEPSS 77 %openbsd · openssh12 мая 2003 г.
- CVE-2019-1007142В плане
The code which checks HMAC in form submissions used String.equals() for comparisons, which results in a timing side channel for the comparis
КритическаяCVSS 9,8Эксплойта нетEPSS 9 %apache · tapestry16 сент. 2019 г.
- CVE-2018-363940В плане
Systems with microprocessors utilizing speculative execution and speculative execution of memory reads before the addresses of all prior mem
СредняяCVSS 5,5Proof of conceptEPSS 61 %intel · atom c22 мая 2018 г.
- CVE-2022-2330340В плане
The implementations of SAE in hostapd before 2.10 and wpa_supplicant before 2.10 are vulnerable to side channel attacks as a result of cache
КритическаяCVSS 9,8Proof of conceptEPSS 3 %w1.fi · hostapd16 янв. 2022 г.
- CVE-2022-2330440В плане
The implementations of EAP-pwd in hostapd before 2.10 and wpa_supplicant before 2.10 are vulnerable to side-channel attacks as a result of c
КритическаяCVSS 9,8Эксплойта нетEPSS 2 %w1.fi · hostapd16 янв. 2022 г.
- CVE-2018-100088439Наблюдать
Vesta CP version Prior to commit f6f6f9cfbbf2979e301956d1c6ab5c44386822c0 -- any release prior to 0.9.8-18 contains a CWE-208 / Information
КритическаяCVSS 9,8Эксплойта нетEPSS 1 %vestacp · vesta control panel20 дек. 2018 г.
- CVE-2024-2377139Наблюдать
darkhttpd before 1.15 uses strcmp (which is not constant time) to verify authentication, which makes it easier for remote attackers to bypas
КритическаяCVSS 9,8Эксплойта нетEPSS 1 %unix4lyfe · darkhttpd22 янв. 2024 г.
- CVE-2024-2518939Наблюдать
libjwt 1.15.3 uses strcmp (which is not constant time) to verify authentication, which makes it easier to bypass authentication via a timing
КритическаяCVSS 9,8Эксплойта нетEPSS 1 %libjwt · libjwt8 февр. 2024 г.
- CVE-2024-2519039Наблюдать
l8w8jwt 2.2.1 uses memcmp (which is not constant time) to verify authentication, which makes it easier to bypass authentication via a timing
КритическаяCVSS 9,8Эксплойта нетEPSS 1 %glitchedpolygons · l8w8jwt8 февр. 2024 г.
- CVE-2023-4075639Наблюдать
User enumeration is found in PHPJabbers Callback Widget v1.0.
КритическаяCVSS 9,8Эксплойта нетEPSS 1 %phpjabbers · callback widget28 авг. 2023 г.
- CVE-2024-2519139Наблюдать
php-jwt 1.0.0 uses strcmp (which is not constant time) to verify authentication, which makes it easier to bypass authentication via a timing
КритическаяCVSS 9,8Эксплойта нетEPSS 1 %zihanggao · php-jwt8 февр. 2024 г.
- CVE-2024-2571439Наблюдать
In Rhonabwy through 1.1.13, HMAC signature verification uses a strcmp function that is vulnerable to side-channel attacks, because it stops
КритическаяCVSS 9,8Эксплойта нетEPSS 1 %rhonabwy project · rhonabwy10 февр. 2024 г.
- CVE-2023-5070839Наблюдать
yii2-authclient vulnerable to possible timing attack on string comparison in OAuth1, OAuth2 and OpenID Connect implementation
КритическаяCVSS 9,8Эксплойта нетEPSS 1 %yiiframework · yii2-authclient22 дек. 2023 г.
- CVE-2025-2766739Наблюдать
Vasion Print (formerly PrinterLogic) before Virtual Appliance Host 22.0.843 Application 20.0.1923 allows Administrative User Email Enumerati
КритическаяCVSS 9,8Эксплойта нетEPSS 1 %printerlogic · vasion print5 мар. 2025 г.
- CVE-2022-4089537Наблюдать
In certain Nedi products, a vulnerability in the web UI of NeDi login & Community login could allow an unauthenticated, remote attacker to a
КритическаяCVSS 9,1Эксплойта нетEPSS 2 %nedi · nedi6 окт. 2022 г.
- CVE-2026-7269937Наблюдать
Grav Login Plugin before 3.9.1 Email Enumeration via Registration
КритическаяCVSS 9,3Эксплойта нетEPSS 0 %getgrav · grav-plugin-login24 авг. 2026 г.
- CVE-2023-2655636Наблюдать
io.finnet tss-lib before 2.0.0 can leak a secret key via a timing side-channel attack because it relies on the scalar-multiplication impleme
КритическаяCVSS 9,1Эксплойта нетEPSS 1 %iofinnet · tss-lib21 апр. 2023 г.
- CVE-2026-7496136Наблюдать
Side-channel in the Web Audio component
КритическаяCVSS 9,1Эксплойта нетEPSS 0 %mozilla · firefox18 авг. 2026 г.
- GHSA-346h-749j-r28w36Наблюдать
PHPECC vulnerable to multiple cryptographic side-channel attacks
КритическаяCVSS 9,1Эксплойта нетPackagist · mdanter/ecc25 апр. 2024 г.
- CVE-2017-616835Наблюдать
On BIG-IP versions 11.6.0-11.6.2 (fixed in 11.6.2 HF1), 12.0.0-12.1.2 HF1 (fixed in 12.1.2 HF2), or 13.0.0-13.0.0 HF2 (fixed in 13.0.0 HF3)
ВысокаяCVSS 7,4Готовый эксплойтEPSS 20 %f5 · big-ip ltm17 нояб. 2017 г.
- CVE-2022-2086635Наблюдать
Cisco Adaptive Security Appliance Software and Firepower Threat Defense Software RSA Private Key Leak Vulnerability
ВысокаяCVSS 7,5Proof of conceptEPSS 17 %cisco · adaptive security appliance software10 авг. 2022 г.
- CVE-2024-642035Наблюдать
Hide My WP Ghost < 5.2.02 - Hidden Login Page Disclosure
ВысокаяCVSS 8,6Proof of conceptEPSS 2 %wpplugins · hide my wp ghost23 июл. 2024 г.