Перейти к содержимому
Noroxi

CWE-203 · 662 записей

Observable Discrepancy

CVE этого класса

662 записей

  • CVE-2024-39891
    52В плане

    In the Twilio Authy API, accessed by Authy Android before 25.1.0 and Authy iOS before 26.1.0, an unauthenticated endpoint provided access to

    СредняяCVSS 5,3KEVГотовый эксплойтEPSS 2 %

    twilio · authy2 июл. 2024 г.

  • CVE-2017-5753
    50В плане

    Systems with microprocessors utilizing speculative execution and branch prediction may allow unauthorized disclosure of information to an at

    СредняяCVSS 5,6Proof of conceptEPSS 94 %

    intel · atom c4 янв. 2018 г.

  • CVE-2017-5715
    44В плане

    Systems with microprocessors utilizing speculative execution and indirect branch prediction may allow unauthorized disclosure of information

    СредняяCVSS 5,6Proof of conceptEPSS 74 %

    intel · atom c4 янв. 2018 г.

  • CVE-2003-0190
    43В плане

    OpenSSH-portable (OpenSSH) 3.6.1p1 and earlier with PAM support enabled immediately sends an error message when a user does not exist, which

    СредняяCVSS 5,0Готовый эксплойтEPSS 77 %

    openbsd · openssh12 мая 2003 г.

  • CVE-2019-10071
    42В плане

    The code which checks HMAC in form submissions used String.equals() for comparisons, which results in a timing side channel for the comparis

    КритическаяCVSS 9,8Эксплойта нетEPSS 9 %

    apache · tapestry16 сент. 2019 г.

  • CVE-2018-3639
    40В плане

    Systems with microprocessors utilizing speculative execution and speculative execution of memory reads before the addresses of all prior mem

    СредняяCVSS 5,5Proof of conceptEPSS 61 %

    intel · atom c22 мая 2018 г.

  • CVE-2022-23303
    40В плане

    The implementations of SAE in hostapd before 2.10 and wpa_supplicant before 2.10 are vulnerable to side channel attacks as a result of cache

    КритическаяCVSS 9,8Proof of conceptEPSS 3 %

    w1.fi · hostapd16 янв. 2022 г.

  • CVE-2022-23304
    40В плане

    The implementations of EAP-pwd in hostapd before 2.10 and wpa_supplicant before 2.10 are vulnerable to side-channel attacks as a result of c

    КритическаяCVSS 9,8Эксплойта нетEPSS 2 %

    w1.fi · hostapd16 янв. 2022 г.

  • CVE-2018-1000884
    39Наблюдать

    Vesta CP version Prior to commit f6f6f9cfbbf2979e301956d1c6ab5c44386822c0 -- any release prior to 0.9.8-18 contains a CWE-208 / Information

    КритическаяCVSS 9,8Эксплойта нетEPSS 1 %

    vestacp · vesta control panel20 дек. 2018 г.

  • CVE-2024-23771
    39Наблюдать

    darkhttpd before 1.15 uses strcmp (which is not constant time) to verify authentication, which makes it easier for remote attackers to bypas

    КритическаяCVSS 9,8Эксплойта нетEPSS 1 %

    unix4lyfe · darkhttpd22 янв. 2024 г.

  • CVE-2024-25189
    39Наблюдать

    libjwt 1.15.3 uses strcmp (which is not constant time) to verify authentication, which makes it easier to bypass authentication via a timing

    КритическаяCVSS 9,8Эксплойта нетEPSS 1 %

    libjwt · libjwt8 февр. 2024 г.

  • CVE-2024-25190
    39Наблюдать

    l8w8jwt 2.2.1 uses memcmp (which is not constant time) to verify authentication, which makes it easier to bypass authentication via a timing

    КритическаяCVSS 9,8Эксплойта нетEPSS 1 %

    glitchedpolygons · l8w8jwt8 февр. 2024 г.

  • CVE-2023-40756
    39Наблюдать

    User enumeration is found in PHPJabbers Callback Widget v1.0.

    КритическаяCVSS 9,8Эксплойта нетEPSS 1 %

    phpjabbers · callback widget28 авг. 2023 г.

  • CVE-2024-25191
    39Наблюдать

    php-jwt 1.0.0 uses strcmp (which is not constant time) to verify authentication, which makes it easier to bypass authentication via a timing

    КритическаяCVSS 9,8Эксплойта нетEPSS 1 %

    zihanggao · php-jwt8 февр. 2024 г.

  • CVE-2024-25714
    39Наблюдать

    In Rhonabwy through 1.1.13, HMAC signature verification uses a strcmp function that is vulnerable to side-channel attacks, because it stops

    КритическаяCVSS 9,8Эксплойта нетEPSS 1 %

    rhonabwy project · rhonabwy10 февр. 2024 г.

  • CVE-2023-50708
    39Наблюдать

    yii2-authclient vulnerable to possible timing attack on string comparison in OAuth1, OAuth2 and OpenID Connect implementation

    КритическаяCVSS 9,8Эксплойта нетEPSS 1 %

    yiiframework · yii2-authclient22 дек. 2023 г.

  • CVE-2025-27667
    39Наблюдать

    Vasion Print (formerly PrinterLogic) before Virtual Appliance Host 22.0.843 Application 20.0.1923 allows Administrative User Email Enumerati

    КритическаяCVSS 9,8Эксплойта нетEPSS 1 %

    printerlogic · vasion print5 мар. 2025 г.

  • CVE-2022-40895
    37Наблюдать

    In certain Nedi products, a vulnerability in the web UI of NeDi login & Community login could allow an unauthenticated, remote attacker to a

    КритическаяCVSS 9,1Эксплойта нетEPSS 2 %

    nedi · nedi6 окт. 2022 г.

  • CVE-2026-72699
    37Наблюдать

    Grav Login Plugin before 3.9.1 Email Enumeration via Registration

    КритическаяCVSS 9,3Эксплойта нетEPSS 0 %

    getgrav · grav-plugin-login24 авг. 2026 г.

  • CVE-2023-26556
    36Наблюдать

    io.finnet tss-lib before 2.0.0 can leak a secret key via a timing side-channel attack because it relies on the scalar-multiplication impleme

    КритическаяCVSS 9,1Эксплойта нетEPSS 1 %

    iofinnet · tss-lib21 апр. 2023 г.

  • CVE-2026-74961
    36Наблюдать

    Side-channel in the Web Audio component

    КритическаяCVSS 9,1Эксплойта нетEPSS 0 %

    mozilla · firefox18 авг. 2026 г.

  • GHSA-346h-749j-r28w
    36Наблюдать

    PHPECC vulnerable to multiple cryptographic side-channel attacks

    КритическаяCVSS 9,1Эксплойта нет

    Packagist · mdanter/ecc25 апр. 2024 г.

  • CVE-2017-6168
    35Наблюдать

    On BIG-IP versions 11.6.0-11.6.2 (fixed in 11.6.2 HF1), 12.0.0-12.1.2 HF1 (fixed in 12.1.2 HF2), or 13.0.0-13.0.0 HF2 (fixed in 13.0.0 HF3)

    ВысокаяCVSS 7,4Готовый эксплойтEPSS 20 %

    f5 · big-ip ltm17 нояб. 2017 г.

  • CVE-2022-20866
    35Наблюдать

    Cisco Adaptive Security Appliance Software and Firepower Threat Defense Software RSA Private Key Leak Vulnerability

    ВысокаяCVSS 7,5Proof of conceptEPSS 17 %

    cisco · adaptive security appliance software10 авг. 2022 г.

  • CVE-2024-6420
    35Наблюдать

    Hide My WP Ghost < 5.2.02 - Hidden Login Page Disclosure

    ВысокаяCVSS 8,6Proof of conceptEPSS 2 %

    wpplugins · hide my wp ghost23 июл. 2024 г.

Все классы уязвимостей