Перейти к содержимому
Noroxi

CWE-208 · 199 записей

Observable Timing Discrepancy

CVE этого класса

199 записей

  • CVE-2021-43298
    40В плане

    The code that performs password matching when using 'Basic' HTTP authentication does not use a constant-time memcmp and has no rate-limiting

    КритическаяCVSS 9,8Эксплойта нетEPSS 2 %

    embedthis · goahead25 янв. 2022 г.

  • CVE-2023-41313
    39Наблюдать

    Apache Doris: Timing Attack weakness

    КритическаяCVSS 9,8Эксплойта нетEPSS 1 %

    apache · doris12 мар. 2024 г.

  • CVE-2021-21575
    39Наблюдать

    Dell BSAFE Micro Edition Suite, versions before 4.5.2, contain an Observable Timing Discrepancy Vulnerability.

    КритическаяCVSS 9,8Эксплойта нетEPSS 1 %

    dell · bsafe micro-edition-suite2 февр. 2024 г.

  • GHSA-xfqg-p48g-hh94
    38Наблюдать

    Login timing attack in ezsystems/ezpublish-kernel

    КритическаяCVSS 9,5Эксплойта нет

    Packagist · ezsystems/ezpublish-kernel2 июн. 2022 г.

  • GHSA-2x4v-g8cx-jxrq
    38Наблюдать

    Login timing attack in ibexa/core

    КритическаяCVSS 9,5Эксплойта нет

    Packagist · ibexa/core2 июн. 2022 г.

  • GHSA-342c-vcff-2ff2
    38Наблюдать

    Login timing attack in ezsystems/ezplatform-kernel

    КритическаяCVSS 9,5Эксплойта нет

    Packagist · ezsystems/ezplatform-kernel2 июн. 2022 г.

  • CVE-2026-77987
    37Наблюдать

    GitHub Enterprise Server notebook viewer vulnerable to Server-side request forgery

    КритическаяCVSS 9,3Эксплойта нетEPSS 1 %

    github · enterprise server22 сент. 2026 г.

  • CVE-2026-63132
    36Наблюдать

    OpenBao's Recovery Mode Vulnerable To Token Leakage via Timing Attack

    КритическаяCVSS 9,2Эксплойта нетEPSS 0 %

    openbao · openbao6 дней назад

  • CVE-2025-53940
    35Наблюдать

    Quiet uses insecure, inconsistent verification on local backend token

    ВысокаяCVSS 8,5Эксплойта нетEPSS 4 %

    tryquiet · quiet24 июл. 2025 г.

  • CVE-2026-23519
    35Наблюдать

    RustCrypto cmov: thumbv6m-none-eabi compiler emits non-constant time assembly when using cmovnz

    ВысокаяCVSS 8,9Эксплойта нетEPSS 1 %

    rustcrypto · cmov15 янв. 2026 г.

  • CVE-2024-42512
    34Наблюдать

    Vulnerability in the OPC UA .NET Standard Stack before 1.5.374.158 allows an unauthorized attacker to bypass application authentication when

    ВысокаяCVSS 8,6Эксплойта нетEPSS 1 %

    opcfoundation · ua .net standard stack10 февр. 2025 г.

  • CVE-2024-47178
    34Наблюдать

    basic-auth-connect's callback uses time unsafe string comparison

    ВысокаяCVSS 8,7Эксплойта нетEPSS 1 %

    expressjs · basic-auth-connect30 сент. 2024 г.

  • CVE-2026-72700
    34Наблюдать

    Grav before 3.9.1 Timing Attack via Non-Constant-Time Token Comparison

    ВысокаяCVSS 8,7Эксплойта нетEPSS 0 %

    getgrav · grav24 авг. 2026 г.

  • CVE-2026-43606
    34Наблюдать

    Observable Timing Discrepancy in the AMD Vitis Libraries ECDSA secp256k1 component could allow attackers with local access to potentially pe

    ВысокаяCVSS 8,5Эксплойта нетEPSS 0 %

    amd · vitis™ libraries - security module11 авг. 2026 г.

  • GHSA-qv5f-57gw-vx3h
    34Наблюдать

    Duplicate Advisory: Authorization Bypass in OPC UA .NET Standard Stack

    ВысокаяCVSS 8,6Эксплойта нет

    NuGet · OPCFoundation.NetStandard.Opc.Ua10 февр. 2025 г.

  • CVE-2026-16731
    33Наблюдать

    Authentication and authorization bypass via cryptographic timing side-channel attack in StationScout

    ВысокаяCVSS 8,3Эксплойта нетEPSS 0 %

    omicron electronics gmbh · omicron stationscout6 авг. 2026 г.

  • CVE-2024-29995
    32Наблюдать

    Windows Kerberos Elevation of Privilege Vulnerability

    ВысокаяCVSS 8,1Эксплойта нетEPSS 1 %

    microsoft · windows 10 150713 авг. 2024 г.

  • CVE-2026-47783
    32Наблюдать

    In memcached before 1.6.42, username data for SASL password database authentication has a timing side channel because a loop exits as soon a

    ВысокаяCVSS 8,1Эксплойта нетEPSS 1 %

    memcached · memcached20 мая 2026 г.

  • CVE-2026-28464
    32Наблюдать

    OpenClaw < 2026.2.12 - Timing Attack in Hooks Token Authentication

    ВысокаяCVSS 8,2Эксплойта нетEPSS 1 %

    openclaw · openclaw5 мар. 2026 г.

  • CVE-2023-25529
    32Наблюдать

    NVIDIA DGX H100 BMC and DGX A100 BMC contains a vulnerability in the host KVM daemon, where an unauthenticated attacker may cause a leak of

    ВысокаяCVSS 8,1Эксплойта нетEPSS 1 %

    nvidia · dgx h100 firmware19 сент. 2023 г.

  • CVE-2026-47784
    32Наблюдать

    In memcached before 1.6.42, password data for SASL password database authentication has a timing side channel because memcmp is used by sasl

    ВысокаяCVSS 8,1Эксплойта нетEPSS 1 %

    memcached · memcached20 мая 2026 г.

  • CVE-2024-31074
    32Наблюдать

    Observable timing discrepancy in some Intel(R) QAT Engine for OpenSSL software before version v1.6.1 may allow information disclosure via ne

    ВысокаяCVSS 8,2Эксплойта нетEPSS 1 %

    13 нояб. 2024 г.

  • CVE-2026-3337
    32Наблюдать

    Timing Side-Channel in AES-CCM Tag Verification in AWS-LC

    ВысокаяCVSS 8,2Эксплойта нетEPSS 0 %

    amazon · aws-lc-fips-sys2 мар. 2026 г.

  • CVE-2026-41588
    32Наблюдать

    RELATE: Timing Attack Vulnerability in course/auth.py — check_sign_in_key()

    ВысокаяCVSS 8,1Эксплойта нетEPSS 0 %

    inducer · relate8 мая 2026 г.

  • CVE-2026-32935
    32Наблюдать

    phpseclib's AES-CBC unpadding susceptible to padding oracle timing attack

    ВысокаяCVSS 8,2Эксплойта нетEPSS 0 %

    phpseclib · phpseclib19 мар. 2026 г.

Все классы уязвимостей