CWE-208 · 199 записей
Observable Timing Discrepancy
CVE этого класса
199 записей
| Срочность | CVE | Уязвимость | Критичность | KEV | EPSS | Опубликовано |
|---|---|---|---|---|---|---|
40В плане | CVE-2021-43298Эксплойта нет | The code that performs password matching when using 'Basic' HTTP authentication does not use a constant-time memcmp and has no rate-limitingembedthis · goahead · CWE-208 | Критическая9,8 | — | 2,3 % | 25 янв. 2022 г. |
39Наблюдать | CVE-2023-41313Эксплойта нет | Apache Doris: Timing Attack weaknessapache · doris · CWE-208 | Критическая9,8 | — | 1,0 % | 12 мар. 2024 г. |
39Наблюдать | CVE-2021-21575Эксплойта нет | Dell BSAFE Micro Edition Suite, versions before 4.5.2, contain an Observable Timing Discrepancy Vulnerability.dell · bsafe micro-edition-suite · CWE-208 | Критическая9,8 | — | 0,5 % | 2 февр. 2024 г. |
38Наблюдать | GHSA-xfqg-p48g-hh94Эксплойта нет | Login timing attack in ezsystems/ezpublish-kernelPackagist · ezsystems/ezpublish-kernel · CWE-208 | Критическая9,5 | — | — | 2 июн. 2022 г. |
38Наблюдать | GHSA-2x4v-g8cx-jxrqЭксплойта нет | Login timing attack in ibexa/corePackagist · ibexa/core · CWE-208 | Критическая9,5 | — | — | 2 июн. 2022 г. |
38Наблюдать | GHSA-342c-vcff-2ff2Эксплойта нет | Login timing attack in ezsystems/ezplatform-kernelPackagist · ezsystems/ezplatform-kernel · CWE-208 | Критическая9,5 | — | — | 2 июн. 2022 г. |
37Наблюдать | CVE-2026-77987Эксплойта нет | GitHub Enterprise Server notebook viewer vulnerable to Server-side request forgerygithub · enterprise server · CWE-208 | Критическая9,3 | — | 0,9 % | 22 сент. 2026 г. |
36Наблюдать | CVE-2026-63132Эксплойта нет | OpenBao's Recovery Mode Vulnerable To Token Leakage via Timing Attackopenbao · openbao · CWE-208 | Критическая9,2 | — | 0,5 % | 6 дней назад |
35Наблюдать | CVE-2025-53940Эксплойта нет | Quiet uses insecure, inconsistent verification on local backend tokentryquiet · quiet · CWE-208 | Высокая8,5 | — | 3,6 % | 24 июл. 2025 г. |
35Наблюдать | CVE-2026-23519Эксплойта нет | RustCrypto cmov: thumbv6m-none-eabi compiler emits non-constant time assembly when using cmovnzrustcrypto · cmov · CWE-208 | Высокая8,9 | — | 0,6 % | 15 янв. 2026 г. |
34Наблюдать | CVE-2024-42512Эксплойта нет | Vulnerability in the OPC UA .NET Standard Stack before 1.5.374.158 allows an unauthorized attacker to bypass application authentication whenopcfoundation · ua .net standard stack · CWE-208 | Высокая8,6 | — | 0,6 % | 10 февр. 2025 г. |
34Наблюдать | CVE-2024-47178Эксплойта нет | basic-auth-connect's callback uses time unsafe string comparisonexpressjs · basic-auth-connect · CWE-208 | Высокая8,7 | — | 0,5 % | 30 сент. 2024 г. |
34Наблюдать | CVE-2026-72700Эксплойта нет | Grav before 3.9.1 Timing Attack via Non-Constant-Time Token Comparisongetgrav · grav · CWE-208 | Высокая8,7 | — | 0,4 % | 24 авг. 2026 г. |
34Наблюдать | CVE-2026-43606Эксплойта нет | Observable Timing Discrepancy in the AMD Vitis Libraries ECDSA secp256k1 component could allow attackers with local access to potentially peamd · vitis™ libraries - security module · CWE-208 | Высокая8,5 | — | 0,2 % | 11 авг. 2026 г. |
34Наблюдать | GHSA-qv5f-57gw-vx3hЭксплойта нет | Duplicate Advisory: Authorization Bypass in OPC UA .NET Standard StackNuGet · OPCFoundation.NetStandard.Opc.Ua · CWE-208 | Высокая8,6 | — | — | 10 февр. 2025 г. |
33Наблюдать | CVE-2026-16731Эксплойта нет | Authentication and authorization bypass via cryptographic timing side-channel attack in StationScoutomicron electronics gmbh · omicron stationscout · CWE-208 | Высокая8,3 | — | 0,4 % | 6 авг. 2026 г. |
32Наблюдать | CVE-2024-29995Эксплойта нет | Windows Kerberos Elevation of Privilege Vulnerabilitymicrosoft · windows 10 1507 · CWE-208 | Высокая8,1 | — | 1,5 % | 13 авг. 2024 г. |
32Наблюдать | CVE-2026-47783Эксплойта нет | In memcached before 1.6.42, username data for SASL password database authentication has a timing side channel because a loop exits as soon amemcached · memcached · CWE-208 | Высокая8,1 | — | 1,3 % | 20 мая 2026 г. |
32Наблюдать | CVE-2026-28464Эксплойта нет | OpenClaw < 2026.2.12 - Timing Attack in Hooks Token Authenticationopenclaw · openclaw · CWE-208 | Высокая8,2 | — | 0,7 % | 5 мар. 2026 г. |
32Наблюдать | CVE-2023-25529Эксплойта нет | NVIDIA DGX H100 BMC and DGX A100 BMC contains a vulnerability in the host KVM daemon, where an unauthenticated attacker may cause a leak of nvidia · dgx h100 firmware · CWE-208 | Высокая8,1 | — | 0,6 % | 19 сент. 2023 г. |
32Наблюдать | CVE-2026-47784Эксплойта нет | In memcached before 1.6.42, password data for SASL password database authentication has a timing side channel because memcmp is used by saslmemcached · memcached · CWE-208 | Высокая8,1 | — | 0,6 % | 20 мая 2026 г. |
32Наблюдать | CVE-2024-31074Эксплойта нет | Observable timing discrepancy in some Intel(R) QAT Engine for OpenSSL software before version v1.6.1 may allow information disclosure via neCWE-208 | Высокая8,2 | — | 0,5 % | 13 нояб. 2024 г. |
32Наблюдать | CVE-2026-3337Эксплойта нет | Timing Side-Channel in AES-CCM Tag Verification in AWS-LCamazon · aws-lc-fips-sys · CWE-208 | Высокая8,2 | — | 0,5 % | 2 мар. 2026 г. |
32Наблюдать | CVE-2026-41588Эксплойта нет | RELATE: Timing Attack Vulnerability in course/auth.py — check_sign_in_key()inducer · relate · CWE-208 | Высокая8,1 | — | 0,5 % | 8 мая 2026 г. |
32Наблюдать | CVE-2026-32935Эксплойта нет | phpseclib's AES-CBC unpadding susceptible to padding oracle timing attackphpseclib · phpseclib · CWE-208 | Высокая8,2 | — | 0,4 % | 19 мар. 2026 г. |
- CVE-2021-4329840В плане
The code that performs password matching when using 'Basic' HTTP authentication does not use a constant-time memcmp and has no rate-limiting
КритическаяCVSS 9,8Эксплойта нетEPSS 2 %embedthis · goahead25 янв. 2022 г.
- CVE-2023-4131339Наблюдать
Apache Doris: Timing Attack weakness
КритическаяCVSS 9,8Эксплойта нетEPSS 1 %apache · doris12 мар. 2024 г.
- CVE-2021-2157539Наблюдать
Dell BSAFE Micro Edition Suite, versions before 4.5.2, contain an Observable Timing Discrepancy Vulnerability.
КритическаяCVSS 9,8Эксплойта нетEPSS 1 %dell · bsafe micro-edition-suite2 февр. 2024 г.
- GHSA-xfqg-p48g-hh9438Наблюдать
Login timing attack in ezsystems/ezpublish-kernel
КритическаяCVSS 9,5Эксплойта нетPackagist · ezsystems/ezpublish-kernel2 июн. 2022 г.
- GHSA-2x4v-g8cx-jxrq38Наблюдать
Login timing attack in ibexa/core
КритическаяCVSS 9,5Эксплойта нетPackagist · ibexa/core2 июн. 2022 г.
- GHSA-342c-vcff-2ff238Наблюдать
Login timing attack in ezsystems/ezplatform-kernel
КритическаяCVSS 9,5Эксплойта нетPackagist · ezsystems/ezplatform-kernel2 июн. 2022 г.
- CVE-2026-7798737Наблюдать
GitHub Enterprise Server notebook viewer vulnerable to Server-side request forgery
КритическаяCVSS 9,3Эксплойта нетEPSS 1 %github · enterprise server22 сент. 2026 г.
- CVE-2026-6313236Наблюдать
OpenBao's Recovery Mode Vulnerable To Token Leakage via Timing Attack
КритическаяCVSS 9,2Эксплойта нетEPSS 0 %openbao · openbao6 дней назад
- CVE-2025-5394035Наблюдать
Quiet uses insecure, inconsistent verification on local backend token
ВысокаяCVSS 8,5Эксплойта нетEPSS 4 %tryquiet · quiet24 июл. 2025 г.
- CVE-2026-2351935Наблюдать
RustCrypto cmov: thumbv6m-none-eabi compiler emits non-constant time assembly when using cmovnz
ВысокаяCVSS 8,9Эксплойта нетEPSS 1 %rustcrypto · cmov15 янв. 2026 г.
- CVE-2024-4251234Наблюдать
Vulnerability in the OPC UA .NET Standard Stack before 1.5.374.158 allows an unauthorized attacker to bypass application authentication when
ВысокаяCVSS 8,6Эксплойта нетEPSS 1 %opcfoundation · ua .net standard stack10 февр. 2025 г.
- CVE-2024-4717834Наблюдать
basic-auth-connect's callback uses time unsafe string comparison
ВысокаяCVSS 8,7Эксплойта нетEPSS 1 %expressjs · basic-auth-connect30 сент. 2024 г.
- CVE-2026-7270034Наблюдать
Grav before 3.9.1 Timing Attack via Non-Constant-Time Token Comparison
ВысокаяCVSS 8,7Эксплойта нетEPSS 0 %getgrav · grav24 авг. 2026 г.
- CVE-2026-4360634Наблюдать
Observable Timing Discrepancy in the AMD Vitis Libraries ECDSA secp256k1 component could allow attackers with local access to potentially pe
ВысокаяCVSS 8,5Эксплойта нетEPSS 0 %amd · vitis™ libraries - security module11 авг. 2026 г.
- GHSA-qv5f-57gw-vx3h34Наблюдать
Duplicate Advisory: Authorization Bypass in OPC UA .NET Standard Stack
ВысокаяCVSS 8,6Эксплойта нетNuGet · OPCFoundation.NetStandard.Opc.Ua10 февр. 2025 г.
- CVE-2026-1673133Наблюдать
Authentication and authorization bypass via cryptographic timing side-channel attack in StationScout
ВысокаяCVSS 8,3Эксплойта нетEPSS 0 %omicron electronics gmbh · omicron stationscout6 авг. 2026 г.
- CVE-2024-2999532Наблюдать
Windows Kerberos Elevation of Privilege Vulnerability
ВысокаяCVSS 8,1Эксплойта нетEPSS 1 %microsoft · windows 10 150713 авг. 2024 г.
- CVE-2026-4778332Наблюдать
In memcached before 1.6.42, username data for SASL password database authentication has a timing side channel because a loop exits as soon a
ВысокаяCVSS 8,1Эксплойта нетEPSS 1 %memcached · memcached20 мая 2026 г.
- CVE-2026-2846432Наблюдать
OpenClaw < 2026.2.12 - Timing Attack in Hooks Token Authentication
ВысокаяCVSS 8,2Эксплойта нетEPSS 1 %openclaw · openclaw5 мар. 2026 г.
- CVE-2023-2552932Наблюдать
NVIDIA DGX H100 BMC and DGX A100 BMC contains a vulnerability in the host KVM daemon, where an unauthenticated attacker may cause a leak of
ВысокаяCVSS 8,1Эксплойта нетEPSS 1 %nvidia · dgx h100 firmware19 сент. 2023 г.
- CVE-2026-4778432Наблюдать
In memcached before 1.6.42, password data for SASL password database authentication has a timing side channel because memcmp is used by sasl
ВысокаяCVSS 8,1Эксплойта нетEPSS 1 %memcached · memcached20 мая 2026 г.
- CVE-2024-3107432Наблюдать
Observable timing discrepancy in some Intel(R) QAT Engine for OpenSSL software before version v1.6.1 may allow information disclosure via ne
ВысокаяCVSS 8,2Эксплойта нетEPSS 1 %13 нояб. 2024 г.
- CVE-2026-333732Наблюдать
Timing Side-Channel in AES-CCM Tag Verification in AWS-LC
ВысокаяCVSS 8,2Эксплойта нетEPSS 0 %amazon · aws-lc-fips-sys2 мар. 2026 г.
- CVE-2026-4158832Наблюдать
RELATE: Timing Attack Vulnerability in course/auth.py — check_sign_in_key()
ВысокаяCVSS 8,1Эксплойта нетEPSS 0 %inducer · relate8 мая 2026 г.
- CVE-2026-3293532Наблюдать
phpseclib's AES-CBC unpadding susceptible to padding oracle timing attack
ВысокаяCVSS 8,2Эксплойта нетEPSS 0 %phpseclib · phpseclib19 мар. 2026 г.