Vulnerabilities > Incorrect Comparison

DATE CVE VULNERABILITY TITLE RISK
2024-01-24 CVE-2024-23903 Incorrect Comparison vulnerability in Jenkins Github Branch Source
Jenkins GitLab Branch Source Plugin 684.vea_fa_7c1e2fe3 and earlier uses a non-constant time comparison function when checking whether the provided and expected webhook token are equal, potentially allowing attackers to use statistical methods to obtain a valid webhook token.
network
low complexity
jenkins CWE-697
5.3
2023-12-12 CVE-2023-49994 Incorrect Comparison vulnerability in Espeak-Ng 1.52
Espeak-ng 1.52-dev was discovered to contain a Floating Point Exception via the function PeaksToHarmspect at wavegen.c.
local
low complexity
espeak-ng CWE-697
5.5
2023-10-25 CVE-2023-46656 Incorrect Comparison vulnerability in Jenkins Multibranch Scan Webhook Trigger
Jenkins Multibranch Scan Webhook Trigger Plugin 1.0.9 and earlier uses a non-constant time comparison function when checking whether the provided and expected webhook token are equal, potentially allowing attackers to use statistical methods to obtain a valid webhook token.
network
low complexity
jenkins CWE-697
5.3
2023-10-25 CVE-2023-46657 Incorrect Comparison vulnerability in Jenkins Gogs
Jenkins Gogs Plugin 1.0.15 and earlier uses a non-constant time comparison function when checking whether the provided and expected webhook token are equal, potentially allowing attackers to use statistical methods to obtain a valid webhook token.
network
low complexity
jenkins CWE-697
5.3
2023-10-25 CVE-2023-46658 Incorrect Comparison vulnerability in Jenkins Msteams Webhook Trigger 0.1.0/0.1.1
Jenkins MSTeams Webhook Trigger Plugin 0.1.1 and earlier uses a non-constant time comparison function when checking whether the provided and expected webhook token are equal, potentially allowing attackers to use statistical methods to obtain a valid webhook token.
network
low complexity
jenkins CWE-697
5.3
2023-10-25 CVE-2023-46660 Incorrect Comparison vulnerability in Jenkins Zanata
Jenkins Zanata Plugin 0.6 and earlier uses a non-constant time comparison function when checking whether the provided and expected webhook token hashes are equal, potentially allowing attackers to use statistical methods to obtain a valid webhook token.
network
low complexity
jenkins CWE-697
5.3
2023-10-18 CVE-2023-46009 Incorrect Comparison vulnerability in Lcdf Gifsicle 1.94
gifsicle-1.94 was found to have a floating point exception (FPE) vulnerability via resize_stream at src/xform.c.
local
low complexity
lcdf CWE-697
7.8
2023-10-12 CVE-2023-45133 Incorrect Comparison vulnerability in multiple products
Babel is a compiler for writingJavaScript.
local
low complexity
debian babeljs CWE-697
8.8
2023-10-09 CVE-2023-44378 Incorrect Comparison vulnerability in Consensys Gnark
gnark is a zk-SNARK library that offers a high-level API to design circuits.
local
low complexity
consensys CWE-697
5.5
2023-09-25 CVE-2015-6964 Incorrect Comparison vulnerability in Multibit HD
MultiBit HD before 0.1.2 allows attackers to conduct bit-flipping attacks that insert unspendable Bitcoin addresses into the list that MultiBit uses to send fees to the developers.
network
low complexity
multibit CWE-697
5.3