Vulnerabilities > Incorrect Comparison

DATE CVE VULNERABILITY TITLE RISK
2023-09-22 CVE-2023-23766 Incorrect Comparison vulnerability in Github Enterprise Server
An incorrect comparison vulnerability was identified in GitHub Enterprise Server that allowed commit smuggling by displaying an incorrect diff in a re-opened Pull Request.
network
low complexity
github CWE-697
6.5
2023-09-13 CVE-2023-23840 Incorrect Comparison vulnerability in Solarwinds Orion Platform
The SolarWinds Platform was susceptible to the Incorrect Comparison Vulnerability.
network
low complexity
solarwinds CWE-697
7.2
2023-09-13 CVE-2023-23845 Incorrect Comparison vulnerability in Solarwinds Orion Platform
The SolarWinds Platform was susceptible to the Incorrect Comparison Vulnerability.
network
low complexity
solarwinds CWE-697
7.2
2023-09-08 CVE-2023-40271 Incorrect Comparison vulnerability in ARM Trusted Firmware-M
In Trusted Firmware-M through TF-Mv1.8.0, for platforms that integrate the CryptoCell accelerator, when the CryptoCell PSA Driver software Interface is selected, and the Authenticated Encryption with Associated Data Chacha20-Poly1305 algorithm is used, with the single-part verification function (defined during the build-time configuration phase) implemented with a dedicated function (i.e., not relying on usage of multipart functions), the buffer comparison during the verification of the authentication tag does not happen on the full 16 bytes but just on the first 4 bytes, thus leading to the possibility that unauthenticated payloads might be identified as authentic.
network
low complexity
arm CWE-697
7.5
2023-09-06 CVE-2023-41935 Incorrect Comparison vulnerability in Jenkins Azure AD
Jenkins Azure AD Plugin 396.v86ce29279947 and earlier, except 378.380.v545b_1154b_3fb_, uses a non-constant time comparison function when checking whether the provided and expected CSRF protection nonce are equal, potentially allowing attackers to use statistical methods to obtain a valid nonce.
network
low complexity
jenkins CWE-697
7.5
2023-09-06 CVE-2023-41936 Incorrect Comparison vulnerability in Jenkins Google Login
Jenkins Google Login Plugin 1.7 and earlier uses a non-constant time comparison function when checking whether the provided and expected token are equal, potentially allowing attackers to use statistical methods to obtain a valid token.
network
low complexity
jenkins CWE-697
7.5
2023-08-30 CVE-2023-23765 Incorrect Comparison vulnerability in Github Enterprise Server
An incorrect comparison vulnerability was identified in GitHub Enterprise Server that allowed commit smuggling by displaying an incorrect diff in a re-opened Pull Request.
network
low complexity
github CWE-697
6.5
2023-08-18 CVE-2023-40037 Incorrect Comparison vulnerability in Apache Nifi 1.21.0/1.22.0
Apache NiFi 1.21.0 through 1.23.0 support JDBC and JNDI JMS access in several Processors and Controller Services with connection URL validation that does not provide sufficient protection against crafted inputs.
network
low complexity
apache CWE-697
6.5
2023-07-27 CVE-2023-23764 Incorrect Comparison vulnerability in Github Enterprise Server
An incorrect comparison vulnerability was identified in GitHub Enterprise Server that allowed commit smuggling by displaying an incorrect diff within the GitHub pull request UI.
network
low complexity
github CWE-697
7.1
2023-07-26 CVE-2023-23843 Incorrect Comparison vulnerability in Solarwinds Platform
The SolarWinds Platform was susceptible to the Incorrect Comparison Vulnerability.
network
low complexity
solarwinds CWE-697
7.2