Vulnerabilities > Information Exposure Through Discrepancy

DATE CVE VULNERABILITY TITLE RISK
2022-09-08 CVE-2022-37146 Information Exposure Through Discrepancy vulnerability in Plextrac
The PlexTrac platform prior to version 1.28.0 allows for username enumeration via HTTP response times on invalid login attempts for users configured to use the PlexTrac authentication provider.
network
low complexity
plextrac CWE-203
5.3
2022-08-23 CVE-2022-1989 Information Exposure Through Discrepancy vulnerability in Codesys Visualization 4.0.0.0
All CODESYS Visualization versions before V4.2.0.0 generate a login dialog vulnerable to information exposure allowing a remote, unauthenticated attacker to enumerate valid users.
network
low complexity
codesys CWE-203
5.3
2022-08-17 CVE-2022-37459 Information Exposure Through Discrepancy vulnerability in Amperecomputing Ampere Altra Firmware and Ampere Altra MAX Firmware
Ampere Altra devices before 1.08g and Ampere Altra Max devices before 2.05a allow attackers to control the predictions for return addresses and potentially hijack code flow to execute arbitrary code via a side-channel attack, aka a "Retbleed" issue.
local
low complexity
amperecomputing CWE-203
7.8
2022-08-12 CVE-2022-2612 Information Exposure Through Discrepancy vulnerability in multiple products
Side-channel information leakage in Keyboard input in Google Chrome prior to 104.0.5112.79 allowed a remote attacker who had compromised the renderer process to obtain potentially sensitive information from process memory via a crafted HTML page.
network
low complexity
google fedoraproject CWE-203
6.5
2022-08-12 CVE-2022-20275 Information Exposure Through Discrepancy vulnerability in Google Android 13.0
In DevicePolicyManager, there is a possible way to determine whether an app is installed, without query permissions, due to side channel information disclosure.
local
low complexity
google CWE-203
5.5
2022-08-12 CVE-2022-20276 Information Exposure Through Discrepancy vulnerability in Google Android 13.0
In DevicePolicyManager, there is a possible way to determine whether an app is installed, without query permissions, due to side channel information disclosure.
local
low complexity
google CWE-203
5.5
2022-08-12 CVE-2022-20277 Information Exposure Through Discrepancy vulnerability in Google Android 13.0
In DevicePolicyManager, there is a possible way to determine whether an app is installed, without query permissions, due to side channel information disclosure.
local
low complexity
google CWE-203
5.5
2022-08-12 CVE-2022-20279 Information Exposure Through Discrepancy vulnerability in Google Android 13.0
In DevicePolicyManager, there is a possible way to determine whether an app is installed, without query permissions, due to side channel information disclosure.
local
low complexity
google CWE-203
5.5
2022-08-12 CVE-2022-20291 Information Exposure Through Discrepancy vulnerability in Google Android 13.0
In AppOpsService, there is a possible way to determine whether an app is installed, without query permissions, due to side channel information disclosure.
local
low complexity
google CWE-203
5.5
2022-08-12 CVE-2022-20293 Information Exposure Through Discrepancy vulnerability in Google Android 13.0
In LauncherApps, there is a possible way to determine whether an app is installed, without query permissions, due to side channel information disclosure.
local
low complexity
google CWE-203
5.5