Vulnerabilities > Information Exposure Through Discrepancy

DATE CVE VULNERABILITY TITLE RISK
2022-03-25 CVE-2022-24784 Information Exposure Through Discrepancy vulnerability in Statamic
Statamic is a Laravel and Git powered CMS.
network
high complexity
statamic CWE-203
3.7
2022-03-10 CVE-2021-44421 Information Exposure Through Discrepancy vulnerability in Occlum Project Occlum
The pointer-validation logic in util/mem_util.rs in Occlum before 0.26.0 for Intel SGX acts as a confused deputy that allows a local attacker to access unauthorized information via side-channel analysis.
local
low complexity
occlum-project CWE-203
2.1
2022-03-10 CVE-2020-36517 Information Exposure Through Discrepancy vulnerability in Home-Assistant 2022.03
An information leak in Nabu Casa Home Assistant Operating System and Home Assistant Supervised 2022.03 allows a DNS operator to gain knowledge about internal network resources via the hardcoded DNS resolver configuration.
network
low complexity
home-assistant CWE-203
5.0
2022-02-21 CVE-2022-0564 Information Exposure Through Discrepancy vulnerability in Qlik Sense
A vulnerability in Qlik Sense Enterprise on Windows could allow an remote attacker to enumerate domain user accounts.
network
low complexity
qlik CWE-203
5.3
2022-02-15 CVE-2022-23643 Information Exposure Through Discrepancy vulnerability in Sourcegraph
Sourcegraph is a code search and navigation engine.
network
low complexity
sourcegraph CWE-203
4.0
2022-02-14 CVE-2022-0569 Information Exposure Through Discrepancy vulnerability in Snipeitapp Snipe-It
Observable Discrepancy in Packagist snipe/snipe-it prior to v5.3.9.
network
low complexity
snipeitapp CWE-203
4.3
2022-02-11 CVE-2021-0524 Information Exposure Through Discrepancy vulnerability in Google Android 12.0
In isServiceDistractionOptimized of CarPackageManagerService.java, there is a possible disclosure of installed packages due to side channel information disclosure.
local
low complexity
google CWE-203
2.1
2022-02-10 CVE-2021-45901 Information Exposure Through Discrepancy vulnerability in Servicenow Jakarta
The password-reset form in ServiceNow Orlando provides different responses to invalid authentication attempts depending on whether the username exists.
network
low complexity
servicenow CWE-203
5.0
2022-02-02 CVE-2021-39021 Information Exposure Through Discrepancy vulnerability in IBM Guardium Data Encryption 5.0.0.2
IBM Guardium Data Encryption (GDE) 5.0.0.2 behaves differently or sends different responses under different circumstances in a way that is observable to an unauthorized actor, which could facilitate username enumeration.
network
low complexity
ibm CWE-203
5.0
2022-01-31 CVE-2022-21659 Information Exposure Through Discrepancy vulnerability in Flask-Appbuilder Project Flask-Appbuilder
Flask-AppBuilder is an application development framework, built on top of the Flask web framework.
network
low complexity
flask-appbuilder-project CWE-203
5.0