Vulnerabilities > Information Exposure Through Discrepancy

DATE CVE VULNERABILITY TITLE RISK
2022-05-12 CVE-2021-33149 Information Exposure Through Discrepancy vulnerability in Intel products
Observable behavioral discrepancy in some Intel(R) Processors may allow an authorized user to potentially enable information disclosure via local access.
local
low complexity
intel CWE-203
5.5
2022-05-11 CVE-2021-46744 Information Exposure Through Discrepancy vulnerability in AMD products
An attacker with access to a malicious hypervisor may be able to infer data values used in a SEV guest on AMD CPUs by monitoring ciphertext values over time.
local
low complexity
amd CWE-203
6.5
2022-05-06 CVE-2021-33845 Information Exposure Through Discrepancy vulnerability in Splunk
The Splunk Enterprise REST API allows enumeration of usernames via the lockout error message.
network
low complexity
splunk CWE-203
5.3
2022-04-20 CVE-2022-1318 Information Exposure Through Discrepancy vulnerability in Carrier Hills Comnav Firmware 300219
Hills ComNav version 3002-19 suffers from a weak communication channel.
local
low complexity
carrier CWE-203
5.5
2022-04-14 CVE-2022-27814 Information Exposure Through Discrepancy vulnerability in Waycrate Swhkd 1.1.5
SWHKD 1.1.5 allows arbitrary file-existence tests via the -c option.
local
low complexity
waycrate CWE-203
3.3
2022-04-05 CVE-2022-22356 Information Exposure Through Discrepancy vulnerability in IBM MQ Appliance 9.2.0.0
IBM MQ Appliance 9.2 CD and 9.2 LTS could allow an attacker to enumerate account credentials due to an observable discrepancy in valid and invalid login attempts.
network
low complexity
ibm CWE-203
6.5
2022-03-30 CVE-2021-39744 Information Exposure Through Discrepancy vulnerability in Google Android 12.1
In DevicePolicyManager, there is a possible way to determine whether an app is installed, without query permissions, due to side channel information disclosure.
local
low complexity
google CWE-203
5.5
2022-03-30 CVE-2021-39745 Information Exposure Through Discrepancy vulnerability in Google Android 12.1
In DevicePolicyManager, there is a possible way to determine whether an app is installed, without query permissions, due to side channel information disclosure.
local
low complexity
google CWE-203
5.5
2022-03-30 CVE-2021-39754 Information Exposure Through Discrepancy vulnerability in Google Android 12.1
In ContextImpl, there is a possible way to determine whether an app is installed, without query permissions, due to side channel information disclosure.
local
low complexity
google CWE-203
5.5
2022-03-30 CVE-2021-39755 Information Exposure Through Discrepancy vulnerability in Google Android 12.1
In DevicePolicyManager, there is a possible way to reveal the existence of an installed package without proper query permissions due to side channel information disclosure.
local
low complexity
google CWE-203
5.5