Vulnerabilities > Information Exposure Through Discrepancy

DATE CVE VULNERABILITY TITLE RISK
2022-03-10 CVE-2020-36517 Information Exposure Through Discrepancy vulnerability in Home-Assistant 2022.03
An information leak in Nabu Casa Home Assistant Operating System and Home Assistant Supervised 2022.03 allows a DNS operator to gain knowledge about internal network resources via the hardcoded DNS resolver configuration.
network
low complexity
home-assistant CWE-203
7.5
2022-02-21 CVE-2022-0564 Information Exposure Through Discrepancy vulnerability in Qlik Sense
A vulnerability in Qlik Sense Enterprise on Windows could allow an remote attacker to enumerate domain user accounts.
network
low complexity
qlik CWE-203
5.3
2022-02-15 CVE-2022-23643 Information Exposure Through Discrepancy vulnerability in Sourcegraph
Sourcegraph is a code search and navigation engine.
network
low complexity
sourcegraph CWE-203
6.5
2022-02-14 CVE-2022-0569 Information Exposure Through Discrepancy vulnerability in Snipeitapp Snipe-It
Observable Discrepancy in Packagist snipe/snipe-it prior to v5.3.9.
network
low complexity
snipeitapp CWE-203
4.3
2022-02-11 CVE-2021-0524 Information Exposure Through Discrepancy vulnerability in Google Android 12.0
In isServiceDistractionOptimized of CarPackageManagerService.java, there is a possible disclosure of installed packages due to side channel information disclosure.
local
low complexity
google CWE-203
5.5
2022-02-10 CVE-2021-45901 Information Exposure Through Discrepancy vulnerability in Servicenow Jakarta
The password-reset form in ServiceNow Orlando provides different responses to invalid authentication attempts depending on whether the username exists.
network
low complexity
servicenow CWE-203
5.3
2022-02-02 CVE-2021-39021 Information Exposure Through Discrepancy vulnerability in IBM Guardium Data Encryption 5.0.0.2
IBM Guardium Data Encryption (GDE) 5.0.0.2 behaves differently or sends different responses under different circumstances in a way that is observable to an unauthorized actor, which could facilitate username enumeration.
network
low complexity
ibm CWE-203
5.3
2022-01-31 CVE-2022-21659 Information Exposure Through Discrepancy vulnerability in Flask-Appbuilder Project Flask-Appbuilder
Flask-AppBuilder is an application development framework, built on top of the Flask web framework.
network
low complexity
flask-appbuilder-project CWE-203
5.3
2022-01-30 CVE-2022-24032 Information Exposure Through Discrepancy vulnerability in Adenza Axiomsl Controllerview
Adenza AxiomSL ControllerView through 10.8.1 is vulnerable to user enumeration.
network
low complexity
adenza CWE-203
5.3
2022-01-26 CVE-2019-25056 Information Exposure Through Discrepancy vulnerability in Bromite
In Bromite through 78.0.3904.130, there are adblock rules in the release APK; therefore, probing which resources are blocked and which aren't can identify the application version and defeat the User-Agent protection mechanism.
network
low complexity
bromite CWE-203
5.3