Vulnerabilities > Information Exposure Through Discrepancy

DATE CVE VULNERABILITY TITLE RISK
2021-12-23 CVE-2021-38009 Information Exposure Through Discrepancy vulnerability in multiple products
Inappropriate implementation in cache in Google Chrome prior to 96.0.4664.45 allowed a remote attacker to leak cross-origin data via a crafted HTML page.
network
low complexity
google fedoraproject debian CWE-203
6.5
2021-12-21 CVE-2021-44875 Information Exposure Through Discrepancy vulnerability in Dalmark Systeam Enterprise Resource Planning 2.22.8
Dalmark Systems Systeam 2.22.8 build 1724 is vulnerable to User enumeration.
network
low complexity
dalmark CWE-203
5.3
2021-12-21 CVE-2021-44876 Information Exposure Through Discrepancy vulnerability in Dalmark Systeam Enterprise Resource Planning 2.22.8
Dalmark Systems Systeam 2.22.8 build 1724 is vulnerable to User enumeration.
network
low complexity
dalmark CWE-203
5.3
2021-12-20 CVE-2021-44554 Information Exposure Through Discrepancy vulnerability in Cybelesoft Thinfinity Virtualui
Thinfinity VirtualUI before 3.0 allows a malicious actor to enumerate users registered in the OS (Windows) through the /changePassword URI.
network
low complexity
cybelesoft CWE-203
5.3
2021-12-15 CVE-2021-0987 Information Exposure Through Discrepancy vulnerability in Google Android 12.0
In getNeighboringCellInfo of PhoneInterfaceManager.java, there is a possible way to determine whether an app is installed, without query permissions, due to side channel information disclosure.
local
low complexity
google CWE-203
3.3
2021-12-15 CVE-2021-0988 Information Exposure Through Discrepancy vulnerability in Google Android 12.0
In getLaunchedFromUid and getLaunchedFromPackage of ActivityClientController.java, there is a possible way to determine whether an app is installed, without query permissions, due to side channel information disclosure.
local
low complexity
google CWE-203
3.3
2021-12-15 CVE-2021-0989 Information Exposure Through Discrepancy vulnerability in Google Android 12.0
In hasManageOngoingCallsPermission of TelecomServiceImpl.java, there is a possible way to determine whether an app is installed, without query permissions, due to side channel information disclosure.
local
low complexity
google CWE-203
3.3
2021-12-15 CVE-2021-0990 Information Exposure Through Discrepancy vulnerability in Google Android 12.0
In getDeviceId of PhoneSubInfoController.java, there is a possible way to determine whether an app is installed, without query permissions, due to side channel information disclosure.
local
low complexity
google CWE-203
3.3
2021-12-15 CVE-2021-0995 Information Exposure Through Discrepancy vulnerability in Google Android 12.0
In registerSuggestionConnectionStatusListener of WifiServiceImpl.java, there is a possible way to determine whether an app is installed, without query permissions, due to side channel information disclosure.
local
low complexity
google CWE-203
3.3
2021-12-15 CVE-2021-1005 Information Exposure Through Discrepancy vulnerability in Google Android 12.0
In getDeviceIdWithFeature of PhoneInterfaceManager.java, there is a possible way to determine whether an app is installed, without query permissions, due to side channel information disclosure.
local
low complexity
google CWE-203
5.5