Vulnerabilities > Information Exposure Through Discrepancy

DATE CVE VULNERABILITY TITLE RISK
2021-06-04 CVE-2021-33838 Information Exposure Through Discrepancy vulnerability in Luca-App Luca
Luca through 1.7.4 on Android allows remote attackers to obtain sensitive information about COVID-19 tracking because requests related to Check-In State occur shortly after requests for Phone Number Registration.
network
low complexity
luca-app CWE-203
7.5
2021-05-27 CVE-2021-22892 Information Exposure Through Discrepancy vulnerability in Rocket.Chat
An information disclosure vulnerability exists in the Rocket.Chat server fixed v3.13, v3.12.2 & v3.11.3 that allowed email addresses to be disclosed by enumeration and validation checks.
network
low complexity
rocket-chat CWE-203
5.0
2021-05-21 CVE-2020-27211 Information Exposure Through Discrepancy vulnerability in Nordicsemi Nrf52840 Firmware 20201019
Nordic Semiconductor nRF52840 devices through 2020-10-19 have improper protection against physical side channels.
3.3
2021-05-21 CVE-2021-29415 Information Exposure Through Discrepancy vulnerability in Nordicsemi Nrf52840 Firmware 20201019/20210329
The elliptic curve cryptography (ECC) hardware accelerator, part of the ARM® TrustZone® CryptoCell 310, contained in the NordicSemiconductor nRF52840 through 2021-03-29 has a non-constant time ECDSA implemenation.
local
low complexity
nordicsemi CWE-203
2.1
2021-05-20 CVE-2021-29687 Information Exposure Through Discrepancy vulnerability in IBM Security Identity Manager 6.0.2
IBM Security Identity Manager 7.0.2 could allow a remote user to enumerate usernames due to a difference of responses from valid and invalid login attempts.
network
low complexity
ibm CWE-203
5.0
2021-05-17 CVE-2021-27342 Information Exposure Through Discrepancy vulnerability in Dlink Dir-842E Firmware
An authentication brute-force protection mechanism bypass in telnetd in D-Link Router model DIR-842 firmware version 3.0.2 allows a remote attacker to circumvent the anti-brute-force cool-down delay period via a timing-based side-channel attack
network
dlink CWE-203
4.3
2021-05-06 CVE-2021-1486 Information Exposure Through Discrepancy vulnerability in Cisco Catalyst Sd-Wan Manager and Sd-Wan Vmanage
A vulnerability in Cisco SD-WAN vManage Software could allow an unauthenticated, remote attacker to enumerate user accounts.
network
low complexity
cisco CWE-203
5.3
2021-04-28 CVE-2021-31866 Information Exposure Through Discrepancy vulnerability in multiple products
Redmine before 4.0.9 and 4.1.x before 4.1.3 allows an attacker to learn the values of internal authentication keys by observing timing differences in string comparison operations within SysController and MailHandlerController.
network
low complexity
redmine debian CWE-203
5.0
2021-04-23 CVE-2021-31403 Information Exposure Through Discrepancy vulnerability in Vaadin
Non-constant-time comparison of CSRF tokens in UIDL request handler in com.vaadin:vaadin-server versions 7.0.0 through 7.7.23 (Vaadin 7.0.0 through 7.7.23), and 8.0.0 through 8.12.2 (Vaadin 8.0.0 through 8.12.2) allows attacker to guess a security token via timing attack
local
vaadin CWE-203
1.9
2021-04-23 CVE-2021-31404 Information Exposure Through Discrepancy vulnerability in Vaadin Flow and Vaadin
Non-constant-time comparison of CSRF tokens in UIDL request handler in com.vaadin:flow-server versions 1.0.0 through 1.0.13 (Vaadin 10.0.0 through 10.0.16), 1.1.0 prior to 2.0.0 (Vaadin 11 prior to 14), 2.0.0 through 2.4.6 (Vaadin 14.0.0 through 14.4.6), 3.0.0 prior to 5.0.0 (Vaadin 15 prior to 18), and 5.0.0 through 5.0.2 (Vaadin 18.0.0 through 18.0.5) allows attacker to guess a security token via timing attack.
local
vaadin CWE-203
1.9