Vulnerabilities > Information Exposure Through Discrepancy

DATE CVE VULNERABILITY TITLE RISK
2021-08-02 CVE-2021-35477 Information Exposure Through Discrepancy vulnerability in multiple products
In the Linux kernel through 5.13.7, an unprivileged BPF program can obtain sensitive information from kernel memory via a Speculative Store Bypass side-channel attack because a certain preempting store operation does not necessarily occur before a store operation that has an attacker-controlled value.
local
low complexity
linux debian fedoraproject CWE-203
5.5
2021-07-30 CVE-2021-20113 Information Exposure Through Discrepancy vulnerability in Tecnick Tcexam
An exposure of sensitive information vulnerability exists in TCExam <= 14.8.1.
network
low complexity
tecnick CWE-203
5.3
2021-07-30 CVE-2021-37606 Information Exposure Through Discrepancy vulnerability in Meow Hash Project Meow Hash 0.5
Meow hash 0.5/calico does not sufficiently thwart key recovery by an attacker who can query whether there's a collision in the bottom bits of the hashes of two messages, as demonstrated by an attack against a long-running web service that allows the attacker to infer collisions by measuring timing differences.
network
low complexity
meow-hash-project CWE-203
5.3
2021-07-19 CVE-2020-36421 Information Exposure Through Discrepancy vulnerability in multiple products
An issue was discovered in Arm Mbed TLS before 2.23.0.
network
low complexity
arm debian CWE-203
5.3
2021-07-19 CVE-2020-36422 Information Exposure Through Discrepancy vulnerability in multiple products
An issue was discovered in Arm Mbed TLS before 2.23.0.
network
low complexity
arm debian CWE-203
5.3
2021-07-19 CVE-2020-36424 Information Exposure Through Discrepancy vulnerability in multiple products
An issue was discovered in Arm Mbed TLS before 2.24.0.
local
high complexity
arm debian CWE-203
4.7
2021-07-14 CVE-2021-24117 Information Exposure Through Discrepancy vulnerability in Apache Teaclave SGX SDK 1.1.3
In Apache Teaclave Rust SGX SDK 1.1.3, a side-channel vulnerability in base64 PEM file decoding allows system-level (administrator) attackers to obtain information about secret RSA keys via a controlled-channel and side-channel attack on software running in isolated environments that can be single stepped, especially Intel SGX.
network
low complexity
apache CWE-203
4.9
2021-07-14 CVE-2021-24116 Information Exposure Through Discrepancy vulnerability in Wolfssl
In wolfSSL through 4.6.0, a side-channel vulnerability in base64 PEM file decoding allows system-level (administrator) attackers to obtain information about secret RSA keys via a controlled-channel and side-channel attack on software running in isolated environments that can be single stepped, especially Intel SGX.
network
low complexity
wolfssl CWE-203
4.9
2021-07-14 CVE-2021-24119 Information Exposure Through Discrepancy vulnerability in multiple products
In Trusted Firmware Mbed TLS 2.24.0, a side-channel vulnerability in base64 PEM file decoding allows system-level (administrator) attackers to obtain information about secret RSA keys via a controlled-channel and side-channel attack on software running in isolated environments that can be single stepped, especially Intel SGX.
network
low complexity
arm fedoraproject debian CWE-203
4.9
2021-06-09 CVE-2021-0001 Information Exposure Through Discrepancy vulnerability in Intel products
Observable timing discrepancy in Intel(R) IPP before version 2020 update 1 may allow authorized user to potentially enable information disclosure via local access.
local
high complexity
intel CWE-203
4.7