Vulnerabilities > Information Exposure Through Discrepancy

DATE CVE VULNERABILITY TITLE RISK
2021-04-16 CVE-2021-29444 Information Exposure Through Discrepancy vulnerability in Jose-Node-Cjs-Runtime Project Jose-Node-Cjs-Runtime
jose-browser-runtime is an npm package which provides a number of cryptographic functions.
network
high complexity
jose-node-cjs-runtime-project CWE-203
5.9
2021-04-16 CVE-2021-29443 Information Exposure Through Discrepancy vulnerability in Jose Project Jose
jose is an npm library providing a number of cryptographic operations.
network
high complexity
jose-project CWE-203
5.9
2021-03-26 CVE-2020-35518 Information Exposure Through Discrepancy vulnerability in Redhat 389 Directory Server
When binding against a DN during authentication, the reply from 389-ds-base will be different whether the DN exists or not.
network
low complexity
redhat CWE-203
5.3
2021-03-20 CVE-2020-27170 Information Exposure Through Discrepancy vulnerability in multiple products
An issue was discovered in the Linux kernel before 5.11.8.
local
high complexity
linux fedoraproject canonical debian CWE-203
4.7
2021-03-16 CVE-2020-1926 Information Exposure Through Discrepancy vulnerability in Apache Hive
Apache Hive cookie signature verification used a non constant time comparison which is known to be vulnerable to timing attacks.
network
high complexity
apache CWE-203
5.9
2021-03-09 CVE-2021-21181 Information Exposure Through Discrepancy vulnerability in multiple products
Side-channel information leakage in autofill in Google Chrome prior to 89.0.4389.72 allowed a remote attacker to obtain potentially sensitive information from process memory via a crafted HTML page.
network
low complexity
google fedoraproject debian CWE-203
6.5
2021-03-09 CVE-2021-21173 Information Exposure Through Discrepancy vulnerability in multiple products
Side-channel information leakage in Network Internals in Google Chrome prior to 89.0.4389.72 allowed a remote attacker to leak cross-origin data via a crafted HTML page.
network
low complexity
google fedoraproject debian CWE-203
6.5
2021-02-23 CVE-2021-27583 Information Exposure Through Discrepancy vulnerability in Rangerstudio Directus
In Directus 8.x through 8.8.1, an attacker can discover whether a user is present in the database through the password reset feature.
network
low complexity
rangerstudio CWE-203
5.3
2021-02-22 CVE-2020-11287 Information Exposure Through Discrepancy vulnerability in Qualcomm products
Allowing RTT frames to be linked with non randomized MAC address by comparing the sequence numbers can lead to information disclosure.
network
low complexity
qualcomm CWE-203
7.5
2021-02-03 CVE-2020-9389 Information Exposure Through Discrepancy vulnerability in Squaredup 4.6
A username enumeration issue was discovered in SquaredUp before version 4.6.0.
network
high complexity
squaredup CWE-203
3.7