Vulnerabilities > Information Exposure Through Discrepancy

DATE CVE VULNERABILITY TITLE RISK
2024-06-10 CVE-2024-37880 Information Exposure Through Discrepancy vulnerability in Pq-Crystals Kyber
The Kyber reference implementation before 9b8d306, when compiled by LLVM Clang through 18.x with some common optimization options, has a timing side channel that allows attackers to recover an ML-KEM 512 secret key in minutes.
network
low complexity
pq-crystals CWE-203
7.5
2024-06-09 CVE-2024-2408 Information Exposure Through Discrepancy vulnerability in multiple products
The openssl_private_decrypt function in PHP, when using PKCS1 padding (OPENSSL_PKCS1_PADDING, which is the default), is vulnerable to the Marvin Attack unless it is used with an OpenSSL version that includes the changes from this pull request: https://github.com/openssl/openssl/pull/13817 (rsa_pkcs1_implicit_rejection).
network
high complexity
php fedoraproject CWE-203
5.9
2024-06-06 CVE-2024-5124 Information Exposure Through Discrepancy vulnerability in Gaizhenbiao Chuanhuchatgpt
A timing attack vulnerability exists in the gaizhenbiao/chuanhuchatgpt repository, specifically within the password comparison logic.
network
low complexity
gaizhenbiao CWE-203
7.5
2024-05-04 CVE-2023-27283 Information Exposure Through Discrepancy vulnerability in IBM Aspera Orchestrator 4.0.1
IBM Aspera Orchestrator 4.0.1 could allow a remote attacker to enumerate usernames due to observable response discrepancies.
network
low complexity
ibm CWE-203
5.3
2024-05-03 CVE-2021-20556 Information Exposure Through Discrepancy vulnerability in IBM Cognos Controller 10.4.1/10.4.2/11.0.0
IBM Cognos Controller 10.4.1, 10.4.2, and 11.0.0 could allow a remote user to enumerate usernames due to differentiating error messages on existing usernames.
network
low complexity
ibm CWE-203
5.3
2024-04-09 CVE-2024-26221 Information Exposure Through Discrepancy vulnerability in Microsoft products
Windows DNS Server Remote Code Execution Vulnerability
network
high complexity
microsoft CWE-203
6.6
2024-03-04 CVE-2023-38362 Information Exposure Through Discrepancy vulnerability in IBM Cics TX 10.1
IBM CICS TX Advanced 10.1 could disclose sensitive information to a remote attacker due to observable discrepancy in HTTP responses.
network
low complexity
ibm CWE-203
5.3
2024-02-21 CVE-2022-45177 Information Exposure Through Discrepancy vulnerability in Liveboxcloud Vdesk 018/031
An issue was discovered in LIVEBOX Collaboration vDesk through v031.
network
low complexity
liveboxcloud CWE-203
7.5
2024-02-11 CVE-2024-25714 Information Exposure Through Discrepancy vulnerability in multiple products
In Rhonabwy through 1.1.13, HMAC signature verification uses a strcmp function that is vulnerable to side-channel attacks, because it stops the comparison when the first difference is spotted in the two signatures.
network
low complexity
rhonabwy-project debian CWE-203
critical
9.8
2024-02-09 CVE-2023-6935 Information Exposure Through Discrepancy vulnerability in Wolfssl
wolfSSL SP Math All RSA implementation is vulnerable to the Marvin Attack, new variation of a timing Bleichenbacher style attack, when built with the following options to configure: --enable-all CFLAGS="-DWOLFSSL_STATIC_RSA" The define “WOLFSSL_STATIC_RSA” enables static RSA cipher suites, which is not recommended, and has been disabled by default since wolfSSL 3.6.6.  Therefore the default build since 3.6.6, even with "--enable-all", is not vulnerable to the Marvin Attack.
network
high complexity
wolfssl CWE-203
5.9