Vulnerabilities > Information Exposure Through Discrepancy

DATE CVE VULNERABILITY TITLE RISK
2023-12-04 CVE-2023-40090 Information Exposure Through Discrepancy vulnerability in Google Android
In BTM_BleVerifySignature of btm_ble.cc, there is a possible way to bypass signature validation due to side channel information disclosure.
network
low complexity
google CWE-203
6.5
2023-11-28 CVE-2023-49092 Information Exposure Through Discrepancy vulnerability in Rustcrypto RSA
RustCrypto/RSA is a portable RSA implementation in pure Rust.
network
high complexity
rustcrypto CWE-203
5.9
2023-11-28 CVE-2023-5981 Information Exposure Through Discrepancy vulnerability in multiple products
A vulnerability was found that the response times to malformed ciphertexts in RSA-PSK ClientKeyExchange differ from response times of ciphertexts with correct PKCS#1 v1.5 padding.
network
high complexity
gnu redhat fedoraproject CWE-203
5.9
2023-11-07 CVE-2023-47102 Information Exposure Through Discrepancy vulnerability in Urbackup Server 2.5.31
UrBackup Server 2.5.31 allows brute-force enumeration of user accounts because a failure message confirms that a username is not valid.
network
low complexity
urbackup CWE-203
5.3
2023-10-30 CVE-2022-20264 Information Exposure Through Discrepancy vulnerability in Google Android
In Usage Stats Service, there is a possible way to determine whether an app is installed, without query permissions due to side channel information disclosure.
local
low complexity
google CWE-203
5.5
2023-10-30 CVE-2023-21293 Information Exposure Through Discrepancy vulnerability in Google Android
In PackageManagerNative, there is a possible way to determine whether an app is installed, without query permissions, due to side channel information disclosure.
local
low complexity
google CWE-203
5.5
2023-10-30 CVE-2023-21296 Information Exposure Through Discrepancy vulnerability in Google Android
In Permission, there is a possible way to determine whether an app is installed, without query permissions, due to side channel information disclosure.
local
low complexity
google CWE-203
5.5
2023-10-30 CVE-2023-21298 Information Exposure Through Discrepancy vulnerability in Google Android
In Slice, there is a possible disclosure of installed applications due to side channel information disclosure.
local
low complexity
google CWE-203
7.8
2023-10-30 CVE-2023-21299 Information Exposure Through Discrepancy vulnerability in Google Android
In Package Manager, there is a possible way to determine whether an app is installed, without query permissions, due to side channel information disclosure.
local
low complexity
google CWE-203
5.5
2023-10-30 CVE-2023-21300 Information Exposure Through Discrepancy vulnerability in Google Android
In PackageManager, there is a possible way to determine whether an app is installed, without query permissions, due to side channel information disclosure.
local
low complexity
google CWE-203
5.5