Vulnerabilities > Information Exposure Through Discrepancy

DATE CVE VULNERABILITY TITLE RISK
2019-08-13 CVE-2019-13420 Information Exposure Through Discrepancy vulnerability in Search-Guard Search Guard
Search Guard versions before 21.0 had an timing side channel issue when using the internal user database.
4.3
2019-08-12 CVE-2019-14359 Information Exposure Through Discrepancy vulnerability in Real-Sec BC Vault Firmware
On BC Vault devices, a side channel for the row-based SSD1309 OLED display was found.
low complexity
real-sec CWE-203
2.4
2019-08-10 CVE-2019-14357 Information Exposure Through Discrepancy vulnerability in Mooltipass Mini Firmware
On Mooltipass Mini devices, a side channel for the row-based OLED display was found.
low complexity
mooltipass CWE-203
2.4
2019-08-10 CVE-2019-14355 Information Exposure Through Discrepancy vulnerability in Shapeshift Keepkey Firmware
On ShapeShift KeepKey devices, a side channel for the row-based OLED display was found.
low complexity
shapeshift CWE-203
2.4
2019-07-29 CVE-2019-1020002 Information Exposure Through Discrepancy vulnerability in Pterodactyl Panel
Pterodactyl before 0.7.14 with 2FA allows credential sniffing.
network
low complexity
pterodactyl CWE-203
5.0
2019-07-23 CVE-2019-2818 Information Exposure Through Discrepancy vulnerability in Oracle JDK and JRE
Vulnerability in the Java SE component of Oracle Java SE (subcomponent: Security).
network
high complexity
oracle CWE-203
2.6
2019-07-23 CVE-2019-9815 Information Exposure Through Discrepancy vulnerability in Mozilla Firefox
If hyperthreading is not disabled, a timing attack vulnerability exists, similar to previous Spectre attacks.
network
mozilla CWE-203
6.8
2019-07-16 CVE-2019-13383 Information Exposure Through Discrepancy vulnerability in Control-Webpanel Webpanel 0.9.8.836
In CentOS-WebPanel.com (aka CWP) CentOS Web Panel 0.9.8.846, the Login process allows attackers to check whether a username is valid by reading the HTTP response.
network
low complexity
control-webpanel CWE-203
5.3
2019-05-28 CVE-2019-12383 Information Exposure Through Discrepancy vulnerability in Torproject TOR Browser
Tor Browser before 8.0.1 has an information exposure vulnerability.
network
low complexity
torproject CWE-203
4.3
2019-05-24 CVE-2019-10848 Information Exposure Through Discrepancy vulnerability in Computrols Building Automation Software
Computrols CBAS 18.0.0 allows Username Enumeration.
network
low complexity
computrols CWE-203
5.0