Vulnerabilities > Information Exposure Through Discrepancy

DATE CVE VULNERABILITY TITLE RISK
2019-11-02 CVE-2019-14358 Information Exposure Through Discrepancy vulnerability in Archos Safe-T
On Archos Safe-T devices, a side channel for the row-based OLED display was found.
low complexity
archos CWE-203
4.6
2019-10-31 CVE-2019-14356 Information Exposure Through Discrepancy vulnerability in Coinkite Coldcard MK1 Firmware and Coldcard MK2 Firmware
On Coldcard MK1 and MK2 devices, a side channel for the row-based OLED display was found.
network
low complexity
coinkite CWE-203
5.3
2019-10-03 CVE-2019-15809 Information Exposure Through Discrepancy vulnerability in multiple products
Smart cards from the Athena SCS manufacturer, based on the Atmel Toolbox 00.03.11.05 and the AT90SC chip, contain a timing side channel in ECDSA signature generation.
4.7
2019-10-03 CVE-2019-13629 Information Exposure Through Discrepancy vulnerability in Matrixssl
MatrixSSL 4.2.1 and earlier contains a timing side channel in ECDSA signature generation.
network
high complexity
matrixssl CWE-203
5.9
2019-10-03 CVE-2019-13628 Information Exposure Through Discrepancy vulnerability in Wolfssl
wolfSSL and wolfCrypt 4.0.0 and earlier (when configured without --enable-fpecc, --enable-sp, or --enable-sp-math) contain a timing side channel in ECDSA signature generation.
local
high complexity
wolfssl CWE-203
4.7
2019-09-30 CVE-2019-3732 Information Exposure Through Discrepancy vulnerability in multiple products
RSA BSAFE Crypto-C Micro Edition, versions prior to 4.0.5.3 (in 4.0.x) and versions prior to 4.1.3.3 (in 4.1.x), and RSA Micro Edition Suite, versions prior to 4.0.11 (in 4.0.x) versions prior to 4.1.6.1 (in 4.1.x) and versions prior to 4.3.3 (4.2.x and 4.3.x) are vulnerable to an Information Exposure Through Timing Discrepancy.
network
low complexity
emc dell CWE-203
7.5
2019-09-30 CVE-2019-3731 Information Exposure Through Discrepancy vulnerability in Dell products
RSA BSAFE Crypto-C Micro Edition versions prior to 4.1.4 and RSA Micro Edition Suite versions prior to 4.4 are vulnerable to an Information Exposure Through Timing Discrepancy.
network
low complexity
dell CWE-203
7.5
2019-09-27 CVE-2019-11743 Information Exposure Through Discrepancy vulnerability in Mozilla Firefox
Navigation events were not fully adhering to the W3C's "Navigation-Timing Level 2" draft specification in some instances for the unload event, which restricts access to detailed timing attributes to only be same-origin.
network
high complexity
mozilla CWE-203
3.7
2019-09-25 CVE-2019-6651 Information Exposure Through Discrepancy vulnerability in F5 products
In BIG-IP 15.0.0, 14.1.0-14.1.0.6, 14.0.0-14.0.0.5, 13.0.0-13.1.1.5, 12.1.0-12.1.4.1, 11.5.1-11.6.4, BIG-IQ 7.0.0, 6.0.0-6.1.0,5.2.0-5.4.0, iWorkflow 2.3.0, and Enterprise Manager 3.1.1, the Configuration utility login page may not follow best security practices when handling a malicious request.
network
low complexity
f5 CWE-203
5.3
2019-09-25 CVE-2019-13627 Information Exposure Through Discrepancy vulnerability in multiple products
It was discovered that there was a ECDSA timing attack in the libgcrypt20 cryptographic library.
6.3