Skip to main content

CWE archive

CWE-203 CVEs

Programmatic archive

748 CVEs tagged with CWE-20316 Critical, 107 High, 538 Medium, 87 Low, 0 Unrated.

CVE-2023-21319

Published Oct 30, 2023

In UsageStatsService, there is a possible way to read installed 3rd party apps due to side channel information disclosure. This could lead to local information disclosure with no…

CVSS 5.5 · Medium
Vendor/product tagsBeta · best-effort

CVE-2023-21318

Published Oct 30, 2023

In Content, there is a possible way to determine whether an app is installed, without query permissions, due to side channel information disclosure. This could lead to local infor…

CVSS 5.5 · Medium
Vendor/product tagsBeta · best-effort

CVE-2023-21317

Published Oct 30, 2023

In ContentService, there is a possible way to determine whether an app is installed, without query permissions, due to side channel information disclosure. This could lead to loca…

CVSS 5.5 · Medium
Vendor/product tagsBeta · best-effort

CVE-2023-21316

Published Oct 30, 2023

In Content, there is a possible way to determine whether an app is installed, without query permissions, due to side channel information disclosure. This could lead to local infor…

CVSS 5.5 · Medium
Vendor/product tagsBeta · best-effort

CVE-2023-21306

Published Oct 30, 2023

In ContentService, there is a possible way to read installed sync content providers due to side channel information disclosure. This could lead to local information disclosure wit…

CVSS 5.5 · Medium
Vendor/product tagsBeta · best-effort

CVE-2023-21305

Published Oct 30, 2023

In Content, there is a possible way to determine whether an app is installed, without query permissions, due to side channel information disclosure. This could lead to local infor…

CVSS 5.5 · Medium
Vendor/product tagsBeta · best-effort

CVE-2023-21304

Published Oct 30, 2023

In Content Service, there is a possible way to determine whether an app is installed, without query permissions, due to side channel information disclosure. This could lead to loc…

CVSS 5.5 · Medium
Vendor/product tagsBeta · best-effort

CVE-2023-21303

Published Oct 30, 2023

In Content, here is a possible way to determine whether an app is installed, without query permissions, due to side channel information disclosure. This could lead to local inform…

CVSS 5.5 · Medium
Vendor/product tagsBeta · best-effort

CVE-2023-21302

Published Oct 30, 2023

In Package Manager, there is a possible way to determine whether an app is installed, without query permissions, due to side channel information disclosure. This could lead to loc…

CVSS 5.5 · Medium
Vendor/product tagsBeta · best-effort

CVE-2023-21301

Published Oct 30, 2023

In ActivityManagerService, there is a possible way to determine whether an app is installed, without query permissions, due to side channel information disclosure. This could lead…

CVSS 5.5 · Medium
Vendor/product tagsBeta · best-effort

CVE-2023-21300

Published Oct 30, 2023

In PackageManager, there is a possible way to determine whether an app is installed, without query permissions, due to side channel information disclosure. This could lead to loca…

CVSS 5.5 · Medium
Vendor/product tagsBeta · best-effort

CVE-2023-21299

Published Oct 30, 2023

In Package Manager, there is a possible way to determine whether an app is installed, without query permissions, due to side channel information disclosure. This could lead to loc…

CVSS 5.5 · Medium
Vendor/product tagsBeta · best-effort

CVE-2023-21298

Published Oct 30, 2023

In Slice, there is a possible disclosure of installed applications due to side channel information disclosure. This could lead to local escalation of privilege with no additional…

CVSS 7.8 · High
Vendor/product tagsBeta · best-effort

CVE-2023-21296

Published Oct 30, 2023

In Permission, there is a possible way to determine whether an app is installed, without query permissions, due to side channel information disclosure. This could lead to local es…

CVSS 5.5 · Medium
Vendor/product tagsBeta · best-effort

CVE-2023-21293

Published Oct 30, 2023

In PackageManagerNative, there is a possible way to determine whether an app is installed, without query permissions, due to side channel information disclosure. This could lead t…

CVSS 5.5 · Medium
Vendor/product tagsBeta · best-effort

CVE-2022-20264

Published Oct 30, 2023

In Usage Stats Service, there is a possible way to determine whether an app is installed, without query permissions due to side channel information disclosure. This could lead to…

CVSS 5.5 · Medium
Vendor/product tagsBeta · best-effort

CVE-2023-5722

Published Oct 25, 2023

Using iterative requests an attacker was able to learn the size of an opaque response, as well as the contents of a server-supplied Vary header. This vulnerability affects Firefox…

CVSS 5.3 · Medium
Vendor/product tagsBeta · best-effort

CVE-2022-25332

Published Oct 19, 2023

The AES implementation in the Texas Instruments OMAP L138 (secure variants), present in mask ROM, suffers from a timing side channel which can be exploited by an adversary with no…

CVSS 4.4 · Medium
Vendor/product tagsBeta · best-effort

CVE-2023-36127

Published Oct 10, 2023

User enumeration is found in in PHPJabbers Appointment Scheduler 3.0. This issue occurs during password recovery, where a difference in messages could allow an attacker to determi…

CVSS 7.5 · High
Vendor/product tagsBeta · best-effort

CVE-2023-43623

Published Oct 10, 2023

A vulnerability has been identified in Mendix Forgot Password (Mendix 10 compatible) (All versions < V5.4.0), Mendix Forgot Password (Mendix 7 compatible) (All versions < V3.7.3),…

CVSS 5.3 · Medium
Vendor/product tagsBeta · best-effort

CVE-2023-38871

Published Sep 28, 2023

The commit 3730880 (April 2023) and v.0.9-beta1 of gugoan Economizzer has a user enumeration vulnerability in the login and forgot password functionalities. The app reacts differe…

CVSS 5.3 · Medium
Vendor/product tagsBeta · best-effort

CVE-2023-44216

Published Sep 27, 2023

PVRIC (PowerVR Image Compression) on Imagination 2018 and later GPU devices offers software-transparent compression that enables cross-origin pixel-stealing attacks against feTurb…

CVSS 5.3 · Medium

CVE-2023-4095

Published Sep 19, 2023

User enumeration vulnerability in Arconte Áurea 1.5.0.0 version. The exploitation of this vulnerability could allow an attacker to obtain a list of registered users in the applica…

CVSS 5.3 · Medium
Vendor/product tagsBeta · best-effort

CVE-2023-41885

Published Sep 12, 2023

Piccolo is an ORM and query builder which supports asyncio. In versions 0.120.0 and prior, the implementation of `BaseUser.login` leaks enough information to a malicious user such…

CVSS 5.3 · Medium
Vendor/product tagsBeta · best-effort
Showing 276-300 of 748 CVEsPage 12 of 30