Skip to main content

CWE archive

CWE-203 CVEs

Programmatic archive

748 CVEs tagged with CWE-20316 Critical, 107 High, 538 Medium, 87 Low, 0 Unrated.

CVE-2022-20251

Published Aug 11, 2022

In LocaleManager, there is a possible way to determine whether an app is installed, without query permissions, due to side channel information disclosure. This could lead to local…

CVSS 3.3 · Low
Vendor/product tagsBeta · best-effort

CVE-2022-20249

Published Aug 11, 2022

In LocaleManager, there is a possible way to determine whether an app is installed, without query permissions, due to side channel information disclosure. This could lead to local…

CVSS 3.3 · Low
Vendor/product tagsBeta · best-effort

CVE-2022-20242

Published Aug 11, 2022

In Telephony, there is a possible way to determine whether an app is installed, without query permissions, due to side channel information disclosure. This could lead to local inf…

CVSS 5.5 · Medium
Vendor/product tagsBeta · best-effort

CVE-2021-0975

Published Aug 11, 2022

In USB Manager, there is a possible way to determine whether an app is installed, without query permissions, due to side channel information disclosure. This could lead to local i…

CVSS 5.5 · Medium
Vendor/product tagsBeta · best-effort

CVE-2022-24912

Published Jul 29, 2022

The package github.com/runatlantis/atlantis/server/controllers/events before 0.19.7 are vulnerable to Timing Attack in the webhook event validator code, which does not use a const…

CVSS 7.5 · High
Vendor/product tagsBeta · best-effort

CVE-2022-36885

Published Jul 27, 2022

Jenkins GitHub Plugin 1.34.4 and earlier uses a non-constant time comparison function when checking whether the provided and computed webhook signatures are equal, allowing attack…

CVSS 5.3 · Medium
Vendor/product tagsBeta · best-effort

CVE-2022-1146

Published Jul 23, 2022

Inappropriate implementation in Resource Timing in Google Chrome prior to 100.0.4896.60 allowed a remote attacker to leak cross-origin data via a crafted HTML page.

CVSS 6.5 · Medium
Vendor/product tagsBeta · best-effort

CVE-2022-1139

Published Jul 23, 2022

Inappropriate implementation in Background Fetch API in Google Chrome prior to 100.0.4896.60 allowed a remote attacker to leak cross-origin data via a crafted HTML page.

CVSS 6.5 · Medium
Vendor/product tagsBeta · best-effort

CVE-2022-32425

Published Jul 14, 2022

The login function of Mealie v1.0.0beta-2 allows attackers to enumerate existing usernames by timing the server's response time.

CVSS 5.3 · Medium
Vendor/product tagsBeta · best-effort

CVE-2022-31142

Published Jul 14, 2022

@fastify/bearer-auth is a Fastify plugin to require bearer Authorization headers. @fastify/bearer-auth prior to versions 7.0.2 and 8.0.1 does not securely use crypto.timingSafeEqu…

CVSS 7.5 · High
Vendor/product tagsBeta · best-effort

CVE-2021-41634

Published Jun 24, 2022

A user enumeration vulnerability in MELAG FTP Server 2.2.0.4 allows an attacker to identify valid FTP usernames.

CVSS 5.3 · Medium
Vendor/product tagsBeta · best-effort

CVE-2022-34174

Published Jun 23, 2022

In Jenkins 2.355 and earlier, LTS 2.332.3 and earlier, an observable timing discrepancy on the login form allows distinguishing between login attempts with an invalid username, an…

CVSS 7.5 · High
Vendor/product tagsBeta · best-effort

CVE-2022-24436

Published Jun 15, 2022

Observable behavioral in power management throttling for some Intel(R) Processors may allow an authenticated user to potentially enable information disclosure via network access.

CVSS 6.5 · Medium
evidence mentions
3
Buzz score
21.9

CVE-2022-27221

Published Jun 14, 2022

A vulnerability has been identified in SINEMA Remote Connect Server (All versions < V3.1). An attacker in machine-in-the-middle could obtain plaintext secret values by observing l…

CVSS 5.9 · Medium
Vendor/product tagsBeta · best-effort

CVE-2022-32273

Published Jun 8, 2022

As a result of an observable discrepancy in returned messages, OPSWAT MetaDefender Core (MDCore) before 5.1.2 could allow an authenticated user to enumerate filenames on the serve…

CVSS 4.3 · Medium
Vendor/product tagsBeta · best-effort

CVE-2022-29185

Published May 20, 2022

totp-rs is a Rust library that permits the creation of 2FA authentification tokens per time-based one-time password (TOTP). Prior to version 1.1.0, token comparison was not consta…

CVSS 4.2 · Medium
Vendor/product tagsBeta · best-effort
Showing 426-450 of 748 CVEsPage 18 of 30