Skip to main content

CWE archive

CWE-203 CVEs

Programmatic archive

748 CVEs tagged with CWE-20316 Critical, 107 High, 538 Medium, 87 Low, 0 Unrated.

CVE-2021-33845

Published May 6, 2022

The Splunk Enterprise REST API allows enumeration of usernames via the lockout error message. The potential vulnerability impacts Splunk Enterprise instances before 8.1.7 when con…

CVSS 5.3 · Medium
Vendor/product tagsBeta · best-effort

CVE-2022-22356

Published Apr 5, 2022

IBM MQ Appliance 9.2 CD and 9.2 LTS could allow an attacker to enumerate account credentials due to an observable discrepancy in valid and invalid login attempts. IBM X-Force ID:…

CVSS 6.5 · Medium
Vendor/product tagsBeta · best-effort

CVE-2021-39791

Published Mar 30, 2022

In WallpaperManagerService, there is a possible way to determine whether an app is installed, without query permissions, due to side channel information disclosure. This could lea…

CVSS 5.5 · Medium
Vendor/product tagsBeta · best-effort

CVE-2021-39788

Published Mar 30, 2022

In TelecomManager, there is a possible way to check if a particular self managed phone account was registered on the device due to side channel information disclosure. This could…

CVSS 5.5 · Medium
Vendor/product tagsBeta · best-effort

CVE-2021-39775

Published Mar 30, 2022

In People, there is a possible way to determine whether an app is installed, without query permissions, due to side channel information disclosure. This could lead to local inform…

CVSS 5.5 · Medium
Vendor/product tagsBeta · best-effort

CVE-2021-39773

Published Mar 30, 2022

In VpnManagerService, there is a possible disclosure of installed VPN packages due to side channel information disclosure. This could lead to local information disclosure with no…

CVSS 5.5 · Medium
Vendor/product tagsBeta · best-effort

CVE-2021-39766

Published Mar 30, 2022

In Settings, there is a possible way to determine whether an app is installed, without query permissions, due to side channel information disclosure. This could lead to local info…

CVSS 5.5 · Medium
Vendor/product tagsBeta · best-effort

CVE-2021-39761

Published Mar 30, 2022

In Media, there is a possible way to determine whether an app is installed, without query permissions, due to side channel information disclosure. This could lead to local informa…

CVSS 5.5 · Medium
Vendor/product tagsBeta · best-effort

CVE-2021-39760

Published Mar 30, 2022

In AudioService, there is a possible way to determine whether an app is installed, without query permissions, due to side channel information disclosure. This could lead to local…

CVSS 5.5 · Medium
Vendor/product tagsBeta · best-effort

CVE-2021-39756

Published Mar 30, 2022

In Framework, there is a possible way to determine whether an app is installed, without query permissions, due to side channel information disclosure. This could lead to local inf…

CVSS 5.5 · Medium
Vendor/product tagsBeta · best-effort

CVE-2021-39755

Published Mar 30, 2022

In DevicePolicyManager, there is a possible way to reveal the existence of an installed package without proper query permissions due to side channel information disclosure. This c…

CVSS 5.5 · Medium
Vendor/product tagsBeta · best-effort

CVE-2021-39754

Published Mar 30, 2022

In ContextImpl, there is a possible way to determine whether an app is installed, without query permissions, due to side channel information disclosure. This could lead to local i…

CVSS 5.5 · Medium
Vendor/product tagsBeta · best-effort

CVE-2021-39745

Published Mar 30, 2022

In DevicePolicyManager, there is a possible way to determine whether an app is installed, without query permissions, due to side channel information disclosure. This could lead to…

CVSS 5.5 · Medium
Vendor/product tagsBeta · best-effort

CVE-2021-39744

Published Mar 30, 2022

In DevicePolicyManager, there is a possible way to determine whether an app is installed, without query permissions, due to side channel information disclosure. This could lead to…

CVSS 5.5 · Medium
Vendor/product tagsBeta · best-effort

CVE-2022-24784

Published Mar 25, 2022

Statamic is a Laravel and Git powered CMS. Before versions 3.2.39 and 3.3.2, it is possible to confirm a single character of a user's password hash using a specially crafted regul…

CVSS 3.7 · Low
Vendor/product tagsBeta · best-effort

CVE-2021-44421

Published Mar 10, 2022

The pointer-validation logic in util/mem_util.rs in Occlum before 0.26.0 for Intel SGX acts as a confused deputy that allows a local attacker to access unauthorized information vi…

CVSS 5.5 · Medium
Vendor/product tagsBeta · best-effort

CVE-2020-36517

Published Mar 10, 2022

An information leak in Nabu Casa Home Assistant Operating System and Home Assistant Supervised 2022.03 allows a DNS operator to gain knowledge about internal network resources via…

CVSS 7.5 · High
Vendor/product tagsBeta · best-effort

CVE-2022-0564

Published Feb 21, 2022

A vulnerability in Qlik Sense Enterprise on Windows could allow an remote attacker to enumerate domain user accounts. An attacker could exploit this vulnerability by sending authe…

CVSS 5.3 · Medium
Vendor/product tagsBeta · best-effort

CVE-2022-23643

Published Feb 15, 2022

Sourcegraph is a code search and navigation engine. Sourcegraph versions 3.35 and 3.36 reintroduced a previously fixed side-channel vulnerabilitity in the Code Monitoring feature…

CVSS 6.5 · Medium
Vendor/product tagsBeta · best-effort

CVE-2021-0524

Published Feb 11, 2022

In isServiceDistractionOptimized of CarPackageManagerService.java, there is a possible disclosure of installed packages due to side channel information disclosure. This could lead…

CVSS 5.5 · Medium
Vendor/product tagsBeta · best-effort

CVE-2021-45901

Published Feb 10, 2022

The password-reset form in ServiceNow Orlando provides different responses to invalid authentication attempts depending on whether the username exists.

CVSS 5.3 · Medium
Vendor/product tagsBeta · best-effort
Showing 451-475 of 748 CVEsPage 19 of 30