Skip to main content

CWE archive

CWE-203 CVEs

Programmatic archive

748 CVEs tagged with CWE-20316 Critical, 107 High, 538 Medium, 87 Low, 0 Unrated.

CVE-2021-39021

Published Feb 2, 2022

IBM Guardium Data Encryption (GDE) 5.0.0.2 behaves differently or sends different responses under different circumstances in a way that is observable to an unauthorized actor, whi…

CVSS 5.3 · Medium
Vendor/product tagsBeta · best-effort

CVE-2022-21659

Published Jan 31, 2022

Flask-AppBuilder is an application development framework, built on top of the Flask web framework. In affected versions there exists a user enumeration vulnerability. This vulnera…

CVSS 5.3 · Medium
Vendor/product tagsBeta · best-effort

CVE-2022-24032

Published Jan 30, 2022

Adenza AxiomSL ControllerView through 10.8.1 is vulnerable to user enumeration. An attacker can identify valid usernames on the platform because a failed login attempt produces a…

CVSS 5.3 · Medium
Vendor/product tagsBeta · best-effort

CVE-2019-25056

Published Jan 26, 2022

In Bromite through 78.0.3904.130, there are adblock rules in the release APK; therefore, probing which resources are blocked and which aren't can identify the application version…

CVSS 5.3 · Medium
Vendor/product tagsBeta · best-effort

CVE-2022-23106

Published Jan 12, 2022

Jenkins Configuration as Code Plugin 1.55 and earlier used a non-constant time comparison function when validating an authentication token allowing attackers to use statistical me…

CVSS 5.3 · Medium
Vendor/product tagsBeta · best-effort

CVE-2022-22120

Published Jan 10, 2022

In NocoDB, versions 0.9 to 0.83.8 are vulnerable to Observable Discrepancy in the password-reset feature. When requesting a password reset for a given email address, the applicati…

CVSS 5.3 · Medium
Vendor/product tagsBeta · best-effort

CVE-2021-20147

Published Jan 3, 2022

ManageEngine ADSelfService Plus below build 6116 contains an observable response discrepancy in the UMCP operation of the ChangePasswordAPI. This allows an unauthenticated remote…

CVSS 5.3 · Medium
Vendor/product tagsBeta · best-effort

CVE-2020-35398

Published Dec 23, 2021

An issue was discovered in UTI Mutual fund Android application 5.4.18 and prior, allows attackers to brute force enumeration of usernames determined by the error message returned…

CVSS 5.3 · Medium
Vendor/product tagsBeta · best-effort

CVE-2021-20049

Published Dec 23, 2021

A vulnerability in SonicWall SMA100 password change API allows a remote unauthenticated attacker to perform SMA100 username enumeration based on the server responses. This vulnera…

CVSS 7.5 · High

CVE-2021-44554

Published Dec 20, 2021

Thinfinity VirtualUI before 3.0 allows a malicious actor to enumerate users registered in the OS (Windows) through the /changePassword URI. By accessing the vector, an attacker ca…

CVSS 5.3 · Medium
Vendor/product tagsBeta · best-effort

CVE-2021-1032

Published Dec 15, 2021

In getMimeGroup of PackageManagerService.java, there is a possible way to determine whether an app is installed, without query permissions, due to side channel information disclos…

CVSS 3.3 · Low
Vendor/product tagsBeta · best-effort

CVE-2021-1031

Published Dec 15, 2021

In cancelNotificationsFromListener of NotificationManagerService.java, there is a possible way to determine whether an app is installed, without query permissions, due to side cha…

CVSS 3.3 · Low
Vendor/product tagsBeta · best-effort

CVE-2021-1030

Published Dec 15, 2021

In setNotificationsShownFromListener of NotificationManagerService.java, there is a possible way to determine whether an app is installed, without query permissions, due to side c…

CVSS 5.5 · Medium
Vendor/product tagsBeta · best-effort

CVE-2021-1026

Published Dec 15, 2021

In startRanging of RttServiceImpl.java, there is a possible way to determine whether an app is installed, without query permissions, due to side channel information disclosure. Th…

CVSS 5.5 · Medium
Vendor/product tagsBeta · best-effort

CVE-2021-1018

Published Dec 15, 2021

In adjustStreamVolume of AudioService.java, there is a possible way to determine whether an app is installed, without query permissions, due to side channel information disclosure…

CVSS 3.3 · Low
Vendor/product tagsBeta · best-effort

CVE-2021-1015

Published Dec 15, 2021

In getMeidForSlot of PhoneInterfaceManager.java, there is a possible way to determine whether an app is installed, without query permissions, due to side channel information discl…

CVSS 3.3 · Low
Vendor/product tagsBeta · best-effort

CVE-2021-1014

Published Dec 15, 2021

In getNetworkTypeForSubscriber of PhoneInterfaceManager.java, there is a possible way to determine whether an app is installed, without query permissions, due to side channel info…

CVSS 5.5 · Medium
Vendor/product tagsBeta · best-effort

CVE-2021-1013

Published Dec 15, 2021

In checkExistsAndEnforceCannotModifyImmutablyRestrictedPermission of PermissionManagerService.java, there is a possible way to determine whether an app is installed, without query…

CVSS 5.5 · Medium
Vendor/product tagsBeta · best-effort

CVE-2021-1012

Published Dec 15, 2021

In onResume of NotificationAccessDetails.java, there is a possible way to determine whether an app is installed, without query permissions, due to side channel information disclos…

CVSS 5.5 · Medium
Vendor/product tagsBeta · best-effort

CVE-2021-1009

Published Dec 15, 2021

In setApplicationCategoryHint of PackageManagerService.java, there is a possible way to determine whether an app is installed, without query permissions, due to side channel infor…

CVSS 5.5 · Medium
Vendor/product tagsBeta · best-effort
Showing 476-500 of 748 CVEsPage 20 of 30