Skip to main content

CWE archive

CWE-203 CVEs

Programmatic archive

748 CVEs tagged with CWE-20316 Critical, 107 High, 538 Medium, 87 Low, 0 Unrated.

CVE-2021-1005

Published Dec 15, 2021

In getDeviceIdWithFeature of PhoneInterfaceManager.java, there is a possible way to determine whether an app is installed, without query permissions, due to side channel informati…

CVSS 5.5 · Medium
Vendor/product tagsBeta · best-effort

CVE-2021-0995

Published Dec 15, 2021

In registerSuggestionConnectionStatusListener of WifiServiceImpl.java, there is a possible way to determine whether an app is installed, without query permissions, due to side cha…

CVSS 3.3 · Low
Vendor/product tagsBeta · best-effort

CVE-2021-0990

Published Dec 15, 2021

In getDeviceId of PhoneSubInfoController.java, there is a possible way to determine whether an app is installed, without query permissions, due to side channel information disclos…

CVSS 3.3 · Low
Vendor/product tagsBeta · best-effort

CVE-2021-0989

Published Dec 15, 2021

In hasManageOngoingCallsPermission of TelecomServiceImpl.java, there is a possible way to determine whether an app is installed, without query permissions, due to side channel inf…

CVSS 3.3 · Low
Vendor/product tagsBeta · best-effort

CVE-2021-0988

Published Dec 15, 2021

In getLaunchedFromUid and getLaunchedFromPackage of ActivityClientController.java, there is a possible way to determine whether an app is installed, without query permissions, due…

CVSS 3.3 · Low
Vendor/product tagsBeta · best-effort

CVE-2021-0987

Published Dec 15, 2021

In getNeighboringCellInfo of PhoneInterfaceManager.java, there is a possible way to determine whether an app is installed, without query permissions, due to side channel informati…

CVSS 3.3 · Low
Vendor/product tagsBeta · best-effort

CVE-2021-43823

Published Dec 13, 2021

Sourcegraph is a code search and navigation engine. Sourcegraph prior to version 3.33.2 is vulnerable to a side-channel attack where strings in private source code could be guesse…

CVSS 6.5 · Medium
Vendor/product tagsBeta · best-effort

CVE-2021-44848

Published Dec 13, 2021

In Cibele Thinfinity VirtualUI before 3.0, /changePassword returns different responses for invalid authentication requests depending on whether the username exists.

CVSS 5.3 · Medium
Vendor/product tagsBeta · best-effort

CVE-2021-43398

Published Nov 4, 2021

Crypto++ (aka Cryptopp) 8.6.0 and earlier contains a timing leakage in MakePublicKey(). There is a clear correlation between execution time and private key length, which may cause…

CVSS 5.3 · Medium
Vendor/product tagsBeta · best-effort

CVE-2021-24651

Published Oct 11, 2021

The Poll Maker WordPress plugin before 3.4.2 allows unauthenticated users to perform SQL injection via the ays_finish_poll AJAX action. While the result is not disclosed in the re…

CVSS 7.5 · High
Vendor/product tagsBeta · best-effort

CVE-2021-20376

Published Oct 7, 2021

IBM Sterling File Gateway 2.2.0.0 through 6.1.1.0 could allow an authenticated attacker to enumerate usernames due to there being an observable discrepancy in returned messages. I…

CVSS 4.3 · Medium
Vendor/product tagsBeta · best-effort

CVE-2021-38153

Published Sep 22, 2021

Some components in Apache Kafka use `Arrays.equals` to validate a password or key, which is vulnerable to timing attacks that make brute force attacks for such credentials more li…

CVSS 5.9 · Medium

CVE-2021-39189

Published Sep 15, 2021

Pimcore is an open source data & experience management platform. In versions prior to 10.1.3, it is possible to enumerate usernames via the forgot password functionality. This iss…

CVSS 5.3 · Medium
Vendor/product tagsBeta · best-effort

CVE-2021-37151

Published Sep 1, 2021

CyberArk Identity 21.5.131, when handling an invalid authentication attempt, sometimes reveals whether the username is valid. In certain authentication policy configurations with…

CVSS 5.3 · Medium
Vendor/product tagsBeta · best-effort

CVE-2020-25082

Published Aug 10, 2021

An attacker with physical access to Nuvoton Trusted Platform Module (NPCT75x 7.2.x before 7.2.2.0) could extract an Elliptic Curve Cryptography (ECC) private key via a side-channe…

CVSS 3.8 · Low
Vendor/product tagsBeta · best-effort

CVE-2021-38209

Published Aug 8, 2021

net/netfilter/nf_conntrack_standalone.c in the Linux kernel before 5.12.2 allows observation of changes in any net namespace because these changes are leaked into all other net na…

CVSS 3.3 · Low
Vendor/product tagsBeta · best-effort
Showing 501-525 of 748 CVEsPage 21 of 30