Fallos del tipo CWE-203

350 resultados

Discrepância Observável em Respostas

A aplicação revela informações sensíveis através de diferenças detectáveis em seu comportamento, tempo de resposta ou mensagens de erro — por exemplo, retornando erros diferentes para usuário inexistente vs. senha incorreta. Um atacante pode explorar essas pistas para inferir dados confidenciais sem acesso direto.

Ejemplo

Um sistema de login que responde 'Usuário não encontrado' em 100ms, mas 'Senha incorreta' em 500ms (após validação). Um invasor enumera contas válidas medindo latência, ou identifica emails registrados pela velocidade da resposta.

Cómo mitigar

Padronize respostas de erro (mesma mensagem genérica), normalize tempos de execução com delays constantes, e evite vazar informações estruturais (ex: 'este email já existe'). Auditoria de logs e timestamps também revelar quem tentou enumerar dados sensíveis.

CVE-2026-73409MEDIUMBudibase: Server Filesystem Existence/Read Oracle via Builder-Controlled MongoDB tlsCertificateKeyFileEPSS 0.2%CVE-2025-68164LOWIn JetBrains TeamCity before 2025.11 port enumeration was possible via the Perforce connection testEPSS 0.2%CVE-2026-11754MEDIUMUser Enumeration in Seres Software's syWEBEPSS 0.2%CVE-2026-59502MEDIUMPriority - CWE-203: Observable DiscrepancyEPSS 0.2%CVE-2024-50102MEDIUMx86: fix user address masking non-canonical speculation issueEPSS 0.2%CVE-2023-27931MEDIUMThis issue was addressed by removing the vulnerable code. This issue is fixed in macOS Ventura 13.3, macOS Monterey 12.6.3, iOS 16.4 and iPaEPSS 0.2%CVE-2026-87620MEDIUMObservable discrepancy in SVG in Google Chrome prior to 153.0.8010.36 allowed a remote attacker to obtain sensitive information via a crafteEPSS 0.2%CVE-2026-91714MEDIUMObservable discrepancy in Fonts in Google Chrome prior to 153.0.8010.47 allowed a remote attacker leveraging social engineering to leak sensEPSS 0.2%CVE-2026-87623MEDIUMObservable discrepancy in DOM in Google Chrome prior to 153.0.8010.36 allowed a remote attacker leveraging social engineering to obtain sensEPSS 0.2%CVE-2026-91725MEDIUMObservable discrepancy in CSS in Google Chrome prior to 153.0.8010.47 allowed a remote attacker to leak sensitive information via a crafted EPSS 0.2%CVE-2026-11284MEDIUMSide-channel information leakage in PerformanceAPIs in Google Chrome prior to 149.0.7827.53 allowed a remote attacker to leak cross-origin dEPSS 0.2%CVE-2025-24391MEDIUMPossible user enumerationEPSS 0.2%CVE-2026-87516MEDIUMObservable discrepancy in Navigation in Google Chrome prior to 153.0.8010.36 allowed a remote attacker to leak cross-origin data via a craftEPSS 0.2%CVE-2025-9031MEDIUMTiming-Based Username Enumeration in DivvyDrive Information Technologies' DivvyDrive WebEPSS 0.2%CVE-2022-42792This issue was addressed with improved data protection. This issue is fixed in iOS 16.1 and iPadOS 16. An app may be able to read sensitive EPSS 0.2%CVE-2026-58445LOWCross-repository label-ID enumeration oracle via unscoped DeleteIssueLabel APIEPSS 0.2%CVE-2025-36225MEDIUMIBM Aspera Faspex information disclosureEPSS 0.2%CVE-2025-29780MEDIUMPost-Quantum Secure Feldman's Verifiable Secret Sharing has Timing Side-Channels in Matrix OperationsEPSS 0.2%CVE-2022-0823MEDIUMAn improper control of interaction frequency vulnerability in Zyxel GS1200 series switches could allow a local attacker to guess the passworEPSS 0.2%CVE-2026-47011LOWVulnerability in the Siebel CRM Deployment product of Oracle Siebel CRM (component: Application Interface). Supported versions that are affEPSS 0.2%