Fallos del tipo CWE-203

350 resultados

Discrepância Observável em Respostas

A aplicação revela informações sensíveis através de diferenças detectáveis em seu comportamento, tempo de resposta ou mensagens de erro — por exemplo, retornando erros diferentes para usuário inexistente vs. senha incorreta. Um atacante pode explorar essas pistas para inferir dados confidenciais sem acesso direto.

Ejemplo

Um sistema de login que responde 'Usuário não encontrado' em 100ms, mas 'Senha incorreta' em 500ms (após validação). Um invasor enumera contas válidas medindo latência, ou identifica emails registrados pela velocidade da resposta.

Cómo mitigar

Padronize respostas de erro (mesma mensagem genérica), normalize tempos de execução com delays constantes, e evite vazar informações estruturais (ex: 'este email já existe'). Auditoria de logs e timestamps também revelar quem tentou enumerar dados sensíveis.

CVE-2026-79181MEDIUMObservable discrepancy in Glic in Google Chrome prior to 152.0.7977.65 allowed a remote attacker to obtain sensitive information via a craftEPSS 0.2%CVE-2026-87566MEDIUMObservable discrepancy in Layout in Google Chrome prior to 153.0.8010.36 allowed a remote attacker to leak sensitive information via a craftEPSS 0.2%CVE-2026-59640HIGHOpenPGP CFB quick-check oracle active on symmetric/session-key pathsEPSS 0.2%CVE-2025-46804LOWScreen 5.0.0 and older versions allow file existence tests when installed setuid-rootEPSS 0.2%CVE-2025-13166LOWUsername Enumeration via SMS OTP Flow in WSO2 Identity Server Allows User Account DiscoveryEPSS 0.2%CVE-2026-87539LOWObservable discrepancy in Network in Google Chrome prior to 153.0.8010.36 allowed a remote attacker to obtain cross-origin data via a crafteEPSS 0.2%CVE-2018-9364HIGHIn the LG LAF component, there is a special command that allowed modification of certain partitions. This could lead to bypass of secure booEPSS 0.2%CVE-2026-45294MEDIUMFreeScout: User Account Enumeration via Password Reset Response DifferentiationEPSS 0.2%CVE-2024-23984MEDIUMObservable discrepancy in RAPL interface for some Intel(R) Processors may allow a privileged user to potentially enable information disclosuEPSS 0.2%CVE-2026-33425MEDIUMDiscourse has inferable private group membership or existence via exclude_groups parameterEPSS 0.2%CVE-2024-27839MEDIUMA privacy issue was addressed by moving sensitive data to a more secure location. This issue is fixed in iOS 17.5 and iPadOS 17.5. A malicioEPSS 0.2%CVE-2026-45410MEDIUMTime-based user enumeration in TREK authentication endpointEPSS 0.2%CVE-2026-73630MEDIUMSiYuan before v3.7.4 Information Disclosure via authFilePublishAccessEPSS 0.2%CVE-2026-72699CRITICALGrav Login Plugin before 3.9.1 Email Enumeration via RegistrationEPSS 0.2%CVE-2026-11289MEDIUMSide-channel information leakage in Paint in Google Chrome prior to 149.0.7827.53 allowed a remote attacker to leak cross-origin data via a EPSS 0.2%CVE-2026-55227MEDIUMObservable object existence disclosure in private Weblate projects via globally scoped object lookupsEPSS 0.2%CVE-2025-54999LOWOpenBao: Timing Side-Channel in Userpass Auth MethodEPSS 0.2%CVE-2026-87619MEDIUMObservable discrepancy in Prefetch in Google Chrome prior to 153.0.8010.36 allowed a remote attacker to leak cross-origin data via a craftedEPSS 0.2%CVE-2026-23620MEDIUMGFI MailEssentials AI < 22.4 ListServer.IsDBExist() Absolute Directory Traversal to File EnumerationEPSS 0.2%CVE-2026-21386MEDIUMPrivate channel enumeration via /mute slash commandEPSS 0.2%