Fallos del tipo CWE-203

350 resultados

Discrepância Observável em Respostas

A aplicação revela informações sensíveis através de diferenças detectáveis em seu comportamento, tempo de resposta ou mensagens de erro — por exemplo, retornando erros diferentes para usuário inexistente vs. senha incorreta. Um atacante pode explorar essas pistas para inferir dados confidenciais sem acesso direto.

Ejemplo

Um sistema de login que responde 'Usuário não encontrado' em 100ms, mas 'Senha incorreta' em 500ms (após validação). Um invasor enumera contas válidas medindo latência, ou identifica emails registrados pela velocidade da resposta.

Cómo mitigar

Padronize respostas de erro (mesma mensagem genérica), normalize tempos de execução com delays constantes, e evite vazar informações estruturais (ex: 'este email já existe'). Auditoria de logs e timestamps também revelar quem tentou enumerar dados sensíveis.

CVE-2023-5410HIGHA potential security vulnerability has been reported in the system BIOS of certain HP PC products, which might allow memory tampering. HP isEPSS 0.2%CVE-2025-13736LOWUsername Enumeration via Login Interface in Multiple WSO2 Products Allows User Account DiscoveryEPSS 0.2%CVE-2025-8774LOWriscv-boom SonicBOOM L1 Data Cache timing discrepancyEPSS 0.2%CVE-2025-65185LOWThere is a username enumeration via local user login in Entrinsik Informer v5.10.1 which allows malicious users to enumerate users by enteriEPSS 0.2%CVE-2024-47153MEDIUMSome Honor products are affected by information leak vulnerability, successful exploitation could cause the information leak.EPSS 0.2%CVE-2024-8993MEDIUMSome Honor products are affected by information leak vulnerability, successful exploitation could cause the information leak.EPSS 0.2%CVE-2024-8994MEDIUMSome Honor products are affected by information leak vulnerability, successful exploitation could cause the information leak.EPSS 0.2%CVE-2024-47154MEDIUMSome Honor products are affected by information leak vulnerability, successful exploitation could cause the information leak.EPSS 0.2%CVE-2024-47155MEDIUMSome Honor products are affected by information leak vulnerability, successful exploitation could cause the information leak.EPSS 0.2%CVE-2024-8992MEDIUMSome Honor products are affected by information leak vulnerability, successful exploitation could cause the information leak.EPSS 0.2%CVE-2024-47150LOWSome Honor products are affected by information leak vulnerability, successful exploitation could cause the information leak.EPSS 0.1%CVE-2024-47156LOWInformation Leak Vulnerability in Honor ProductEPSS 0.1%CVE-2024-47149LOWSome Honor products are affected by incorrect privilege assignment vulnerability, successful exploitation could cause device service exceptiEPSS 0.1%CVE-2025-13912LOWPotential non-constant time compiled code with Clang LLVMEPSS 0.1%CVE-2026-28490HIGHAuthlib Vulnerable to JWE RSA1_5 Bleichenbacher Padding OracleEPSS 0.1%CVE-2026-4040MEDIUMOpenClaw File Existence tools.exec.safeBins information exposureEPSS 0.1%CVE-2026-3580LOWCompiler-induced timing leak in sp_256_get_entry_256_9 on RISC-VEPSS 0.1%CVE-2025-48561MEDIUMIn multiple locations, there is a possible way to access data displayed on the screen due to side channel information disclosure. This couldEPSS 0.1%CVE-2022-20538MEDIUMIn getSmsRoleHolder of RoleService.java, there is a possible way to determine whether an app is installed, without query permissions, due toEPSS 0.1%CVE-2022-20535LOWIn registerLocalOnlyHotspotSoftApCallback of WifiManager.java, there is a possible way to determine whether an app is installed, without queEPSS 0.1%