Fallos del tipo CWE-203

350 resultados

Discrepância Observável em Respostas

A aplicação revela informações sensíveis através de diferenças detectáveis em seu comportamento, tempo de resposta ou mensagens de erro — por exemplo, retornando erros diferentes para usuário inexistente vs. senha incorreta. Um atacante pode explorar essas pistas para inferir dados confidenciais sem acesso direto.

Ejemplo

Um sistema de login que responde 'Usuário não encontrado' em 100ms, mas 'Senha incorreta' em 500ms (após validação). Um invasor enumera contas válidas medindo latência, ou identifica emails registrados pela velocidade da resposta.

Cómo mitigar

Padronize respostas de erro (mesma mensagem genérica), normalize tempos de execução com delays constantes, e evite vazar informações estruturais (ex: 'este email já existe'). Auditoria de logs e timestamps também revelar quem tentou enumerar dados sensíveis.

CVE-2024-40490HIGHAn issue in Sourcebans++ before v.1.8.0 allows a remote attacker to obtain sensitive information via a crafted XAJAX call to the Forgot PassEPSS 0.5%CVE-2026-64713HIGHThis issue was addressed with improved checks. This issue is fixed in Safari 26.6, iOS 26.6 and iPadOS 26.6, macOS Tahoe 26.6, tvOS 26.6, viEPSS 0.5%CVE-2024-2464MEDIUMApplication users enumeration in CDeXEPSS 0.5%CVE-2026-26315MEDIUMGo Ethereum Improperly Validates the ECIES Public Key in RLPx HandshakeEPSS 0.5%CVE-2026-56339HIGHCapgo - Unauthenticated Organization Existence Enumeration via rescind_invitation RPCEPSS 0.5%CVE-2022-4025MEDIUMInappropriate implementation in Paint in Google Chrome prior to 98.0.4758.80 allowed a remote attacker to leak cross-origin data outside an EPSS 0.5%CVE-2023-33518MEDIUMemoncms v11 and later was discovered to contain an information disclosure vulnerability which allows attackers to obtain the web directory pEPSS 0.5%CVE-2024-41335HIGHDraytek devices Vigor 165/166 prior to v4.2.6 , Vigor 2620/LTE200 prior to v3.9.8.8, Vigor 2860/2925 prior to v3.9.7, Vigor 2862/2926 prior EPSS 0.5%CVE-2024-11084MEDIUMPotential Username Enumeration in Helix ALMEPSS 0.5%CVE-2023-28015MEDIUMHCL Domino AppDev Pack is susceptible to a User Account Enumeration vulnerabilityEPSS 0.4%CVE-2023-34344MEDIUMA vulnerability in the IPMI handler, where an unauthorized attacker can use certain oracles to guess a valid usernameEPSS 0.4%CVE-2024-31878MEDIUMIBM i information disclosureEPSS 0.4%CVE-2023-1696HIGHThe multimedia video module has a vulnerability in data processing.Successful exploitation of this vulnerability may affect availability.EPSS 0.4%CVE-2024-21206MEDIUMVulnerability in the Oracle Enterprise Command Center Framework product of Oracle E-Business Suite (component: Diagnostics). Supported versEPSS 0.4%CVE-2026-78955MEDIUMObservable discrepancy in PerformanceAPIs in Google Chrome prior to 152.0.7977.65 allowed a remote attacker to potentially obtain cross-origEPSS 0.4%CVE-2024-12663MEDIUMfunnyzpc Mee-Admin Login login observable response discrepancyEPSS 0.4%CVE-2024-28885HIGHObservable discrepancy in some Intel(R) QAT Engine for OpenSSL software before version v1.6.1 may allow information disclosure via network aEPSS 0.4%CVE-2026-47379MEDIUMNocoDB: Plaintext Password Comparison in Shared ViewsEPSS 0.4%CVE-2024-39921HIGHObservable timing discrepancy issue exists in IPCOM EX2 Series V01L02NF0001 to V01L06NF0401, V01L20NF0001 to V01L20NF0401, V02L20NF0001 to VEPSS 0.4%CVE-2026-64822MEDIUMdjangoSIGE 1.10 User Enumeration via ForgotPasswordViewEPSS 0.4%