CWE-203: CWE-203
Yearly Trend
Top Affected Vendors
All CWE-203 CVEs (95)
CVE-2019-25337 is a username enumeration vulnerability in ownCloud that allows remote attackers to discover valid user accounts by sending crafted req...
Feb 12, 2026This vulnerability allows attackers to enumerate administrative user email addresses in Vasion Print (formerly PrinterLogic) systems. Attackers can id...
Mar 5, 2025CVE-2024-25714 is a critical timing side-channel vulnerability in Rhonabwy's HMAC signature verification that allows attackers to potentially forge va...
Feb 11, 2024CVE-2024-25190 is a timing side-channel vulnerability in l8w8jwt 2.2.1 that allows attackers to bypass authentication by exploiting non-constant-time ...
Feb 8, 2024This vulnerability in darkhttpd allows remote attackers to bypass authentication via timing side-channel attacks. The web server uses non-constant-tim...
Jan 22, 2024This vulnerability in PHPJabbers Callback Widget v1.0 allows attackers to enumerate valid user accounts through differences in password recovery messa...
Aug 28, 2023CVE-2022-23303 is a side-channel vulnerability in SAE (Simultaneous Authentication of Equals) implementations in hostapd and wpa_supplicant that allow...
Jan 17, 2022This vulnerability allows attackers to extract secret cryptographic keys through timing side-channel attacks in threshold signature implementations. T...
Apr 21, 2023This vulnerability allows attackers to extract RSA private keys through timing and power side-channel attacks during modular exponentiation in RSA-CRT...
Nov 12, 2021This vulnerability in HP PC system BIOS could allow attackers to tamper with memory, potentially leading to privilege escalation or system compromise....
Mar 12, 2024This CVE describes a logic error in Android that allows local attackers to obtain any system permission without additional privileges. User interactio...
Jan 21, 2025This vulnerability in Android's InputMethod allows attackers to determine whether specific apps are installed without requiring query permissions, exp...
Oct 30, 2023This vulnerability in Android's Package Installer allows attackers to detect whether specific apps are installed without requiring query permissions, ...
Oct 30, 2023This vulnerability in Android's Slice component allows attackers to detect which applications are installed on a device through side-channel analysis....
Oct 30, 2023A cryptographic flaw in go-ethereum's ECIES implementation allows attackers to extract bits of the p2p node key. This affects all Geth nodes running v...
Feb 19, 2026H3C SSL VPN has a user enumeration vulnerability that allows attackers to determine valid usernames by analyzing login response differences. Attackers...
Dec 30, 2025This vulnerability allows attackers to extract private keys from X25519 cryptographic implementations on Xtensa-based ESP32 chips through timing side-...
Nov 21, 2025This timing attack vulnerability in the parisneo/lollms authentication system allows attackers to enumerate valid usernames and guess passwords by ana...
Jul 7, 2025An unauthenticated remote attacker can access sensitive authentication information in CODESYS OPC UA Server when using the non-default Basic128Rsa15 s...
Mar 18, 2025This vulnerability in Draytek routers allows attackers to perform timing attacks against insecure strcmp/memcmp implementations, potentially revealing...
Feb 27, 2025This vulnerability in Oracle JD Edwards EnterpriseOne Tools allows unauthenticated attackers to remotely access sensitive data via HTTP. It affects We...
Jan 21, 2025An access control vulnerability in AVM FRITZ!Box 7530 AX routers allows unauthenticated attackers to access sensitive system information via the /juis...
Jan 6, 2025CVE-2018-9364 is a vulnerability in LG's LAF component that allows modification of protected partitions without user interaction. This could lead to s...
Nov 19, 2024A timing side-channel vulnerability in IPCOM EX2 and VE2 series devices allows attackers to potentially decrypt encrypted communications by analyzing ...
Sep 4, 2024This vulnerability allows attackers to recover ML-KEM 512 secret keys through timing side-channel attacks when the Kyber reference implementation is c...
Jun 10, 2024This timing attack vulnerability in gaizhenbiao/chuanhuchatgpt allows attackers to guess passwords by measuring how long password comparisons take. At...
Jun 6, 2024This vulnerability in LIVEBOX Collaboration vDesk allows attackers to infer internal system state information through observable response discrepancie...
Feb 21, 2024This vulnerability allows attackers to decrypt RSA-encrypted data by exploiting timing discrepancies in the jsrsasign library's PKCS1.5 and RSAOAEP de...
Jan 22, 2024This CVE describes a timing side-channel vulnerability in Go's RSA-based TLS key exchange implementation prior to version 1.20. Attackers could potent...
Dec 5, 2023CVE-2023-36127 is a user enumeration vulnerability in PHPJabbers Appointment Scheduler 3.0 that allows attackers to determine valid usernames via pass...
Oct 10, 2023The Macrovideo v380pro security camera firmware v1.4.97 exposes device credentials when sharing camera access. This allows unauthorized users to obtai...
May 30, 2023SENAYAN Library Management System (SLiMS) Bulian v9.5.2 fails to strip EXIF metadata from uploaded images, allowing attackers to extract sensitive inf...
Apr 14, 2023This vulnerability allows attackers to perform timing attacks against the webhook secret validation in Atlantis, potentially recovering the secret thr...
Jul 29, 2022This vulnerability in Jenkins creates a timing side-channel in the login form that allows attackers to distinguish between invalid usernames and valid...
Jun 23, 2022This vulnerability allows DNS operators to discover internal network resources through hardcoded DNS resolver configurations in Home Assistant systems...
Mar 10, 2022This vulnerability in Best Practical Request Tracker (RT) allows attackers to perform timing attacks against the REST2 authentication middleware, pote...
Oct 18, 2021This vulnerability in Pengutronix barebox bootloader leaks timing information during password hash comparison, allowing attackers to perform timing at...
Aug 2, 2021This vulnerability allows unauthenticated attackers to enumerate valid user accounts in MB connect line mymbCONNECT24 and mbCONNECT24 software. By ana...
Aug 2, 2021This vulnerability in Libgcrypt allows side-channel attacks against ElGamal encryption due to missing exponent blinding and inappropriate window size ...
Jun 8, 2021The Luca COVID-19 contact tracing app for Android versions through 1.7.4 leaks sensitive information about users' COVID-19 status. Remote attackers ca...
Jun 4, 2021This vulnerability in Qualcomm Snapdragon chipsets allows attackers to link RTT (Round Trip Time) frames with non-randomized MAC addresses by comparin...
Feb 22, 2021CVE-2020-1459 is a speculative execution side-channel vulnerability affecting ARM processors that allows local attackers to potentially access sensiti...
Aug 17, 2020This vulnerability allows attackers to forge SASL Role Tokens that pass signature verification due to timing discrepancies in Apache Pulsar's authenti...
Feb 7, 2024CVE-2024-23342 is a vulnerability in the Python ecdsa package that allows attackers to perform side-channel timing attacks (Minerva attack) to extract...
Jan 23, 2024This CVE describes a timing side-channel vulnerability in GnuTLS that allows attackers to perform Bleichenbacher-style attacks against RSA encryption....
Feb 15, 2023This vulnerability allows off-path attackers to hijack TCP sessions on OpenWrt routers with NAT enabled, enabling them to impersonate clients or serve...
May 28, 2024This vulnerability allows a physically proximate attacker with elevated privileges to falsify tamper events on Entrust nShield hardware security modul...
Dec 2, 2025This CVE addresses a timing side-channel vulnerability in the Linux kernel's IPv6 Segment Routing (SR) implementation. Attackers could potentially exp...
Sep 5, 2025This CVE describes an information leak vulnerability affecting certain Honor products. Successful exploitation could allow unauthorized access to sens...
Dec 26, 2024This vulnerability in Intel QAT Engine for OpenSSL before version 1.6.1 allows an attacker to infer sensitive information through timing discrepancies...
Nov 13, 2024About CWE-203 (CWE-203)
Our database tracks 95 CVEs classified as CWE-203, with 9 rated critical and 39 rated high severity. The average CVSS score for CWE-203 vulnerabilities is 6.5.
External reference: View CWE-203 on MITRE CWE →
Monitor CWE-203 Vulnerabilities
Get alerted when new CWE-203 CVEs affect your infrastructure.
Start Monitoring Free