VulnSea

CWE-203

CVEs classified under CWE-203, newest first.

41 CVEsRSS

CVE-2025-59702High· 7.2
9mo ago

Entrust nShield Connect XC, nShield 5c, and nShield HSMi through 13.6.11, or 13.7 (patched in 13.6.12 (LTS) and 13.9.0 (STS)), allow a physically proximate attacker with elevated privileges to falsify tamper events by accessing internal …

Entrust nShield Connect XC, nShield 5c, and nShield HSMi through 13.6.11, or 13.7 (patched in 13.6.12 (LTS) and 13.9.0 (STS)), allow a physically proximate attacker with elevated privileges to falsify tamper events by accessing internal …

Twilightentrust · nshield_5c_firmwareEPSS 0.31%via NVD
CVE-2023-50781High· 7.5
2y ago

A flaw was found in m2crypto

A flaw was found in m2crypto. This issue may allow a remote attacker to decrypt captured messages in TLS servers that use RSA key exchanges, which may lead to exposure of confidential or sensitive data.

Twilightredhat · update_infrastructureEPSS 1.1%via NVD
CVE-2023-52323Medium· 5.3
2y ago

PyCryptodome and pycryptodomex side-channel leakage for OAEP decryption

PyCryptodome and pycryptodomex side-channel leakage for OAEP decryption

Sunlitpycryptodomex · pycryptodomexEPSS 0.62%via OSV
CVE-2023-3640High· 7.0PoC
3y ago

A possible unauthorized memory access flaw was found in the Linux kernel's cpu_entry_area mapping of X86 CPU data to memory, where a user may guess the location of exception stacks or other important data

A possible unauthorized memory access flaw was found in the Linux kernel's cpu_entry_area mapping of X86 CPU data to memory, where a user may guess the location of exception stacks or other important data. Based on the previous CVE-2023-…

Midnightlinux · linux_kernelEPSS 0.76%via NVD
CVE-2023-28840High· 7.5
3y ago

Moby is an open source container framework developed by Docker Inc

Moby is an open source container framework developed by Docker Inc. that is distributed as Docker, Mirantis Container Runtime, and various other downstream projects/products. The Moby daemon component (`dockerd`), which is developed as m…

Twilightmobyproject · mobyEPSS 2.6%via NVD
CVE-2022-37146Medium· 5.3
4y ago

The PlexTrac platform prior to version 1.28.0 allows for username enumeration via HTTP response times on invalid login attempts for users configured to use the PlexTrac authentication provider

The PlexTrac platform prior to version 1.28.0 allows for username enumeration via HTTP response times on invalid login attempts for users configured to use the PlexTrac authentication provider. Login attempts for valid, unlocked users co…

Sunlitplextrac · plextracEPSS 0.82%via NVD
CVE-2022-23304Critical· 9.8
4y ago

The implementations of EAP-pwd in hostapd before 2.10 and wpa_supplicant before 2.10 are vulnerable to side-channel attacks as a result of cache access patterns

The implementations of EAP-pwd in hostapd before 2.10 and wpa_supplicant before 2.10 are vulnerable to side-channel attacks as a result of cache access patterns. NOTE: this issue exists because of an incomplete fix for CVE-2019-9495.

Midnightw1.fi · hostapdEPSS 1.9%via NVD
CVE-2022-23303Critical· 9.8PoC
4y ago

The implementations of SAE in hostapd before 2.10 and wpa_supplicant before 2.10 are vulnerable to side channel attacks as a result of cache access patterns

The implementations of SAE in hostapd before 2.10 and wpa_supplicant before 2.10 are vulnerable to side channel attacks as a result of cache access patterns. NOTE: this issue exists because of an incomplete fix for CVE-2019-9494.

Abyssalw1.fi · hostapdEPSS 3.1%via NVD
CVE-2020-3585Medium· 5.3
5y ago

A vulnerability in the TLS handler of Cisco Adaptive Security Appliance (ASA) Software and Cisco Firepower Threat Defense (FTD) Software for Cisco Firepower 1000 Series firewalls could allow an unauthenticated, remote attacker to gain ac…

A vulnerability in the TLS handler of Cisco Adaptive Security Appliance (ASA) Software and Cisco Firepower Threat Defense (FTD) Software for Cisco Firepower 1000 Series firewalls could allow an unauthenticated, remote attacker to gain ac…

Sunlitcisco · secure_firewall_threat_defenseEPSS 1.3%via NVD
CVE-2020-12401Medium· 4.7
5y ago

During ECDSA signature generation, padding applied in the nonce designed to ensure constant-time scalar multiplication was removed, resulting in variable-time execution dependent on secret data

During ECDSA signature generation, padding applied in the nonce designed to ensure constant-time scalar multiplication was removed, resulting in variable-time execution dependent on secret data. This vulnerability affects Firefox < 80 an…

Sunlitmozilla · firefoxEPSS 0.32%via NVD
CVE-2020-12400Medium· 4.7
5y ago

When converting coordinates from projective to affine, the modular inversion was not performed in constant time, resulting in a possible timing-based side channel attack

When converting coordinates from projective to affine, the modular inversion was not performed in constant time, resulting in a possible timing-based side channel attack. This vulnerability affects Firefox < 80 and Firefox for Android < 80.

Sunlitmozilla · firefoxEPSS 0.27%via NVD
CWE-203 vulnerabilities (CVEs) — page 2 · VulnSea