The software receives input from an upstream component, but it
does not account for byte ordering (e.g. big-endian and little-endian) when
processing the input, causing an incorrect number or value to be
used.
An information exposure is the intentional or unintentional
disclosure of information to an actor that is not explicitly authorized to have
access to that information.
The accidental exposure of sensitive information through sent
data refers to the transmission of data which are either sensitive in and of
itself or useful in the further exploitation of the system through standard data
channels.
The product behaves differently or sends different responses in
a way that exposes security-relevant information about the state of the product,
such as whether a particular operation was successful or
not.
The software provides different responses to incoming requests
in a way that allows an actor to determine system state information that is
outside of that actor's control sphere.