CWE-346— Origin Validation Error
468 active CVEs classified under this weakness category. Sourced from NVD, GHSA, and vendor advisories. Full definition on MITRE →
CVEs classified under CWE-346page 1 of 10
- CVE-1999-1549HIGHCVSS 7.8EG 7.81999-11-16
Lynx 2.x does not properly distinguish between internal and external HTML, which may allow a local attacker to read a "secure" hidden form value from a temporary file and craft a LYNXOPTIONS: URL that causes Lynx to modify the user's confi…
- CVE-2001-1452HIGHCVSS 7.5EG 7.52001-08-31
By default, DNS servers on Windows NT 4.0 and Windows 2000 Server cache glue records received from non-delegated name servers, which allows remote attackers to poison the DNS cache via spoofed DNS responses.
- CVE-2003-0981MEDIUMCVSS 6.1EG 6.12004-01-05
FreeScripts VisitorBook LE (visitorbook.pl) logs the reverse DNS name of a visiting host, which allows remote attackers to spoof the origin of their incoming requests and facilitate cross-site scripting (XSS) attacks.
- CVE-2005-0877HIGHCVSS 7.5EG 7.52005-05-02
Dnsmasq before 2.21 allows remote attackers to poison the DNS cache via answers to queries that were not made by Dnsmasq.
- CVE-2009-1185NONECVSS 0.0EG 9.02009-04-17
udev before 1.4.1 does not verify whether a NETLINK message originates from kernel space, which allows local users to gain privileges by sending a NETLINK message from user space.
- CVE-2009-4139MEDIUMCVSS 6.8EG 6.82011-07-27
A flaw was found in Spacewalk Java site packages. This cross-site request forgery (CSRF) vulnerability allows a remote attacker to hijack the authentication of arbitrary users. This can lead to unauthorized actions, including disabling use…
- CVE-2011-2856NONECVSS 0.0EG 0.02011-09-19
Google V8, as used in Google Chrome before 14.0.835.163, allows remote attackers to bypass the Same Origin Policy via unspecified vectors.
- CVE-2011-3056NONECVSS 0.0EG 0.02012-03-22
Google Chrome before 17.0.963.83 allows remote attackers to bypass the Same Origin Policy via vectors involving a "magic iframe."
- CVE-2011-3067NONECVSS 0.0EG 0.02012-04-05
Google Chrome before 18.0.1025.151 allows remote attackers to bypass the Same Origin Policy via vectors related to replacement of IFRAME elements.
- CVE-2011-3072NONECVSS 0.0EG 0.02012-04-05
Google Chrome before 18.0.1025.151 allows remote attackers to bypass the Same Origin Policy via vectors related to pop-up windows.
- CVE-2011-3956NONECVSS 0.0EG 0.02012-02-09
The extension implementation in Google Chrome before 17.0.963.46 does not properly handle sandboxed origins, which might allow remote attackers to bypass the Same Origin Policy via a crafted extension.
- CVE-2012-4193NONECVSS 0.0EG 0.02012-10-12
Mozilla Firefox before 16.0.1, Firefox ESR 10.x before 10.0.9, Thunderbird before 16.0.1, Thunderbird ESR 10.x before 10.0.9, and SeaMonkey before 2.13.1 omit a security check in the defaultValue function during the unwrapping of security …
- CVE-2014-125071MEDIUMCVSS 5.5EG 9.82023-01-09
A vulnerability was found in lukehutch Gribbit. It has been classified as problematic. Affected is the function messageReceived of the file src/gribbit/request/HttpRequestHandler.java. The manipulation leads to missing origin validation in…
- CVE-2014-1487HIGHCVSS 7.5EG 7.52014-02-06
The Web workers implementation in Mozilla Firefox before 27.0, Firefox ESR 24.x before 24.3, Thunderbird before 24.3, and SeaMonkey before 2.24 allows remote attackers to bypass the Same Origin Policy and obtain sensitive authentication in…
- CVE-2014-1502NONECVSS 0.0EG 0.02014-03-19
The (1) WebGL.compressedTexImage2D and (2) WebGL.compressedTexSubImage2D functions in Mozilla Firefox before 28.0 and SeaMonkey before 2.25 allow remote attackers to bypass the Same Origin Policy and render content in a different domain vi…
- CVE-2015-4495HIGHCVSS 8.8EG 9.0⚠ KEV2015-08-08
The PDF reader in Mozilla Firefox before 39.0.3, Firefox ESR 38.x before 38.1.1, and Firefox OS before 2.2 allows remote attackers to bypass the Same Origin Policy, and read arbitrary files or gain privileges, via vectors involving crafted…
- CVE-2016-9902HIGHCVSS 7.5EG 7.52018-06-11
The Pocket toolbar button, once activated, listens for events fired from it's own pages but does not verify the origin of incoming events. This allows content from other origins to fire events and inject content and commands into the Pocke…
- CVE-2017-1000455MEDIUMCVSS 5.5EG 5.52018-01-02
GuixSD prior to Git commit 5e66574a128937e7f2fcf146d146225703ccfd5d used POSIX hard links incorrectly, leading the creation of setuid executables in "the store", violating a fundamental security assumption of GNU Guix.
- CVE-2017-13274CRITICALCVSS 9.8EG 9.82018-04-04
In the getHost() function of UriTest.java, there is the possibility of incorrect web origin determination. This could lead to incorrect security decisions with no additional execution privileges needed. User interaction is not needed for e…
- CVE-2017-18016MEDIUMCVSS 5.3EG 5.32018-01-11
Parity Browser 1.6.10 and earlier allows remote attackers to bypass the Same Origin Policy and obtain sensitive information by requesting other websites via the Parity web proxy engine (reusing the current website's token, which is not bou…
- CVE-2017-20146CRITICALCVSS 9.8EG 9.82022-12-27
Usage of the CORS handler may apply improper CORS headers, allowing the requester to explicitly control the value of the Access-Control-Allow-Origin header, which bypasses the expected behavior of the Same Origin Policy.
- CVE-2017-7797HIGHCVSS 7.5EG 7.52018-06-11
Response header name interning does not have same-origin protections and these headers are stored in a global registry. This allows stored header names to be available cross-origin. This vulnerability affects Firefox < 55.
- CVE-2017-7808MEDIUMCVSS 5.3EG 5.32018-06-11
A content security policy (CSP) "frame-ancestors" directive containing origins with paths allows for comparisons against those paths instead of the origin. This results in a cross-origin information leak of this path information. This vuln…
- CVE-2018-10591MEDIUMCVSS 6.1EG 6.12018-05-15
In Advantech WebAccess versions V8.2_20170817 and prior, WebAccess versions V8.3.0 and prior, WebAccess Dashboard versions V.2.0.15 and prior, WebAccess Scada Node versions prior to 8.3.1, and WebAccess/NMS 2.0.3 and prior, an origin valid…
- CVE-2018-12402MEDIUMCVSS 6.5EG 6.52019-02-28
The internal WebBrowserPersist code does not use correct origin context for a resource being saved. This manifests when sub-resources are loaded as part of "Save Page As..." functionality. For example, a malicious page could recover a visi…
- CVE-2018-14903HIGHCVSS 7.5EG 7.52018-08-30
EPSON WF-2750 printers with firmware JP02I2 do not properly validate files before running updates, which allows remote attackers to cause a printer malfunction or send malicious data to the printer.
- CVE-2018-15723CRITICALCVSS 9.8EG 9.82018-12-20
The Logitech Harmony Hub before version 4.15.206 is vulnerable to application level command injection via crafted HTTP request. An unauthenticated remote attacker can leverage this vulnerability to execute application defined commands (e.g…
- CVE-2018-16072MEDIUMCVSS 6.5EG 6.52019-01-09
A missing origin check related to HLS manifests in Blink in Google Chrome prior to 69.0.3497.81 allowed a remote attacker to bypass same origin policy via a crafted HTML page.
- CVE-2018-18494MEDIUMCVSS 6.5EG 6.52019-02-28
A same-origin policy violation allowing the theft of cross-origin URL entries when using the Javascript location property to cause a redirection to another site using performance.getEntries(). This is a same-origin policy violation and cou…
- CVE-2018-18499MEDIUMCVSS 6.5EG 6.52019-02-28
A same-origin policy violation allowing the theft of cross-origin URL entries when using a meta http-equiv="refresh" on a page to cause a redirection to another site using performance.getEntries(). This is a same-origin policy violation an…
- CVE-2018-20744MEDIUMCVSS 5.9EG 5.92019-01-28
The Olivier Poitrey Go CORS handler through 1.3.0 actively converts a wildcard CORS policy into reflecting an arbitrary Origin header value, which is incompatible with the CORS security design, and could lead to CORS misconfiguration secur…
- CVE-2018-20745MEDIUMCVSS 5.9EG 5.92019-01-28
Yii 2.x through 2.0.15.1 actively converts a wildcard CORS policy into reflecting an arbitrary Origin header value, which is incompatible with the CORS security design, and could lead to CORS misconfiguration security problems.
- CVE-2018-3834HIGHCVSS 7.4EG 7.42018-08-02
An exploitable permanent denial of service vulnerability exists in Insteon Hub running firmware version 1013. The firmware upgrade functionality, triggered via PubNub, retrieves signed firmware binaries using plain HTTP requests. The devic…
- CVE-2018-4319HIGHCVSS 8.1EG 8.12019-04-03
A cross-origin issue existed with "iframe" elements. This was addressed with improved tracking of security origins. This issue affected versions prior to iOS 12, watchOS 5, Safari 12, iTunes 12.9 for Windows, iCloud for Windows 7.7.
- CVE-2018-5109MEDIUMCVSS 5.3EG 5.32018-06-11
An audio capture session can started under an incorrect origin from the site making the capture request. Users are still prompted to allow the request but the prompt can display the wrong origin, leading to user confusion about which site …
- CVE-2018-5116CRITICALCVSS 9.8EG 9.82018-06-11
WebExtensions with the "ActiveTab" permission are able to access frames hosted within the active tab even if the frames are cross-origin. Malicious extensions can inject frames from arbitrary origins into the loaded page and then interact …
- CVE-2018-5157HIGHCVSS 7.5EG 7.52018-06-11
Same-origin protections for the PDF viewer can be bypassed, allowing a malicious site to intercept messages meant for the viewer. This could allow the site to retrieve PDF files restricted to viewing by an authenticated user on a third-par…
- CVE-2018-5400CRITICALCVSS 9.1EG 9.12018-10-08
The Auto-Maskin products utilize an undocumented custom protocol to set up Modbus communications with other devices without validating those devices. The originating device sends a message in plaintext, 48:65:6c:6c:6f:20:57:6f:72:6c:64, "H…
- CVE-2018-5409CRITICALCVSS 9.8EG 9.82019-05-08
The PrinterLogic Print Management software, versions up to and including 18.3.1.96, updates and executes the code without sufficiently verifying the origin and integrity of the code. An attacker can execute malicious code by compromising t…
- CVE-2018-6654HIGHCVSS 8.8EG 8.82018-02-06
The Grammarly extension before 2018-02-02 for Chrome allows remote attackers to discover authentication tokens via an 'action: "user"' request to iframe.gr_-ifr, because the exposure of these tokens is not restricted to any specific web si…
- CVE-2018-6690HIGHCVSS 7.1EG 7.12018-09-18
Accessing, modifying, or executing executable files vulnerability in Microsoft Windows client in McAfee Application and Change Control (MACC) 8.0.0 Hotfix 4 and earlier allows authenticated users to execute arbitrary code via file transfer…
- CVE-2018-6764HIGHCVSS 7.8EG 7.82018-02-23
util/virlog.c in libvirt does not properly determine the hostname on LXC container startup, which allows local guest OS users to bypass an intended container protection mechanism and execute arbitrary commands via a crafted NSS module.
- CVE-2018-8112MEDIUMCVSS 4.3EG 4.32018-05-09
A security feature bypass vulnerability exists when Microsoft Edge improperly handles requests of different origins, aka "Microsoft Edge Security Feature Bypass Vulnerability." This affects Microsoft Edge.
- CVE-2018-8235MEDIUMCVSS 4.3EG 4.32018-06-14
A security feature bypass vulnerability exists when Microsoft Edge improperly handles requests of different origins, aka "Microsoft Edge Security Feature Bypass Vulnerability." This affects Microsoft Edge.
- CVE-2019-11723HIGHCVSS 7.5EG 7.52019-07-23
A vulnerability exists during the installation of add-ons where the initial fetch ignored the origin attributes of the browsing context. This could leak cookies in private browsing mode or across different "containers" for people who use t…
- CVE-2019-11762MEDIUMCVSS 6.1EG 6.12020-01-08
If two same-origin documents set document.domain differently to become cross-origin, it was possible for them to call arbitrary DOM methods/getters/setters on the now-cross-origin window. This vulnerability affects Firefox < 70, Thunderbir…
- CVE-2019-11777HIGHCVSS 7.5EG 7.52019-09-11
In the Eclipse Paho Java client library version 1.2.0, when connecting to an MQTT server using TLS and setting a host name verifier, the result of that verification is not checked. This could allow one MQTT server to impersonate another an…
- CVE-2019-1235HIGHCVSS 7.8EG 7.82019-09-11
An elevation of privilege vulnerability exists in Windows Text Service Framework (TSF) when the TSF server process does not validate the source of input or commands it receives, aka 'Windows Text Service Framework Elevation of Privilege Vu…
- CVE-2019-13664MEDIUMCVSS 6.5EG 6.52019-11-25
Insufficient policy enforcement in Blink in Google Chrome prior to 77.0.3865.75 allowed a remote attacker to bypass content security policy via a crafted HTML page.
- CVE-2019-13740MEDIUMCVSS 6.5EG 6.52019-12-10
Incorrect security UI in sharing in Google Chrome prior to 79.0.3945.79 allowed a remote attacker to perform domain spoofing via a crafted HTML page.
Map vulnerabilities like CWE-346 to your infrastructure
EchelonGraph correlates every CVE — across CWE-346 and 150+ other weakness categories — against the assets you actually run. See blast radius, fix versions, and remediation steps in one graph.
Start Free Scan →