CWE-346— Origin Validation Error
468 active CVEs classified under this weakness category. Sourced from NVD, GHSA, and vendor advisories. Full definition on MITRE →
CVEs classified under CWE-346page 2 of 10
- CVE-2019-1413MEDIUMCVSS 4.3EG 4.32019-11-12
A security feature bypass vulnerability exists when Microsoft Edge improperly handles extension requests and fails to request host permission for all_urls, aka 'Microsoft Edge Security Feature Bypass Vulnerability'.
- CVE-2019-1442MEDIUMCVSS 5.5EG 5.52019-11-12
A security feature bypass vulnerability exists when Microsoft Office does not validate URLs.An attacker could send a victim a specially crafted file, which could trick the victim into entering credentials, aka 'Microsoft Office Security Fe…
- CVE-2019-1445MEDIUMCVSS 5.4EG 5.42019-11-12
A spoofing vulnerability exists when Office Online does not validate origin in cross-origin communications handlers correctly, aka 'Microsoft Office Online Spoofing Vulnerability'. This CVE ID is unique from CVE-2019-1447.
- CVE-2019-1447MEDIUMCVSS 5.4EG 5.42019-11-12
A spoofing vulnerability exists when Office Online does not validate origin in cross-origin communications handlers correctly, aka 'Microsoft Office Online Spoofing Vulnerability'. This CVE ID is unique from CVE-2019-1445.
- CVE-2019-15020CRITICALCVSS 9.8EG 9.82019-10-09
A security vulnerability exists in the Zingbox Inspector versions 1.293 and earlier, that could allow an attacker to supply an invalid software update image to the Zingbox Inspector that could result in command injection.
- CVE-2019-16235HIGHCVSS 7.5EG 7.52019-09-11
Dino before 2019-09-10 does not properly check the source of a carbons message in module/xep/0280_message_carbons.vala.
- CVE-2019-16237HIGHCVSS 7.5EG 7.52019-09-11
Dino before 2019-09-10 does not properly check the source of an MAM message in module/xep/0313_message_archive_management.vala.
- CVE-2019-16275MEDIUMCVSS 6.5EG 6.52019-09-12
hostapd before 2.10 and wpa_supplicant before 2.10 allow an incorrect indication of disconnection in certain situations because source address validation is mishandled. This is a denial of service that should have been prevented by PMF (ak…
- CVE-2019-16517CRITICALCVSS 9.8EG 9.82020-01-23
An issue was discovered in ConnectWise Control (formerly known as ScreenConnect) 19.3.25270.7185. There is a CORS misconfiguration, which reflected the Origin provided by incoming requests. This allowed JavaScript running on any domain to …
- CVE-2019-18381MEDIUMCVSS 6.3EG 6.32019-12-05
Norton Password Manager, prior to 6.6.2.5, may be susceptible to a cross origin resource sharing (CORS) vulnerability, which is a type of issue that allows restricted resources on a web page to be requested from another domain outside the …
- CVE-2019-19019HIGHCVSS 7.5EG 7.52019-12-02
An issue was discovered in TitanHQ WebTitan before 5.18. It contains a Remote Code Execution issue through which an attacker can execute arbitrary code as root. The issue stems from the hotfix download mechanism, which downloads a shell sc…
- CVE-2019-19545MEDIUMCVSS 6.3EG 6.32019-12-05
Norton Password Manager, prior to 6.6.2.5, may be susceptible to a cross origin resource sharing (CORS) vulnerability, which is a type of issue that allows restricted resources on a web page to be requested from another domain outside the …
- CVE-2019-20329HIGHCVSS 8.1EG 8.12020-01-03
OpenLambda 2019-09-10 allows DNS rebinding attacks against the OL server for the REST API on TCP port 5000.
- CVE-2019-25211CRITICALCVSS 9.1EG 9.12024-06-29
parseWildcardRules in Gin-Gonic CORS middleware before 1.6.0 mishandles a wildcard at the end of an origin string, e.g., https://example.community/* is allowed when the intention is that only https://example.com/* should be allowed, and ht…
- CVE-2019-3980CRITICALCVSS 9.8EG 9.82019-10-08
The Solarwinds Dameware Mini Remote Client agent v12.1.0.89 supports smart card authentication which can allow a user to upload an executable to be executed on the DWRCS.exe host. An unauthenticated, remote attacker can request smart card …
- CVE-2019-4640CRITICALCVSS 9.8EG 9.82020-02-19
IBM Security Secret Server 10.7 processes patches, image backups and other updates without sufficiently verifying the origin and integrity of the code which could result in an attacker executing malicious code. IBM X-Force ID: 170046.
- CVE-2019-5036HIGHCVSS 7.5EG 7.52019-08-20
An exploitable denial-of-service vulnerability exists in the Weave error reporting functionality of the Nest Cam IQ Indoor, version 4620002. A specially crafted weave packets can cause an arbitrary Weave Exchange Session to close, resultin…
- CVE-2019-5062MEDIUMCVSS 6.5EG 6.52019-12-12
An exploitable denial-of-service vulnerability exists in the 802.11w security state handling for hostapd 2.6 connected clients with valid 802.11w sessions. By simulating an incomplete new association, an attacker can trigger a deauthentica…
- CVE-2019-5226MEDIUMCVSS 5.5EG 5.52019-11-29
P30, P30 Pro, Mate 20 smartphones with software of versions earlier than ELLE-AL00B 9.1.0.193(C00E190R2P1), versions earlier than VOGUE-AL00A 9.1.0.193(C00E190R2P1), versions earlier than Hima-AL00B 9.1.0.135(C00E133R2P1) and HiSuite with …
- CVE-2019-5227MEDIUMCVSS 5.5EG 5.52019-11-29
P30, P30 Pro, Mate 20 smartphones with software of versions earlier than ELLE-AL00B 9.1.0.193(C00E190R2P1), versions earlier than VOGUE-AL00A 9.1.0.193(C00E190R2P1), versions earlier than Hima-AL00B 9.1.0.135(C00E133R2P1) and HiSuite with …
- CVE-2019-5773MEDIUMCVSS 6.5EG 6.52019-02-19
Insufficient origin validation in IndexedDB in Google Chrome prior to 72.0.3626.81 allowed a remote attacker who had compromised the renderer process to bypass same origin policy via a crafted HTML page.
- CVE-2019-5834MEDIUMCVSS 6.5EG 6.52019-06-27
Insufficient data validation in Blink in Google Chrome prior to 75.0.3770.80 allowed a remote attacker to perform domain spoofing via a crafted HTML page.
- CVE-2019-7399HIGHCVSS 7.4EG 7.42019-02-17
Amazon Fire OS before 5.3.6.4 allows a man-in-the-middle attack against HTTP requests for "Terms of Use" and Privacy pages.
- CVE-2019-8069CRITICALCVSS 9.8EG 9.82019-09-12
Adobe Flash Player 32.0.0.238 and earlier versions, 32.0.0.207 and earlier versions have a Same Origin Method Execution vulnerability. Successful exploitation could lead to Arbitrary Code Execution in the context of the current user.
- CVE-2019-8075HIGHCVSS 7.5EG 7.52019-09-27
Adobe Flash Player version 32.0.0.192 and earlier versions have a Same Origin Policy Bypass vulnerability. Successful exploitation could lead to Information Disclosure in the context of the current user.
- CVE-2019-8282MEDIUMCVSS 5.3EG 5.32019-06-07
Gemalto Admin Control Center, all versions prior to 7.92, uses cleartext HTTP to communicate with www3.safenet-inc.com to obtain language packs. This allows attacker to do man-in-the-middle (MITM) attack and replace original language pack …
- CVE-2019-8754MEDIUMCVSS 6.5EG 6.52020-10-27
A cross-origin issue existed with "iframe" elements. This was addressed with improved tracking of security origins. This issue is fixed in macOS Catalina 10.15.1, Security Update 2019-001, and Security Update 2019-006. A malicious HTML doc…
- CVE-2019-9498HIGHCVSS 8.1EG 8.12019-04-17
The implementations of EAP-PWD in hostapd EAP Server, when built against a crypto library missing explicit validation on imported elements, do not validate the scalar and element values in EAP-pwd-Commit. An attacker may be able to use inv…
- CVE-2019-9499HIGHCVSS 8.1EG 8.12019-04-17
The implementations of EAP-PWD in wpa_supplicant EAP Peer, when built against a crypto library missing explicit validation on imported elements, do not validate the scalar and element values in EAP-pwd-Commit. An attacker may complete auth…
- CVE-2019-9764HIGHCVSS 7.4EG 7.42019-03-26
HashiCorp Consul 1.4.3 lacks server hostname verification for agent-to-agent TLS communication. In other words, the product behaves as if verify_server_hostname were set to false, even when it is actually set to true. This is fixed in 1.4.…
- CVE-2019-9797MEDIUMCVSS 5.3EG 5.32019-04-26
Cross-origin images can be read in violation of the same-origin policy by exporting an image after using createImageBitmap to read the image and then rendering the resulting bitmap image within a canvas element. This vulnerability affects …
- CVE-2019-9803HIGHCVSS 7.4EG 7.42019-04-26
The Upgrade-Insecure-Requests (UIR) specification states that if UIR is enabled through Content Security Policy (CSP), navigation to a same-origin URL must be upgraded to HTTPS. Firefox will incorrectly navigate to an HTTP URL rather than …
- CVE-2019-9808MEDIUMCVSS 5.3EG 5.32019-04-26
If WebRTC permission is requested from documents with data: or blob: URLs, the permission notifications do not properly display the originating domain. The notification states "Unknown origin" as the requestee, leading to user confusion ab…
- CVE-2019-9817MEDIUMCVSS 5.3EG 5.32019-07-23
Images from a different domain can be read using a canvas object in some circumstances. This could be used to steal image data from a different site in violation of same-origin policy. This vulnerability affects Thunderbird < 60.7, Firefox…
- CVE-2020-0647MEDIUMCVSS 5.4EG 5.42020-01-14
A spoofing vulnerability exists when Office Online does not validate origin in cross-origin communications correctly, aka 'Microsoft Office Online Spoofing Vulnerability'.
- CVE-2020-0695MEDIUMCVSS 5.4EG 5.42020-02-11
A spoofing vulnerability exists when Office Online Server does not validate origin in cross-origin communications correctly, aka 'Microsoft Office Online Server Spoofing Vulnerability'.
- CVE-2020-11069HIGHCVSS 8.0EG 8.02020-05-14
In TYPO3 CMS 9.0.0 through 9.5.16 and 10.0.0 through 10.4.1, it has been discovered that the backend user interface and install tool are vulnerable to a same-site request forgery. A backend user can be tricked into interacting with a malic…
- CVE-2020-11868HIGHCVSS 7.5EG 7.52020-04-17
ntpd in ntp before 4.2.8p14 and 4.3.x before 4.3.100 allows an off-path attacker to block unauthenticated synchronization via a server mode packet with a spoofed source IP address, because transmissions are rescheduled even when a packet l…
- CVE-2020-12397MEDIUMCVSS 4.3EG 4.32020-05-22
By encoding Unicode whitespace characters within the From email header, an attacker can spoof the sender email address that Thunderbird displays. This vulnerability affects Thunderbird < 68.8.0.
- CVE-2020-1408HIGHCVSS 8.8EG 8.82020-07-14
A remote code execution vulnerability exists when the Windows font library improperly handles specially crafted embedded fonts, aka 'Microsoft Graphics Remote Code Execution Vulnerability'.
- CVE-2020-14456HIGHCVSS 7.3EG 7.32020-06-19
An issue was discovered in Mattermost Desktop App before 4.4.0. The Same Origin Policy is mishandled during access-control decisions for web APIs, aka MMSA-2020-0006.
- CVE-2020-1449HIGHCVSS 7.8EG 7.82020-07-14
A remote code execution vulnerability exists in Microsoft Project software when the software fails to check the source markup of a file, aka 'Microsoft Project Remote Code Execution Vulnerability'.
- CVE-2020-14519HIGHCVSS 7.5EG 7.52020-09-16
This vulnerability allows an attacker to use the internal WebSockets API for CodeMeter (All versions prior to 7.00 are affected, including Version 7.0 or newer with the affected WebSockets API still enabled. This is especially relevant for…
- CVE-2020-15104MEDIUMCVSS 4.6EG 4.62020-07-14
In Envoy before versions 1.12.6, 1.13.4, 1.14.4, and 1.15.0 when validating TLS certificates, Envoy would incorrectly allow a wildcard DNS Subject Alternative Name apply to multiple subdomains. For example, with a SAN of *.example.com, Env…
- CVE-2020-15652MEDIUMCVSS 6.5EG 6.52020-08-10
By observing the stack trace for JavaScript errors in web workers, it was possible to leak the result of a cross-origin redirect. This applied only to content that can be parsed as script. This vulnerability affects Firefox < 79, Firefox E…
- CVE-2020-15682MEDIUMCVSS 6.5EG 6.52020-10-22
When a link to an external protocol was clicked, a prompt was presented that allowed the user to choose what application to open it in. An attacker could induce that prompt to be associated with an origin they didn't control, resulting in …
- CVE-2020-15733MEDIUMCVSS 6.5EG 6.52020-12-14
An Origin Validation Error vulnerability in the SafePay component of Bitdefender Antivirus Plus allows a web resource to misrepresent itself in the URL bar. This issue affects: Bitdefender Antivirus Plus versions prior to 25.0.7.29.
- CVE-2020-15734MEDIUMCVSS 5.5EG 5.52021-04-12
An Origin Validation Error vulnerability in Bitdefender Safepay allows an attacker to manipulate the browser's file upload capability into accessing other files in the same directory or sub-directories. This issue affects: Bitdefender Safe…
- CVE-2020-15773MEDIUMCVSS 6.5EG 6.52020-09-18
An issue was discovered in Gradle Enterprise before 2020.2.4. Because of unrestricted cross-origin requests to read-only data in the Export API, an attacker can access data as a user (for the duration of the browser session) after previous…
- CVE-2020-16168MEDIUMCVSS 6.5EG 6.52020-08-07
Origin Validation Error in temi Robox OS prior to 120, temi Android app up to 1.3.7931 allows remote attackers to access the REST API and MQTT broker used by the temi and send it custom data/requests via unspecified vectors.
Map vulnerabilities like CWE-346 to your infrastructure
EchelonGraph correlates every CVE — across CWE-346 and 150+ other weakness categories — against the assets you actually run. See blast radius, fix versions, and remediation steps in one graph.
Start Free Scan →