CWE-290
627 CVEs • Abstraction: Base
Authentication Bypass by Spoofing
This attack-focused weakness is caused by incorrectly implemented authentication schemes that are subject to spoofing attacks.
CVEs (627)
CVE VENDORS PRODUCTS UPDATED PUBLISHED CVSS |
|---|
1Sap 1Netweaver Process Integration Jun 17, 2026 Apr 10, 2019 N/A· v4 7.1 HIGH· v3 5.5 MEDIUM· v2 SAP NetWeaver Process Integration (Adapter Engine), fixed in versions 7.10 to 7.11, 7.30, 7.31, 7.40, 7.50; is vulnerable to Digital Signature Spoofing. It is possible to spoof XML signatures and send arbitrary requests...Show more |
A URL spoofing vulnerability was found in all international versions of Xiaomi Mi browser 10.5.6-g (aka the MIUI native browser) and Mint Browser 1.5.3 due to the way they handle the "q" query parameter. The portion of a...Show more |
Cloud Foundry UAA, versions prior to v70.0, allows a user to update their own email address. A remote authenticated user can impersonate a different user by changing their email address to that of a different user. |
MailMate before 1.11.3 mishandles a suspicious HTML/MIME structure in a signed/encrypted email. |
1Express Cart Project 1Express Cart Nov 21, 2024 Feb 1, 2019 N/A· v4 8.8 HIGH· v3 6.5 MEDIUM· v2 A deficiency in the access control in module express-cart <=1.1.5 allows unprivileged users to add new users to the application as administrators. |
Zoom clients on Windows (before version 4.1.34814.1119), Mac OS (before version 4.1.34801.1116), and Linux (2.4.129780.0915 and below) are vulnerable to unauthorized message processing. A remote unauthenticated attacker...Show more |
1Elastic 1Elastic Cloud Enterprise Nov 21, 2024 Sep 19, 2018 N/A· v4 5.3 MEDIUM· v3 3.5 LOW· v2 In Elastic Cloud Enterprise (ECE) versions prior to 1.1.4 it was discovered that a user could scale out allocators on new hosts with an invalid roles token. An attacker with access to the previous runner ID and IP addres...Show more |
A spoofing vulnerability exists when Microsoft Edge improperly handles specific HTML content, aka "Microsoft Edge Spoofing Vulnerability." This affects Microsoft Edge. |
1Ibm 1Websphere Application Server Nov 21, 2024 Sep 6, 2018 N/A· v4 5.6 MEDIUM· v3 6.8 MEDIUM· v2 IBM WebSphere Application Server 7.0, 8.0, and 8.5.5 installations using Form Login could allow a remote attacker to conduct spoofing attacks. IBM X-Force ID: 145769. |
A spoofing vulnerability exists when Microsoft Edge improperly handles specific HTML content, aka "Microsoft Edge Spoofing Vulnerability." This affects Microsoft Edge. This CVE ID is unique from CVE-2018-8383. |
A spoofing vulnerability exists when Microsoft Edge does not properly parse HTTP content, aka "Microsoft Edge Spoofing Vulnerability." This affects Microsoft Edge. This CVE ID is unique from CVE-2018-8388. |
A spoofing vulnerability exists when Microsoft Edge improperly handles specific HTML content, aka "Microsoft Edge Spoofing Vulnerability." This affects Microsoft Edge. |
1Ecos 1System Management Appliance Nov 21, 2024 Jun 17, 2018 N/A· v4 7.4 HIGH· v3 5.8 MEDIUM· v2 Authentication Bypass by Spoofing vulnerability in ECOS System Management Appliance (aka SMA) 5.2.68 allows a man-in-the-middle attacker to compromise authentication keys and configurations via IP spoofing during "Easy E...Show more |
The Node.js inspector, in 6.x and later is vulnerable to a DNS rebinding attack which could be exploited to perform remote code execution. An attack is possible from malicious websites open in a web browser on the same c...Show more |
A spoofing vulnerability exists in Microsoft Exchange Server when Outlook Web Access (OWA) fails to properly handle web requests, aka "Microsoft Exchange Spoofing Vulnerability." This affects Microsoft Exchange Server. |
1Meetcircle 1Circle With Disney Firmware Nov 21, 2024 Apr 5, 2018 N/A· v4 6.5 MEDIUM· v3 3.3 LOW· v2 An exploitable vulnerability exists in the WiFi Access Point feature of Circle with Disney running firmware 2.0.1. A series of WiFi packets can force Circle to setup an Access Point with default credentials. An attacker...Show more |
3Apple CanonicalDebian3Cups Debian LinuxUbuntu LinuxNov 21, 2024 Feb 16, 2018 N/A· v4 7.5 HIGH· v3 5.0 MEDIUM· v2 A localhost.localdomain whitelist entry in valid_host() in scheduler/client.c in CUPS before 2.2.2 allows remote attackers to execute arbitrary IPP commands by sending POST requests to the CUPS daemon in conjunction with...Show more |
A vulnerability has been discovered in the Auth0 passport-wsfed-saml2 library affecting versions < 3.0.5. This vulnerability allows an attacker to impersonate another user and potentially elevate their privileges if the...Show more |
The OhMiBod Remote app for Android and iOS allows remote attackers to impersonate users by sniffing network traffic for search responses from the OhMiBod API server and then editing the username, user_id, and token field...Show more |
1Meetcircle 1Circle With Disney Firmware May 13, 2026 Nov 7, 2017 N/A· v4 6.5 MEDIUM· v3 6.1 MEDIUM· v2 An exploitable vulnerability exists in the WiFi management of Circle with Disney. A crafted Access Point with the same name as the legitimate one can be used to make Circle connect to an untrusted network. An attacker ne...Show more |