CWE-346
615 CVEs • Abstraction: Class
Origin Validation Error
The product does not properly verify that the source of data or communication is valid.
CVEs (615)
CVE VENDORS PRODUCTS UPDATED PUBLISHED CVSS |
|---|
An issue was discovered in TitanHQ WebTitan before 5.18. It contains a Remote Code Execution issue through which an attacker can execute arbitrary code as root. The issue stems from the hotfix download mechanism, which d...Show more |
1Huawei 4Hisuite Firmware Mate 20 FirmwareP30 Firmware+1 moreJun 17, 2026 Nov 29, 2019 N/A· v4 5.5 MEDIUM· v3 4.3 MEDIUM· v2 P30, P30 Pro, Mate 20 smartphones with software of versions earlier than ELLE-AL00B 9.1.0.193(C00E190R2P1), versions earlier than VOGUE-AL00A 9.1.0.193(C00E190R2P1), versions earlier than Hima-AL00B 9.1.0.135(C00E133R2P1...Show more |
1Huawei 4Hisuite Firmware Mate 20 FirmwareP30 Firmware+1 moreJun 17, 2026 Nov 29, 2019 N/A· v4 5.5 MEDIUM· v3 4.3 MEDIUM· v2 P30, P30 Pro, Mate 20 smartphones with software of versions earlier than ELLE-AL00B 9.1.0.193(C00E190R2P1), versions earlier than VOGUE-AL00A 9.1.0.193(C00E190R2P1), versions earlier than Hima-AL00B 9.1.0.135(C00E133R2P1...Show more |
Insufficient policy enforcement in Blink in Google Chrome prior to 77.0.3865.75 allowed a remote attacker to bypass content security policy via a crafted HTML page. |
1Microsoft 1Office Online Server Jun 17, 2026 Nov 12, 2019 N/A· v4 5.4 MEDIUM· v3 5.8 MEDIUM· v2 A spoofing vulnerability exists when Office Online does not validate origin in cross-origin communications handlers correctly, aka 'Microsoft Office Online Spoofing Vulnerability'. This CVE ID is unique from CVE-2019-144...Show more |
1Microsoft 1Office Online Server Jun 17, 2026 Nov 12, 2019 N/A· v4 5.4 MEDIUM· v3 5.8 MEDIUM· v2 A spoofing vulnerability exists when Office Online does not validate origin in cross-origin communications handlers correctly, aka 'Microsoft Office Online Spoofing Vulnerability'. This CVE ID is unique from CVE-2019-144...Show more |
1Microsoft 1Sharepoint Server Jun 17, 2026 Nov 12, 2019 N/A· v4 5.5 MEDIUM· v3 4.3 MEDIUM· v2 A security feature bypass vulnerability exists when Microsoft Office does not validate URLs.An attacker could send a victim a specially crafted file, which could trick the victim into entering credentials, aka 'Microsoft...Show more |
A security feature bypass vulnerability exists when Microsoft Edge improperly handles extension requests and fails to request host permission for all_urls, aka 'Microsoft Edge Security Feature Bypass Vulnerability'. |
A security vulnerability exists in the Zingbox Inspector versions 1.293 and earlier, that could allow an attacker to supply an invalid software update image to the Zingbox Inspector that could result in command injection...Show more |
1Solarwinds 1Dameware Mini Remote Control Jun 17, 2026 Oct 8, 2019 N/A· v4 9.8 CRITICAL· v3 10.0 HIGH· v2 The Solarwinds Dameware Mini Remote Client agent v12.1.0.89 supports smart card authentication which can allow a user to upload an executable to be executed on the DWRCS.exe host. An unauthenticated, remote attacker can...Show more |
3Canonical DebianW1.fi4Debian Linux HostapdUbuntu Linux+1 moreJun 17, 2026 Sep 12, 2019 N/A· v4 6.5 MEDIUM· v3 3.3 LOW· v2 hostapd before 2.10 and wpa_supplicant before 2.10 allow an incorrect indication of disconnection in certain situations because source address validation is mishandled. This is a denial of service that should have been p...Show more |
1Adobe 2Flash Player Flash Player Desktop RuntimeJun 17, 2026 Sep 12, 2019 N/A· v4 9.8 CRITICAL· v3 10.0 HIGH· v2 Adobe Flash Player 32.0.0.238 and earlier versions, 32.0.0.207 and earlier versions have a Same Origin Method Execution vulnerability. Successful exploitation could lead to Arbitrary Code Execution in the context of the...Show more |
1Microsoft 8Windows 10 Windows 7Windows 8.1+5 moreJun 17, 2026 Sep 11, 2019 N/A· v4 7.8 HIGH· v3 7.2 HIGH· v2 An elevation of privilege vulnerability exists in Windows Text Service Framework (TSF) when the TSF server process does not validate the source of input or commands it receives, aka 'Windows Text Service Framework Elevat...Show more |
4Canonical DebianDino+1 more4Debian Linux DinoFedora+1 moreJun 17, 2026 Sep 11, 2019 N/A· v4 7.5 HIGH· v3 5.0 MEDIUM· v2 Dino before 2019-09-10 does not properly check the source of an MAM message in module/xep/0313_message_archive_management.vala. |
4Canonical DebianDino+1 more4Debian Linux DinoFedora+1 moreJun 17, 2026 Sep 11, 2019 N/A· v4 7.5 HIGH· v3 5.0 MEDIUM· v2 Dino before 2019-09-10 does not properly check the source of a carbons message in module/xep/0280_message_carbons.vala. |
In the Eclipse Paho Java client library version 1.2.0, when connecting to an MQTT server using TLS and setting a host name verifier, the result of that verification is not checked. This could allow one MQTT server to imp...Show more |
1Google 1Nest Cam Iq Indoor Firmware Jun 17, 2026 Aug 20, 2019 N/A· v4 7.5 HIGH· v3 7.8 HIGH· v2 An exploitable denial-of-service vulnerability exists in the Weave error reporting functionality of the Nest Cam IQ Indoor, version 4620002. A specially crafted weave packets can cause an arbitrary Weave Exchange Session...Show more |
1Mozilla 3Firefox Firefox EsrThunderbirdJun 17, 2026 Jul 23, 2019 N/A· v4 5.3 MEDIUM· v3 5.0 MEDIUM· v2 Images from a different domain can be read using a canvas object in some circumstances. This could be used to steal image data from a different site in violation of same-origin policy. This vulnerability affects Thunderb...Show more |
A vulnerability exists during the installation of add-ons where the initial fetch ignored the origin attributes of the browsing context. This could leak cookies in private browsing mode or across different "containers" f...Show more |
4Debian FedoraprojectGoogle+1 more5Backports ChromeDebian Linux+2 moreJun 17, 2026 Jun 27, 2019 N/A· v4 6.5 MEDIUM· v3 4.3 MEDIUM· v2 Insufficient data validation in Blink in Google Chrome prior to 75.0.3770.80 allowed a remote attacker to perform domain spoofing via a crafted HTML page. |