← Back
CWE-346

615 CVEs • Abstraction: Class

Origin Validation Error

The product does not properly verify that the source of data or communication is valid.

JSON object

Loading...

CVEs (615)

CVE
VENDORS
PRODUCTS
UPDATED
PUBLISHED
CVSS
1Titanhq
1Webtitan
Jun 17, 2026
Dec 2, 2019
N/A· v4
7.5 HIGH· v3
8.5 HIGH· v2
An issue was discovered in TitanHQ WebTitan before 5.18. It contains a Remote Code Execution issue through which an attacker can execute arbitrary code as root. The issue stems from the hotfix download mechanism, which d...Show more
An issue was discovered in TitanHQ WebTitan before 5.18. It contains a Remote Code Execution issue through which an attacker can execute arbitrary code as root. The issue stems from the hotfix download mechanism, which downloads a shell script via HTTP, and then executes it as root. This is analogous to CVE-2019-6800 but for a different product.Show less
1Huawei
4Hisuite Firmware
Mate 20 FirmwareP30 Firmware+1 more
Jun 17, 2026
Nov 29, 2019
N/A· v4
5.5 MEDIUM· v3
4.3 MEDIUM· v2
P30, P30 Pro, Mate 20 smartphones with software of versions earlier than ELLE-AL00B 9.1.0.193(C00E190R2P1), versions earlier than VOGUE-AL00A 9.1.0.193(C00E190R2P1), versions earlier than Hima-AL00B 9.1.0.135(C00E133R2P1...Show more
P30, P30 Pro, Mate 20 smartphones with software of versions earlier than ELLE-AL00B 9.1.0.193(C00E190R2P1), versions earlier than VOGUE-AL00A 9.1.0.193(C00E190R2P1), versions earlier than Hima-AL00B 9.1.0.135(C00E133R2P1) and HiSuite with versions earlier than HiSuite 9.1.0.305 have a version downgrade vulnerability. The device and HiSuite software do not validate the upgrade package sufficiently, so that the system of smartphone can be downgraded to an older version.Show less
1Huawei
4Hisuite Firmware
Mate 20 FirmwareP30 Firmware+1 more
Jun 17, 2026
Nov 29, 2019
N/A· v4
5.5 MEDIUM· v3
4.3 MEDIUM· v2
P30, P30 Pro, Mate 20 smartphones with software of versions earlier than ELLE-AL00B 9.1.0.193(C00E190R2P1), versions earlier than VOGUE-AL00A 9.1.0.193(C00E190R2P1), versions earlier than Hima-AL00B 9.1.0.135(C00E133R2P1...Show more
P30, P30 Pro, Mate 20 smartphones with software of versions earlier than ELLE-AL00B 9.1.0.193(C00E190R2P1), versions earlier than VOGUE-AL00A 9.1.0.193(C00E190R2P1), versions earlier than Hima-AL00B 9.1.0.135(C00E133R2P1) and HiSuite with versions earlier than HiSuite 9.1.0.305 have a version downgrade vulnerability. The device and HiSuite software do not validate the upgrade package sufficiently, so that the system of smartphone can be downgraded to an older version.Show less
1Google
1Chrome
Jun 17, 2026
Nov 25, 2019
N/A· v4
6.5 MEDIUM· v3
4.3 MEDIUM· v2
Insufficient policy enforcement in Blink in Google Chrome prior to 77.0.3865.75 allowed a remote attacker to bypass content security policy via a crafted HTML page.
1Microsoft
1Office Online Server
Jun 17, 2026
Nov 12, 2019
N/A· v4
5.4 MEDIUM· v3
5.8 MEDIUM· v2
A spoofing vulnerability exists when Office Online does not validate origin in cross-origin communications handlers correctly, aka 'Microsoft Office Online Spoofing Vulnerability'. This CVE ID is unique from CVE-2019-144...Show more
A spoofing vulnerability exists when Office Online does not validate origin in cross-origin communications handlers correctly, aka 'Microsoft Office Online Spoofing Vulnerability'. This CVE ID is unique from CVE-2019-1445.Show less
1Microsoft
1Office Online Server
Jun 17, 2026
Nov 12, 2019
N/A· v4
5.4 MEDIUM· v3
5.8 MEDIUM· v2
A spoofing vulnerability exists when Office Online does not validate origin in cross-origin communications handlers correctly, aka 'Microsoft Office Online Spoofing Vulnerability'. This CVE ID is unique from CVE-2019-144...Show more
A spoofing vulnerability exists when Office Online does not validate origin in cross-origin communications handlers correctly, aka 'Microsoft Office Online Spoofing Vulnerability'. This CVE ID is unique from CVE-2019-1447.Show less
1Microsoft
1Sharepoint Server
Jun 17, 2026
Nov 12, 2019
N/A· v4
5.5 MEDIUM· v3
4.3 MEDIUM· v2
A security feature bypass vulnerability exists when Microsoft Office does not validate URLs.An attacker could send a victim a specially crafted file, which could trick the victim into entering credentials, aka 'Microsoft...Show more
A security feature bypass vulnerability exists when Microsoft Office does not validate URLs.An attacker could send a victim a specially crafted file, which could trick the victim into entering credentials, aka 'Microsoft Office Security Feature Bypass Vulnerability'.Show less
1Microsoft
1Edge
Jun 17, 2026
Nov 12, 2019
N/A· v4
4.3 MEDIUM· v3
4.3 MEDIUM· v2
A security feature bypass vulnerability exists when Microsoft Edge improperly handles extension requests and fails to request host permission for all_urls, aka 'Microsoft Edge Security Feature Bypass Vulnerability'.
1Zingbox
1Inspector
Jun 17, 2026
Oct 9, 2019
N/A· v4
9.8 CRITICAL· v3
7.5 HIGH· v2
A security vulnerability exists in the Zingbox Inspector versions 1.293 and earlier, that could allow an attacker to supply an invalid software update image to the Zingbox Inspector that could result in command injection...Show more
A security vulnerability exists in the Zingbox Inspector versions 1.293 and earlier, that could allow an attacker to supply an invalid software update image to the Zingbox Inspector that could result in command injection.Show less
1Solarwinds
1Dameware Mini Remote Control
Jun 17, 2026
Oct 8, 2019
N/A· v4
9.8 CRITICAL· v3
10.0 HIGH· v2
The Solarwinds Dameware Mini Remote Client agent v12.1.0.89 supports smart card authentication which can allow a user to upload an executable to be executed on the DWRCS.exe host. An unauthenticated, remote attacker can...Show more
The Solarwinds Dameware Mini Remote Client agent v12.1.0.89 supports smart card authentication which can allow a user to upload an executable to be executed on the DWRCS.exe host. An unauthenticated, remote attacker can request smart card login and upload and execute an arbitrary executable run under the Local System account.Show less
3Canonical
DebianW1.fi
4Debian Linux
HostapdUbuntu Linux+1 more
Jun 17, 2026
Sep 12, 2019
N/A· v4
6.5 MEDIUM· v3
3.3 LOW· v2
hostapd before 2.10 and wpa_supplicant before 2.10 allow an incorrect indication of disconnection in certain situations because source address validation is mishandled. This is a denial of service that should have been p...Show more
hostapd before 2.10 and wpa_supplicant before 2.10 allow an incorrect indication of disconnection in certain situations because source address validation is mishandled. This is a denial of service that should have been prevented by PMF (aka management frame protection). The attacker must send a crafted 802.11 frame from a location that is within the 802.11 communications range.Show less
1Adobe
2Flash Player
Flash Player Desktop Runtime
Jun 17, 2026
Sep 12, 2019
N/A· v4
9.8 CRITICAL· v3
10.0 HIGH· v2
Adobe Flash Player 32.0.0.238 and earlier versions, 32.0.0.207 and earlier versions have a Same Origin Method Execution vulnerability. Successful exploitation could lead to Arbitrary Code Execution in the context of the...Show more
Adobe Flash Player 32.0.0.238 and earlier versions, 32.0.0.207 and earlier versions have a Same Origin Method Execution vulnerability. Successful exploitation could lead to Arbitrary Code Execution in the context of the current user.Show less
1Microsoft
8Windows 10
Windows 7Windows 8.1+5 more
Jun 17, 2026
Sep 11, 2019
N/A· v4
7.8 HIGH· v3
7.2 HIGH· v2
An elevation of privilege vulnerability exists in Windows Text Service Framework (TSF) when the TSF server process does not validate the source of input or commands it receives, aka 'Windows Text Service Framework Elevat...Show more
An elevation of privilege vulnerability exists in Windows Text Service Framework (TSF) when the TSF server process does not validate the source of input or commands it receives, aka 'Windows Text Service Framework Elevation of Privilege Vulnerability'.Show less
4Canonical
DebianDino+1 more
4Debian Linux
DinoFedora+1 more
Jun 17, 2026
Sep 11, 2019
N/A· v4
7.5 HIGH· v3
5.0 MEDIUM· v2
Dino before 2019-09-10 does not properly check the source of an MAM message in module/xep/0313_message_archive_management.vala.
4Canonical
DebianDino+1 more
4Debian Linux
DinoFedora+1 more
Jun 17, 2026
Sep 11, 2019
N/A· v4
7.5 HIGH· v3
5.0 MEDIUM· v2
Dino before 2019-09-10 does not properly check the source of a carbons message in module/xep/0280_message_carbons.vala.
1Eclipse
1Paho Java Client
Jun 17, 2026
Sep 11, 2019
N/A· v4
7.5 HIGH· v3
5.0 MEDIUM· v2
In the Eclipse Paho Java client library version 1.2.0, when connecting to an MQTT server using TLS and setting a host name verifier, the result of that verification is not checked. This could allow one MQTT server to imp...Show more
In the Eclipse Paho Java client library version 1.2.0, when connecting to an MQTT server using TLS and setting a host name verifier, the result of that verification is not checked. This could allow one MQTT server to impersonate another and provide the client library with incorrect information.Show less
1Google
1Nest Cam Iq Indoor Firmware
Jun 17, 2026
Aug 20, 2019
N/A· v4
7.5 HIGH· v3
7.8 HIGH· v2
An exploitable denial-of-service vulnerability exists in the Weave error reporting functionality of the Nest Cam IQ Indoor, version 4620002. A specially crafted weave packets can cause an arbitrary Weave Exchange Session...Show more
An exploitable denial-of-service vulnerability exists in the Weave error reporting functionality of the Nest Cam IQ Indoor, version 4620002. A specially crafted weave packets can cause an arbitrary Weave Exchange Session to close, resulting in a denial of service. An attacker can send a specially crafted packet to trigger this vulnerability.Show less
1Mozilla
3Firefox
Firefox EsrThunderbird
Jun 17, 2026
Jul 23, 2019
N/A· v4
5.3 MEDIUM· v3
5.0 MEDIUM· v2
Images from a different domain can be read using a canvas object in some circumstances. This could be used to steal image data from a different site in violation of same-origin policy. This vulnerability affects Thunderb...Show more
Images from a different domain can be read using a canvas object in some circumstances. This could be used to steal image data from a different site in violation of same-origin policy. This vulnerability affects Thunderbird < 60.7, Firefox < 67, and Firefox ESR < 60.7.Show less
2Mozilla
Opensuse
2Firefox
Leap
Jun 17, 2026
Jul 23, 2019
N/A· v4
7.5 HIGH· v3
5.0 MEDIUM· v2
A vulnerability exists during the installation of add-ons where the initial fetch ignored the origin attributes of the browsing context. This could leak cookies in private browsing mode or across different "containers" f...Show more
A vulnerability exists during the installation of add-ons where the initial fetch ignored the origin attributes of the browsing context. This could leak cookies in private browsing mode or across different "containers" for people who use the Firefox Multi-Account Containers Web Extension. This vulnerability affects Firefox < 68.Show less
4Debian
FedoraprojectGoogle+1 more
5Backports
ChromeDebian Linux+2 more
Jun 17, 2026
Jun 27, 2019
N/A· v4
6.5 MEDIUM· v3
4.3 MEDIUM· v2
Insufficient data validation in Blink in Google Chrome prior to 75.0.3770.80 allowed a remote attacker to perform domain spoofing via a crafted HTML page.