← Back
CWE-346

615 CVEs • Abstraction: Class

Origin Validation Error

The product does not properly verify that the source of data or communication is valid.

JSON object

Loading...

CVEs (615)

CVE
VENDORS
PRODUCTS
UPDATED
PUBLISHED
CVSS
7Canonical
DebianFedoraproject+4 more
17Debian Linux
Enterprise Linux DesktopEnterprise Linux Eus+14 more
Apr 29, 2026
Feb 6, 2014
N/A· v4
7.5 HIGH· v3
5.0 MEDIUM· v2
The Web workers implementation in Mozilla Firefox before 27.0, Firefox ESR 24.x before 24.3, Thunderbird before 24.3, and SeaMonkey before 2.24 allows remote attackers to bypass the Same Origin Policy and obtain sensitiv...Show more
The Web workers implementation in Mozilla Firefox before 27.0, Firefox ESR 24.x before 24.3, Thunderbird before 24.3, and SeaMonkey before 2.24 allows remote attackers to bypass the Same Origin Policy and obtain sensitive authentication information via vectors involving error messages.Show less
4Canonical
MozillaRedhat+1 more
12Enterprise Linux Desktop
Enterprise Linux EusEnterprise Linux Server+9 more
Apr 29, 2026
Oct 12, 2012
N/A· v4
N/A· v3
6.8 MEDIUM· v2
Mozilla Firefox before 16.0.1, Firefox ESR 10.x before 10.0.9, Thunderbird before 16.0.1, Thunderbird ESR 10.x before 10.0.9, and SeaMonkey before 2.13.1 omit a security check in the defaultValue function during the unwr...Show more
Mozilla Firefox before 16.0.1, Firefox ESR 10.x before 10.0.9, Thunderbird before 16.0.1, Thunderbird ESR 10.x before 10.0.9, and SeaMonkey before 2.13.1 omit a security check in the defaultValue function during the unwrapping of security wrappers, which allows remote attackers to bypass the Same Origin Policy and read the properties of a Location object, or execute arbitrary JavaScript code, via a crafted web site.Show less
1Google
1Chrome
Apr 29, 2026
Apr 5, 2012
N/A· v4
N/A· v3
6.8 MEDIUM· v2
Google Chrome before 18.0.1025.151 allows remote attackers to bypass the Same Origin Policy via vectors related to pop-up windows.
2Apple
Google
3Chrome
Iphone OsSafari
Apr 29, 2026
Apr 5, 2012
N/A· v4
N/A· v3
6.8 MEDIUM· v2
Google Chrome before 18.0.1025.151 allows remote attackers to bypass the Same Origin Policy via vectors related to replacement of IFRAME elements.
3Apple
GoogleOpensuse
4Chrome
Iphone OsOpensuse+1 more
Apr 29, 2026
Mar 22, 2012
N/A· v4
N/A· v3
6.8 MEDIUM· v2
Google Chrome before 17.0.963.83 allows remote attackers to bypass the Same Origin Policy via vectors involving a "magic iframe."
1Google
1Chrome
Apr 29, 2026
Feb 9, 2012
N/A· v4
N/A· v3
6.8 MEDIUM· v2
The extension implementation in Google Chrome before 17.0.963.46 does not properly handle sandboxed origins, which might allow remote attackers to bypass the Same Origin Policy via a crafted extension.
1Google
1Chrome
Apr 29, 2026
Sep 19, 2011
N/A· v4
N/A· v3
7.5 HIGH· v2
Google V8, as used in Google Chrome before 14.0.835.163, allows remote attackers to bypass the Same Origin Policy via unspecified vectors.
1Redhat
2Network Satellite Server
Spacewalk Java
Apr 29, 2026
Jul 27, 2011
N/A· v4
6.8 MEDIUM· v3
6.8 MEDIUM· v2
A flaw was found in Spacewalk Java site packages. This cross-site request forgery (CSRF) vulnerability allows a remote attacker to hijack the authentication of arbitrary users. This can lead to unauthorized actions, incl...Show more
A flaw was found in Spacewalk Java site packages. This cross-site request forgery (CSRF) vulnerability allows a remote attacker to hijack the authentication of arbitrary users. This can lead to unauthorized actions, including disabling user accounts, adding new user accounts, or escalating privileges by modifying existing user accounts to have administrator access.Show less
7Canonical
DebianFedoraproject+4 more
9Ctpview
Debian LinuxFedora+6 more
Apr 23, 2026
Apr 17, 2009
N/A· v4
N/A· v3
7.2 HIGH· v2
udev before 1.4.1 does not verify whether a NETLINK message originates from kernel space, which allows local users to gain privileges by sending a NETLINK message from user space.
1Thekelleys
1Dnsmasq
Apr 16, 2026
May 2, 2005
N/A· v4
7.5 HIGH· v3
5.0 MEDIUM· v2
Dnsmasq before 2.21 allows remote attackers to poison the DNS cache via answers to queries that were not made by Dnsmasq.
1Freescripts
1Visitorbook Le
Apr 16, 2026
Jan 5, 2004
N/A· v4
6.1 MEDIUM· v3
4.3 MEDIUM· v2
FreeScripts VisitorBook LE (visitorbook.pl) logs the reverse DNS name of a visiting host, which allows remote attackers to spoof the origin of their incoming requests and facilitate cross-site scripting (XSS) attacks.
1Sgi
1Irix
Apr 16, 2026
May 12, 2003
N/A· v4
9.8 CRITICAL· v3
7.5 HIGH· v2
The LDAP name service (nsd) in IRIX 6.5.19 and earlier does not properly verify if the USERPASSWORD attribute has been provided by an LDAP server, which could allow attackers to log in without a password.
1Microsoft
2Windows 2000
Windows Nt
Apr 16, 2026
Aug 31, 2001
N/A· v4
7.5 HIGH· v3
5.0 MEDIUM· v2
By default, DNS servers on Windows NT 4.0 and Windows 2000 Server cache glue records received from non-delegated name servers, which allows remote attackers to poison the DNS cache via spoofed DNS responses.
1Microsoft
5Windows 2000
Windows 98Windows 98se+2 more
Apr 16, 2026
Apr 14, 2000
N/A· v4
9.8 CRITICAL· v3
7.5 HIGH· v2
The default configuration for the domain name resolver for Microsoft Windows 98, NT 4.0, 2000, and XP sets the QueryIpMatching parameter to 0, which causes Windows to accept DNS updates from hosts that it did not query,...Show more
The default configuration for the domain name resolver for Microsoft Windows 98, NT 4.0, 2000, and XP sets the QueryIpMatching parameter to 0, which causes Windows to accept DNS updates from hosts that it did not query, which allows remote attackers to poison the DNS cache.Show less
1Lynx Project
1Lynx
Apr 16, 2026
Nov 16, 1999
N/A· v4
7.8 HIGH· v3
5.0 MEDIUM· v2
Lynx 2.x does not properly distinguish between internal and external HTML, which may allow a local attacker to read a "secure" hidden form value from a temporary file and craft a LYNXOPTIONS: URL that causes Lynx to modi...Show more
Lynx 2.x does not properly distinguish between internal and external HTML, which may allow a local attacker to read a "secure" hidden form value from a temporary file and craft a LYNXOPTIONS: URL that causes Lynx to modify the user's configuration file and execute commands.Show less