CWE-346
615 CVEs • Abstraction: Class
Origin Validation Error
The product does not properly verify that the source of data or communication is valid.
CVEs (615)
CVE VENDORS PRODUCTS UPDATED PUBLISHED CVSS |
|---|
7Canonical DebianFedoraproject+4 more17Debian Linux Enterprise Linux DesktopEnterprise Linux Eus+14 moreApr 29, 2026 Feb 6, 2014 N/A· v4 7.5 HIGH· v3 5.0 MEDIUM· v2 The Web workers implementation in Mozilla Firefox before 27.0, Firefox ESR 24.x before 24.3, Thunderbird before 24.3, and SeaMonkey before 2.24 allows remote attackers to bypass the Same Origin Policy and obtain sensitiv...Show more |
4Canonical MozillaRedhat+1 more12Enterprise Linux Desktop Enterprise Linux EusEnterprise Linux Server+9 moreApr 29, 2026 Oct 12, 2012 N/A· v4 N/A· v3 6.8 MEDIUM· v2 Mozilla Firefox before 16.0.1, Firefox ESR 10.x before 10.0.9, Thunderbird before 16.0.1, Thunderbird ESR 10.x before 10.0.9, and SeaMonkey before 2.13.1 omit a security check in the defaultValue function during the unwr...Show more |
Google Chrome before 18.0.1025.151 allows remote attackers to bypass the Same Origin Policy via vectors related to pop-up windows. |
Google Chrome before 18.0.1025.151 allows remote attackers to bypass the Same Origin Policy via vectors related to replacement of IFRAME elements. |
3Apple GoogleOpensuse4Chrome Iphone OsOpensuse+1 moreApr 29, 2026 Mar 22, 2012 N/A· v4 N/A· v3 6.8 MEDIUM· v2 Google Chrome before 17.0.963.83 allows remote attackers to bypass the Same Origin Policy via vectors involving a "magic iframe." |
The extension implementation in Google Chrome before 17.0.963.46 does not properly handle sandboxed origins, which might allow remote attackers to bypass the Same Origin Policy via a crafted extension. |
Google V8, as used in Google Chrome before 14.0.835.163, allows remote attackers to bypass the Same Origin Policy via unspecified vectors. |
1Redhat 2Network Satellite Server Spacewalk JavaApr 29, 2026 Jul 27, 2011 N/A· v4 6.8 MEDIUM· v3 6.8 MEDIUM· v2 A flaw was found in Spacewalk Java site packages. This cross-site request forgery (CSRF) vulnerability allows a remote attacker to hijack the authentication of arbitrary users. This can lead to unauthorized actions, incl...Show more |
7Canonical DebianFedoraproject+4 more9Ctpview Debian LinuxFedora+6 moreApr 23, 2026 Apr 17, 2009 N/A· v4 N/A· v3 7.2 HIGH· v2 udev before 1.4.1 does not verify whether a NETLINK message originates from kernel space, which allows local users to gain privileges by sending a NETLINK message from user space. |
Dnsmasq before 2.21 allows remote attackers to poison the DNS cache via answers to queries that were not made by Dnsmasq. |
FreeScripts VisitorBook LE (visitorbook.pl) logs the reverse DNS name of a visiting host, which allows remote attackers to spoof the origin of their incoming requests and facilitate cross-site scripting (XSS) attacks. |
The LDAP name service (nsd) in IRIX 6.5.19 and earlier does not properly verify if the USERPASSWORD attribute has been provided by an LDAP server, which could allow attackers to log in without a password. |
1Microsoft 2Windows 2000 Windows NtApr 16, 2026 Aug 31, 2001 N/A· v4 7.5 HIGH· v3 5.0 MEDIUM· v2 By default, DNS servers on Windows NT 4.0 and Windows 2000 Server cache glue records received from non-delegated name servers, which allows remote attackers to poison the DNS cache via spoofed DNS responses. |
1Microsoft 5Windows 2000 Windows 98Windows 98se+2 moreApr 16, 2026 Apr 14, 2000 N/A· v4 9.8 CRITICAL· v3 7.5 HIGH· v2 The default configuration for the domain name resolver for Microsoft Windows 98, NT 4.0, 2000, and XP sets the QueryIpMatching parameter to 0, which causes Windows to accept DNS updates from hosts that it did not query,...Show more |
Lynx 2.x does not properly distinguish between internal and external HTML, which may allow a local attacker to read a "secure" hidden form value from a temporary file and craft a LYNXOPTIONS: URL that causes Lynx to modi...Show more |