CWE-346
746 CVEs • Abstraction: Class
Origin Validation Error
The product does not properly verify that the source of data or communication is valid.
CVEs (746)
CVE VENDORS PRODUCTS UPDATED PUBLISHED CVSS |
|---|
1Solarwinds 1Dameware Mini Remote Control Jun 17, 2026 Oct 8, 2019 N/A· v4 9.8 CRITICAL· v3 10.0 HIGH· v2 The Solarwinds Dameware Mini Remote Client agent v12.1.0.89 supports smart card authentication which can allow a user to upload an executable to be executed on the DWRCS.exe host. An unauthenticated, remote attacker can...Show more |
3Canonical DebianW1.fi4Debian Linux HostapdUbuntu Linux+1 moreJun 17, 2026 Sep 12, 2019 N/A· v4 6.5 MEDIUM· v3 3.3 LOW· v2 hostapd before 2.10 and wpa_supplicant before 2.10 allow an incorrect indication of disconnection in certain situations because source address validation is mishandled. This is a denial of service that should have been p...Show more |
1Adobe 2Flash Player Flash Player Desktop RuntimeJun 17, 2026 Sep 12, 2019 N/A· v4 9.8 CRITICAL· v3 10.0 HIGH· v2 Adobe Flash Player 32.0.0.238 and earlier versions, 32.0.0.207 and earlier versions have a Same Origin Method Execution vulnerability. Successful exploitation could lead to Arbitrary Code Execution in the context of the...Show more |
1Microsoft 8Windows 10 Windows 7Windows 8.1+5 moreJun 17, 2026 Sep 11, 2019 N/A· v4 7.8 HIGH· v3 7.2 HIGH· v2 An elevation of privilege vulnerability exists in Windows Text Service Framework (TSF) when the TSF server process does not validate the source of input or commands it receives, aka 'Windows Text Service Framework Elevat...Show more |
4Canonical DebianDino+1 more4Debian Linux DinoFedora+1 moreJun 17, 2026 Sep 11, 2019 N/A· v4 7.5 HIGH· v3 5.0 MEDIUM· v2 Dino before 2019-09-10 does not properly check the source of an MAM message in module/xep/0313_message_archive_management.vala. |
4Canonical DebianDino+1 more4Debian Linux DinoFedora+1 moreJun 17, 2026 Sep 11, 2019 N/A· v4 7.5 HIGH· v3 5.0 MEDIUM· v2 Dino before 2019-09-10 does not properly check the source of a carbons message in module/xep/0280_message_carbons.vala. |
In the Eclipse Paho Java client library version 1.2.0, when connecting to an MQTT server using TLS and setting a host name verifier, the result of that verification is not checked. This could allow one MQTT server to imp...Show more |
1Google 1Nest Cam Iq Indoor Firmware Jun 17, 2026 Aug 20, 2019 N/A· v4 7.5 HIGH· v3 7.8 HIGH· v2 An exploitable denial-of-service vulnerability exists in the Weave error reporting functionality of the Nest Cam IQ Indoor, version 4620002. A specially crafted weave packets can cause an arbitrary Weave Exchange Session...Show more |
1Mozilla 3Firefox Firefox EsrThunderbirdJun 17, 2026 Jul 23, 2019 N/A· v4 5.3 MEDIUM· v3 5.0 MEDIUM· v2 Images from a different domain can be read using a canvas object in some circumstances. This could be used to steal image data from a different site in violation of same-origin policy. This vulnerability affects Thunderb...Show more |
A vulnerability exists during the installation of add-ons where the initial fetch ignored the origin attributes of the browsing context. This could leak cookies in private browsing mode or across different "containers" f...Show more |
4Debian FedoraprojectGoogle+1 more5Backports ChromeDebian Linux+2 moreJun 17, 2026 Jun 27, 2019 N/A· v4 6.5 MEDIUM· v3 4.3 MEDIUM· v2 Insufficient data validation in Blink in Google Chrome prior to 75.0.3770.80 allowed a remote attacker to perform domain spoofing via a crafted HTML page. |
Gemalto Admin Control Center, all versions prior to 7.92, uses cleartext HTTP to communicate with www3.safenet-inc.com to obtain language packs. This allows attacker to do man-in-the-middle (MITM) attack and replace orig...Show more |
1Printerlogic 1Print Management Jun 17, 2026 May 8, 2019 N/A· v4 9.8 CRITICAL· v3 10.0 HIGH· v2 The PrinterLogic Print Management software, versions up to and including 18.3.1.96, updates and executes the code without sufficiently verifying the origin and integrity of the code. An attacker can execute malicious cod...Show more |
If WebRTC permission is requested from documents with data: or blob: URLs, the permission notifications do not properly display the originating domain. The notification states "Unknown origin" as the requestee, leading t...Show more |
The Upgrade-Insecure-Requests (UIR) specification states that if UIR is enabled through Content Security Policy (CSP), navigation to a same-origin URL must be upgraded to HTTPS. Firefox will incorrectly navigate to an HT...Show more |
Cross-origin images can be read in violation of the same-origin policy by exporting an image after using createImageBitmap to read the image and then rendering the resulting bitmap image within a canvas element. This vul...Show more |
6Debian FedoraprojectFreebsd+3 more9Backports Sle Debian LinuxFedora+6 moreJun 17, 2026 Apr 17, 2019 N/A· v4 8.1 HIGH· v3 6.8 MEDIUM· v2 The implementations of EAP-PWD in wpa_supplicant EAP Peer, when built against a crypto library missing explicit validation on imported elements, do not validate the scalar and element values in EAP-pwd-Commit. An attacke...Show more |
6Debian FedoraprojectFreebsd+3 more9Backports Sle Debian LinuxFedora+6 moreJun 17, 2026 Apr 17, 2019 N/A· v4 8.1 HIGH· v3 6.8 MEDIUM· v2 The implementations of EAP-PWD in hostapd EAP Server, when built against a crypto library missing explicit validation on imported elements, do not validate the scalar and element values in EAP-pwd-Commit. An attacker may...Show more |
1Apple 4Icloud Iphone OsItunes+1 moreNov 21, 2024 Apr 3, 2019 N/A· v4 8.1 HIGH· v3 5.8 MEDIUM· v2 A cross-origin issue existed with "iframe" elements. This was addressed with improved tracking of security origins. This issue affected versions prior to iOS 12, watchOS 5, Safari 12, iTunes 12.9 for Windows, iCloud for...Show more |
HashiCorp Consul 1.4.3 lacks server hostname verification for agent-to-agent TLS communication. In other words, the product behaves as if verify_server_hostname were set to false, even when it is actually set to true. Th...Show more |