CWE-346
746 CVEs • Abstraction: Class
Origin Validation Error
The product does not properly verify that the source of data or communication is valid.
CVEs (746)
CVE VENDORS PRODUCTS UPDATED PUBLISHED CVSS |
|---|
An incorrect implementation of "XEP-0280: Message Carbons" in multiple XMPP clients allows a remote attacker to impersonate any user, including contacts, in the vulnerable application's display. This allows for various k...Show more |
An incorrect implementation of "XEP-0280: Message Carbons" in multiple XMPP clients allows a remote attacker to impersonate any user, including contacts, in the vulnerable application's display. This allows for various k...Show more |
An incorrect implementation of "XEP-0280: Message Carbons" in multiple XMPP clients allows a remote attacker to impersonate any user, including contacts, in the vulnerable application's display. This allows for various k...Show more |
An incorrect implementation of "XEP-0280: Message Carbons" in multiple XMPP clients allows a remote attacker to impersonate any user, including contacts, in the vulnerable application's display. This allows for various k...Show more |
An incorrect implementation of "XEP-0280: Message Carbons" in multiple XMPP clients allows a remote attacker to impersonate any user, including contacts, in the vulnerable application's display. This allows for various k...Show more |
An incorrect implementation of "XEP-0280: Message Carbons" in multiple XMPP clients allows a remote attacker to impersonate any user, including contacts, in the vulnerable application's display. This allows for various k...Show more |
3Poezio Sleekxmpp ProjectSlixmpp Project3Poezio SleekxmppSlixmppMay 13, 2026 Feb 9, 2017 N/A· v4 5.9 MEDIUM· v3 4.3 MEDIUM· v2 An incorrect implementation of "XEP-0280: Message Carbons" in multiple XMPP clients allows a remote attacker to impersonate any user, including contacts, in the vulnerable application's display. This allows for various k...Show more |
An incorrect implementation of "XEP-0280: Message Carbons" in multiple XMPP clients allows a remote attacker to impersonate any user, including contacts, in the vulnerable application's display. This allows for various k...Show more |
An incorrect implementation of "XEP-0280: Message Carbons" in multiple XMPP clients allows a remote attacker to impersonate any user, including contacts, in the vulnerable application's display. This allows for various k...Show more |
6Canonical MozillaOpensuse+3 more15Enterprise Linux Desktop Enterprise Linux EusEnterprise Linux Server+12 moreApr 22, 2026 Aug 8, 2015 N/A· v4 8.8 HIGH· v3 4.3 MEDIUM· v2 The PDF reader in Mozilla Firefox before 39.0.3, Firefox ESR 38.x before 38.1.1, and Firefox OS before 2.2 allows remote attackers to bypass the Same Origin Policy, and read arbitrary files or gain privileges, via vector...Show more |
5Mozilla OpensuseOpensuse Project+2 more8Firefox Linux Enterprise DesktopLinux Enterprise Server+5 moreMay 6, 2026 Mar 19, 2014 N/A· v4 N/A· v3 6.8 MEDIUM· v2 The (1) WebGL.compressedTexImage2D and (2) WebGL.compressedTexSubImage2D functions in Mozilla Firefox before 28.0 and SeaMonkey before 2.25 allow remote attackers to bypass the Same Origin Policy and render content in a...Show more |
7Canonical DebianFedoraproject+4 more17Debian Linux Enterprise Linux DesktopEnterprise Linux Eus+14 moreApr 29, 2026 Feb 6, 2014 N/A· v4 7.5 HIGH· v3 5.0 MEDIUM· v2 The Web workers implementation in Mozilla Firefox before 27.0, Firefox ESR 24.x before 24.3, Thunderbird before 24.3, and SeaMonkey before 2.24 allows remote attackers to bypass the Same Origin Policy and obtain sensitiv...Show more |
4Canonical MozillaRedhat+1 more12Enterprise Linux Desktop Enterprise Linux EusEnterprise Linux Server+9 moreApr 29, 2026 Oct 12, 2012 N/A· v4 N/A· v3 6.8 MEDIUM· v2 Mozilla Firefox before 16.0.1, Firefox ESR 10.x before 10.0.9, Thunderbird before 16.0.1, Thunderbird ESR 10.x before 10.0.9, and SeaMonkey before 2.13.1 omit a security check in the defaultValue function during the unwr...Show more |
Google Chrome before 18.0.1025.151 allows remote attackers to bypass the Same Origin Policy via vectors related to pop-up windows. |
Google Chrome before 18.0.1025.151 allows remote attackers to bypass the Same Origin Policy via vectors related to replacement of IFRAME elements. |
3Apple GoogleOpensuse4Chrome Iphone OsOpensuse+1 moreApr 29, 2026 Mar 22, 2012 N/A· v4 N/A· v3 6.8 MEDIUM· v2 Google Chrome before 17.0.963.83 allows remote attackers to bypass the Same Origin Policy via vectors involving a "magic iframe." |
The extension implementation in Google Chrome before 17.0.963.46 does not properly handle sandboxed origins, which might allow remote attackers to bypass the Same Origin Policy via a crafted extension. |
Google V8, as used in Google Chrome before 14.0.835.163, allows remote attackers to bypass the Same Origin Policy via unspecified vectors. |
1Redhat 2Network Satellite Server Spacewalk JavaApr 29, 2026 Jul 27, 2011 N/A· v4 6.8 MEDIUM· v3 6.8 MEDIUM· v2 A flaw was found in Spacewalk Java site packages. This cross-site request forgery (CSRF) vulnerability allows a remote attacker to hijack the authentication of arbitrary users. This can lead to unauthorized actions, incl...Show more |
7Canonical DebianFedoraproject+4 more9Ctpview Debian LinuxFedora+6 moreApr 23, 2026 Apr 17, 2009 N/A· v4 N/A· v3 7.2 HIGH· v2 udev before 1.4.1 does not verify whether a NETLINK message originates from kernel space, which allows local users to gain privileges by sending a NETLINK message from user space. |