← Back
CWE-346

746 CVEs • Abstraction: Class

Origin Validation Error

The product does not properly verify that the source of data or communication is valid.

JSON object

Loading...

CVEs (746)

CVE
VENDORS
PRODUCTS
UPDATED
PUBLISHED
CVSS
1Thekelleys
1Dnsmasq
Apr 16, 2026
May 2, 2005
N/A· v4
7.5 HIGH· v3
5.0 MEDIUM· v2
Dnsmasq before 2.21 allows remote attackers to poison the DNS cache via answers to queries that were not made by Dnsmasq.
1Freescripts
1Visitorbook Le
Apr 16, 2026
Jan 5, 2004
N/A· v4
6.1 MEDIUM· v3
4.3 MEDIUM· v2
FreeScripts VisitorBook LE (visitorbook.pl) logs the reverse DNS name of a visiting host, which allows remote attackers to spoof the origin of their incoming requests and facilitate cross-site scripting (XSS) attacks.
1Sgi
1Irix
Apr 16, 2026
May 12, 2003
N/A· v4
9.8 CRITICAL· v3
7.5 HIGH· v2
The LDAP name service (nsd) in IRIX 6.5.19 and earlier does not properly verify if the USERPASSWORD attribute has been provided by an LDAP server, which could allow attackers to log in without a password.
1Microsoft
2Windows 2000
Windows Nt
Apr 16, 2026
Aug 31, 2001
N/A· v4
7.5 HIGH· v3
5.0 MEDIUM· v2
By default, DNS servers on Windows NT 4.0 and Windows 2000 Server cache glue records received from non-delegated name servers, which allows remote attackers to poison the DNS cache via spoofed DNS responses.
1Microsoft
5Windows 2000
Windows 98Windows 98se+2 more
Apr 16, 2026
Apr 14, 2000
N/A· v4
9.8 CRITICAL· v3
7.5 HIGH· v2
The default configuration for the domain name resolver for Microsoft Windows 98, NT 4.0, 2000, and XP sets the QueryIpMatching parameter to 0, which causes Windows to accept DNS updates from hosts that it did not query,...Show more
The default configuration for the domain name resolver for Microsoft Windows 98, NT 4.0, 2000, and XP sets the QueryIpMatching parameter to 0, which causes Windows to accept DNS updates from hosts that it did not query, which allows remote attackers to poison the DNS cache.Show less
1Lynx Project
1Lynx
Apr 16, 2026
Nov 16, 1999
N/A· v4
7.8 HIGH· v3
5.0 MEDIUM· v2
Lynx 2.x does not properly distinguish between internal and external HTML, which may allow a local attacker to read a "secure" hidden form value from a temporary file and craft a LYNXOPTIONS: URL that causes Lynx to modi...Show more
Lynx 2.x does not properly distinguish between internal and external HTML, which may allow a local attacker to read a "secure" hidden form value from a temporary file and craft a LYNXOPTIONS: URL that causes Lynx to modify the user's configuration file and execute commands.Show less