This attack-focused weakness is caused by incorrectly implemented authentication schemes that are subject to spoofing attacks.
578 vulnerabilities with CWE-290
CVE-2019-16871
CRITICAL
Beckhoff TwinCAT < 3.1 - Remote Code Execution via ADS Protocol
CVSS 9.8
CVE-2019-18259
CRITICAL
Omron PLC CJ and CS Firmware - Authentication Bypass by Spoofing
CVSS 9.8
CVE-2019-16766
HIGH
wagtail-2fa < 1.3.0 - Authentication Bypass via URL Manipulation
CVSS 8.7
CVE-2019-13715
MEDIUM
Google Chrome < 78.0.3904.70 - Domain Spoofing via IDN Homographs in Omnibox
CVSS 4.3
CVE-2019-13709
MEDIUM
Google Chrome <78.0.3904.70 - Auth Bypass
CVSS 6.5
CVE-2019-13708
MEDIUM
Google Chrome < 78.0.3904.70 - Authentication Bypass by Spoofing via Omnibox Manipulation
CVSS 4.3
CVE-2019-13704
MEDIUM
Google Chrome < 78.0.3904.70 - Content Security Policy Bypass via Crafted HTML Page
CVSS 4.3
CVE-2019-13703
MEDIUM
Google Chrome <78.0.3904.70 - Info Disclosure
CVSS 4.3
CVE-2019-13701
MEDIUM
Google Chrome < 78.0.3904.70 - URL Spoofing via Omnibox Manipulation
CVSS 4.3
CVE-2019-0388
MEDIUM
SAP UI5 - Content Manipulation via Insufficient URL Validation
CVSS 5.3
CVE-2019-1234
HIGH
Azure Stack - Authentication Bypass by Spoofing via Request Validation Failure
CVSS 7.5
CVE-2019-18659
MEDIUM
Wireless Emergency Alerts Protocol - Presidential Alert Spoofing
CVSS 5.3
CVE-2019-1357
MEDIUM
Internet Explorer - Authentication Bypass via Cookie Handling
CVSS 4.3
CVE-2019-1318
MEDIUM
Windows - Authentication Bypass via TLS Non-EMS Session Spoofing
CVSS 5.9
CVE-2019-0608
MEDIUM
Internet Explorer - Spoofing via HTTP Content Parsing
CVSS 4.3
CVE-2019-15022
HIGH
Zingbox Inspector < 1.294 - ARP Spoofing Authentication Bypass
CVSS 7.5
CVE-2019-16378
CRITICAL
OpenDMARC <1.3.2, <1.4.0-Beta1 - Signature Bypass
CVSS 9.8
CVE-2019-3884
MEDIUM
OpenShift 3.6-3.11, 4.1 - Authentication Bypass via UUID Spoofing
CVSS 5.4
CVE-2019-0283
HIGH
SAP NetWeaver Process Integration - Digital Signature Spoofing via PI Axis Adapter
CVSS 7.1
CVE-2019-10875
MEDIUM
Mi Browser and Mint Browser - URL Spoofing via Query Parameter Handling
CVSS 6.5
CVE-2019-3775
HIGH
Cloud Foundry UAA < 70.0 - Authenticated User Impersonation via Email Address Spoofing
CVSS 7.1
CVE-2018-25361
MEDIUM
Soroush IM Desktop App 0.17.0 Authentication Bypass via Database Injection
CVSS 6.8
CVE-2018-25318
CRITICAL
Tenda FH303/A300 V5.07.68_EN Cookie Session Weakness DNS Change
CVSS 9.8
CVE-2018-25317
CRITICAL
Tenda W3002R/A302/W309R V5.07.64_en Cookie Session Weakness DNS Change
CVSS 9.8
CVE-2018-25316
CRITICAL
Tenda W308R v2 V5.07.48 Cookie Session Weakness DNS Change
CVSS 9.8
Details
Vulnerabilities
578