CWE-346

Origin Validation Error

Parent: CWE-345 - Insufficient Verification of Data Authenticity

The product does not properly verify that the source of data or communication is valid.

692 vulnerabilities with CWE-346
CVE-2022-4917 MEDIUM
Google Chrome < 103.0.5060.53 - Origin Validation Error via Notification UI Spoofing
CVSS 4.3
CVE-2022-46718 MEDIUM
iPadOS < 15.7.2 - Unauthorized Sensitive Location Information Access
CVSS 5.5
CVE-2022-42860 MEDIUM
macOS 11.0.0-11.7.0 - Unauthorized File System Modification
CVSS 5.5
CVE-2022-45139 MEDIUM
WAGO PFC100, PFC200, 751-9301, 752-8303/8000-002, Touch Panel 600 Firmware 16-21 - CORS Misconfiguration
CVSS 5.3
CVE-2022-42927 HIGH
Firefox < 106 and Firefox ESR < 102.4 - Same-Origin Policy Violation via performance.getEntries()
CVSS 8.1
CVE-2022-38472 MEDIUM
Thunderbird <102.2-Firefox <104 - CSRF
CVSS 6.5
CVE-2022-29915 MEDIUM
Firefox < 100.0 - Origin Validation Error via Performance API
CVSS 4.3
CVE-2022-22757 MEDIUM
Firefox < 97.0 - Remote Browser Control via WebDriver Host Header Spoofing
CVSS 6.5
CVE-2022-1520 MEDIUM
Thunderbird < 91.9 - Origin Validation Error in Attached Message Security Status Display
CVSS 4.3
CVE-2022-41961 MEDIUM
BigBlueButton < 2.4-rc-6 - Ineffective User Ban Enforcement via Shared extId
CVSS 4.3
CVE-2022-41924 CRITICAL
Tailscale < 1.32.3 - Remote Code Execution via Local API Host Header Spoofing
CVSS 9.6
CVE-2022-3457 CRITICAL
rdiffweb < 2.5.0a5 - Origin Validation Error
CVSS 9.8
CVE-2022-41749 HIGH
Trend Micro Apex One - Privilege Escalation
CVSS 7.8
CVE-2022-41294 MEDIUM
IBM Robotic Process Automation <21.0.5 - SSRF
CVSS 6.5
CVE-2022-22637 HIGH
Safari < 15.4 - Origin Validation Error
CVSS 8.8
CVE-2022-40140 MEDIUM
Trend Micro Apex One - Denial of Service via Origin Validation Error
CVSS 5.5
CVE-2022-23764 HIGH
teruten webcube 1.0.5.5-1.1.9.9 - Remote Code Execution via Insufficient Update File Verification
CVSS 8.8
CVE-2022-1497 MEDIUM
Google Chrome < 101.0.4951.41 - Origin Validation Error via Crafted HTML Page
CVSS 6.5
CVE-2022-31151 LOW
undici < 5.7.1 - Cookie Header Leakage on Cross-Origin Redirect
CVSS 3.7
CVE-2022-26137 HIGH
Atlassian Bamboo < 8.0.9, 8.1.0-8.1.8, 8.2.0-8.2.4 - Unauthenticated CORS Bypass via Servlet Filter Invocation
CVSS 8.8
CVE-2022-23763 HIGH
NeoRS < 2021.3.10.1 - Origin Validation Error in ActiveX Module
CVSS 7.8
CVE-2022-1747 MEDIUM
Dominion Voting Systems ImageCast X - Unauthenticated Ballot Printing via Authentication Forgery
CVSS 4.6
CVE-2022-30228 HIGH
SICAM GridEdge Essential < 2.6.6 - Origin Validation Error
CVSS 8.8
CVE-2022-31024 MEDIUM
NextCloud Collabra <6.0.0, <5.0.4, <4.2.6 - Info Disclosure
CVSS 6.5
CVE-2022-25227 HIGH
Thinfinity VNC 4.0.0.1 - Origin Validation Error
CVSS 8.8
Details
Vulnerabilities 692