The product does not properly verify that the source of data or communication is valid.
557 vulnerabilities with CWE-346
CVE-2017-5858
MEDIUM
converse.js 0.8.0-1.0.6 2.0.0-2.0.4 - User Impersonation via XEP-0280 Message Carbons
CVSS 5.9
CVE-2017-5606
MEDIUM
Xabber < 1.0.30 - Unauthenticated User Impersonation via XEP-0280 Message Carbons
CVSS 5.9
CVE-2017-5605
MEDIUM
Movim 0.8-0.10 - Unauthenticated User Impersonation via XEP-0280 Message Carbons
CVSS 5.9
CVE-2017-5604
MEDIUM
mcabber 1.0.0-1.0.4 - Unauthenticated User Impersonation via XEP-0280 Message Carbons
CVSS 5.9
CVE-2017-5603
MEDIUM
Jitsi 2.5.5061-2.9.5544 - Remote User Impersonation via XEP-0280 Message Carbons
CVSS 5.9
CVE-2017-5602
MEDIUM
jappix 1.0.0-1.1.6 - Remote User Impersonation via XEP-0280 Message Carbons
CVSS 5.9
CVE-2017-5593
MEDIUM
Psi+ 0.16.563.580-0.16.571.627 - User Impersonation via XEP-0280 Message Carbons
CVSS 5.9
CVE-2017-5592
MEDIUM
profanity 0.4.7-0.5.0 - Remote User Impersonation via XEP-0280 Message Carbons
CVSS 5.9
CVE-2017-5591
MEDIUM
SleekXMPP < 1.3.1 and Slixmpp < 1.2.3 - Remote User Impersonation via XEP-0280 Message Carbons
CVSS 5.9
CVE-2017-5590
MEDIUM
ChatSecure 3.2.0-4.0.0 and Zom < 1.0.11 - User Impersonation via XEP-0280 Message Carbons
CVSS 5.9
CVE-2017-5589
MEDIUM
yaxim bruno 0.8.6-0.8.8 - Remote User Impersonation via XEP-0280 Message Carbons
CVSS 5.9
CVE-2016-9902
HIGH
Redhat Enterprise Linux Desktop < 45.6.0 - Origin Validation Error
CVSS 7.5
CVE-2016-5168
HIGH
Google Chrome < 50.0.2661.91 - Same Origin Policy Bypass via Skia
CVSS 7.5
CVE-2016-8358
HIGH
Smiths-Medical CADD-Solis Medication Safety Software - Info Disclosure
CVSS 8.5
CVE-2015-4495
HIGH
KEV
Firefox < 39.0.3 - Same Origin Policy Bypass via PDF Reader Native Setter
CVSS 8.8
CVE-2014-125071
MEDIUM
gribbit < 2014-12-31 - Missing Origin Validation in WebSockets via HttpRequestHandler
CVSS 5.5
CVE-2014-1502
Opensuse < 28.0 - Origin Validation Error
CVE-2014-1487
HIGH
Firefox < 27.0 - Origin Validation Error via Web Workers Error Messages
CVSS 7.5
CVE-2012-4193
Mozilla Firefox < 16.0.1 - Same Origin Policy Bypass via Security Wrapper Unwrapping
CVE-2011-3072
Google Chrome < 18.0.1025.151 - Same Origin Policy Bypass via Pop-Up Windows
CVE-2011-3067
Google Chrome < 18.0.1025.151 - Same Origin Policy Bypass via IFRAME Replacement
CVE-2011-3056
Google Chrome < 17.0.963.83 - Same Origin Policy Bypass via Magic Iframe
CVE-2011-3956
Google Chrome < 17.0.963.46 - Same Origin Policy Bypass via Sandboxed Origin Handling
CVE-2011-2856
Google Chrome < 14.0.835.163 - Same Origin Policy Bypass
CVE-2009-4139
MEDIUM
Spacewalk Java site packages <5.4.1 - CSRF
CVSS 6.8
Details
Vulnerabilities
557