CWE-346

Origin Validation Error

Parent: CWE-345 - Insufficient Verification of Data Authenticity

The product does not properly verify that the source of data or communication is valid.

692 vulnerabilities with CWE-346
CVE-2017-1000455 MEDIUM
GuixSD < 0.13.0 - Origin Validation Error via Incorrect POSIX Hard Link Usage
CVSS 5.5
CVE-2017-7561 HIGH
Red Hat JBoss EAP 3.0.7-3.0.25.Final - Server-Side Cache Poisoning via JAX-RS Component
CVSS 7.5
CVE-2017-0902 HIGH
RubyGems < 2.6.12 - DNS Hijacking via MITM Attack
CVSS 8.1
CVE-2017-8650 MEDIUM
Microsoft Edge - Origin Validation Error
CVSS 5.4
CVE-2017-8530 MEDIUM
Microsoft Edge - Security Feature Bypass via Same-Origin Policy Enforcement
CVSS 5.4
CVE-2017-8523 MEDIUM
Microsoft Edge - Security Feature Bypass via Same Origin Policy Misapplication
CVSS 4.3
CVE-2017-7667 HIGH
Apache NiFi <1.3.0 - Info Disclosure
CVSS 7.5
CVE-2017-5646 MEDIUM
Apache Knox 0.2.0-0.11.0 - Authenticated User Impersonation via Crafted WebHDFS URL
CVSS 6.8
CVE-2017-8793 HIGH
Accellion File Transfer Appliance < 9_12_40 - Same Origin Policy Bypass via acallow Parameter
CVSS 8.8
CVE-2017-6519 CRITICAL
Avahi < 0.6.32 - Denial of Service via IPv6 Unicast Query Response
CVSS 9.1
CVE-2017-5858 MEDIUM
converse.js 0.8.0-1.0.6 2.0.0-2.0.4 - User Impersonation via XEP-0280 Message Carbons
CVSS 5.9
CVE-2017-5606 MEDIUM
Xabber < 1.0.30 - Unauthenticated User Impersonation via XEP-0280 Message Carbons
CVSS 5.9
CVE-2017-5605 MEDIUM
Movim 0.8-0.10 - Unauthenticated User Impersonation via XEP-0280 Message Carbons
CVSS 5.9
CVE-2017-5604 MEDIUM
mcabber 1.0.0-1.0.4 - Unauthenticated User Impersonation via XEP-0280 Message Carbons
CVSS 5.9
CVE-2017-5603 MEDIUM
Jitsi 2.5.5061-2.9.5544 - Remote User Impersonation via XEP-0280 Message Carbons
CVSS 5.9
CVE-2017-5602 MEDIUM
jappix 1.0.0-1.1.6 - Remote User Impersonation via XEP-0280 Message Carbons
CVSS 5.9
CVE-2017-5593 MEDIUM
Psi+ 0.16.563.580-0.16.571.627 - User Impersonation via XEP-0280 Message Carbons
CVSS 5.9
CVE-2017-5592 MEDIUM
profanity 0.4.7-0.5.0 - Remote User Impersonation via XEP-0280 Message Carbons
CVSS 5.9
CVE-2017-5591 MEDIUM
SleekXMPP < 1.3.1 and Slixmpp < 1.2.3 - Remote User Impersonation via XEP-0280 Message Carbons
CVSS 5.9
CVE-2017-5590 MEDIUM
ChatSecure 3.2.0-4.0.0 and Zom < 1.0.11 - User Impersonation via XEP-0280 Message Carbons
CVSS 5.9
CVE-2017-5589 MEDIUM
yaxim bruno 0.8.6-0.8.8 - Remote User Impersonation via XEP-0280 Message Carbons
CVSS 5.9
CVE-2016-9902 HIGH
Redhat Enterprise Linux Desktop < 45.6.0 - Origin Validation Error
CVSS 7.5
CVE-2016-5168 HIGH
Google Chrome < 50.0.2661.91 - Same Origin Policy Bypass via Skia
CVSS 7.5
CVE-2016-8358 HIGH
Smiths-Medical CADD-Solis Medication Safety Software - Info Disclosure
CVSS 8.5
CVE-2015-4495 HIGH KEV
Firefox < 39.0.3 - Same Origin Policy Bypass via PDF Reader Native Setter
CVSS 8.8
Details
Vulnerabilities 692