CWE-346

Origin Validation Error

Parent: CWE-345 - Insufficient Verification of Data Authenticity

The product does not properly verify that the source of data or communication is valid.

692 vulnerabilities with CWE-346
CVE-2014-125071 MEDIUM
gribbit < 2014-12-31 - Missing Origin Validation in WebSockets via HttpRequestHandler
CVSS 5.5
CVE-2014-1502
Opensuse < 28.0 - Origin Validation Error
CVE-2014-1487 HIGH
Firefox < 27.0 - Origin Validation Error via Web Workers Error Messages
CVSS 7.5
CVE-2012-4193
Mozilla Firefox < 16.0.1 - Same Origin Policy Bypass via Security Wrapper Unwrapping
CVE-2011-3072
Google Chrome < 18.0.1025.151 - Same Origin Policy Bypass via Pop-Up Windows
CVE-2011-3067
Google Chrome < 18.0.1025.151 - Same Origin Policy Bypass via IFRAME Replacement
CVE-2011-3056
Google Chrome < 17.0.963.83 - Same Origin Policy Bypass via Magic Iframe
CVE-2011-3956
Google Chrome < 17.0.963.46 - Same Origin Policy Bypass via Sandboxed Origin Handling
CVE-2011-2856
Google Chrome < 14.0.835.163 - Same Origin Policy Bypass
CVE-2009-4139 MEDIUM
Spacewalk Java site packages <5.4.1 - CSRF
CVSS 6.8
CVE-2009-1185
udev < 141 - Privilege Escalation via Unverified NETLINK Message
CVE-2005-0877 HIGH
dnsmasq < 2.21 - DNS Cache Poisoning via Unrequested Query Answers
CVSS 7.5
CVE-2003-0981 MEDIUM
FreeScripts VisitorBook LE - Origin Validation Error
CVSS 6.1
CVE-2003-0174 CRITICAL
IRIX < 6.5.19 - Unauthenticated Login via LDAP USERPASSWORD Attribute Bypass
CVSS 9.8
CVE-2001-1452 HIGH
Windows NT 4.0/2000 - Info Disclosure
CVSS 7.5
CVE-2000-1218 CRITICAL
Microsoft Windows - Info Disclosure
CVSS 9.8
CVE-1999-1549 HIGH
Lynx 2.x - Unauthenticated Configuration File Modification and Command Execution via LYNXOPTIONS URL
CVSS 7.8
Details
Vulnerabilities 692