VYPR

CWE-346

Origin Validation Error

ClassDraft

Description

The product does not properly verify that the source of data or communication is valid.

Hierarchy (View 1000)

Related attack patterns (CAPEC)

CAPEC-111 · CAPEC-141 · CAPEC-142 · CAPEC-160 · CAPEC-21 · CAPEC-384 · CAPEC-385 · CAPEC-386 · CAPEC-387 · CAPEC-388 · CAPEC-510 · CAPEC-59 · CAPEC-60 · CAPEC-75 · CAPEC-76 · CAPEC-89

CVEs mapped to this weakness (729)

page 10 of 37
  • CVE-2023-49803HigDec 11, 2023
    risk 0.49cvss 8.6epss 0.00

    @koa/cors npm provides Cross-Origin Resource Sharing (CORS) for koa, a web framework for Node.js. Prior to version 5.0.0, the middleware operates in a way that if an allowed origin is not provided, it will return an `Access-Control-Allow-Origin` header with the value of the…

  • CVE-2023-29743HigMay 30, 2023
    risk 0.49cvss 7.5epss 0.01

    An issue found in BestWeather v.7.3.1 for Android allows unauthorized apps to cause a persistent denial of service attack by manipulating the database.

  • CVE-2023-33740HigMay 30, 2023
    risk 0.49cvss 7.5epss 0.01

    Incorrect access control in luowice v3.5.18 allows attackers to access cloud source code information via modification fo the Verify parameter in a warning message.

  • CVE-2023-30196HigMay 30, 2023
    risk 0.49cvss 7.5epss 0.01

    Prestashop salesbooster <= 1.10.4 is vulnerable to Incorrect Access Control via modules/salesbooster/downloads/download.php.

  • CVE-2023-23578HigMay 10, 2023
    risk 0.49cvss 7.5epss 0.02

    Improper access control vulnerability in SkyBridge MB-A200 firmware Ver. 01.00.05 and earlier allows a remote unauthenticated attacker to connect to the product's ADB port.

  • CVE-2021-39270HigAug 18, 2021
    risk 0.49cvss 7.5epss 0.00

    In Ping Identity RSA SecurID Integration Kit before 3.2, user impersonation can occur.

  • CVE-2020-4881HigJan 19, 2021
    risk 0.49cvss 7.5epss 0.01

    IBM Planning Analytics 2.0 could allow a remote attacker to obtain sensitive information, caused by the lack of server hostname verification for SSL/TLS communication. By sending a specially-crafted request, an attacker could exploit this vulnerability to obtain sensitive…

  • CVE-2020-6881HigDec 21, 2020
    risk 0.49cvss 7.5epss 0.01

    ZTE E8810/E8820/E8822 series routers have an MQTT DoS vulnerability, which is caused by the failure of the device to verify the validity of abnormal messages. A remote attacker could connect to the MQTT server and send an MQTT exception message to the specified device, which…

  • CVE-2020-9903HigOct 16, 2020
    risk 0.49cvss 7.5epss 0.01

    A logic issue was addressed with improved restrictions. This issue is fixed in iOS 13.6 and iPadOS 13.6, Safari 13.1.2. A malicious attacker may cause Safari to suggest a password for the wrong domain.

  • CVE-2020-14519HigSep 16, 2020
    risk 0.49cvss 7.5epss 0.01

    This vulnerability allows an attacker to use the internal WebSockets API for CodeMeter (All versions prior to 7.00 are affected, including Version 7.0 or newer with the affected WebSockets API still enabled. This is especially relevant for systems or devices where a web browser…

  • CVE-2020-11868HigApr 17, 2020
    risk 0.49cvss 7.5epss 0.02

    ntpd in ntp before 4.2.8p14 and 4.3.x before 4.3.100 allows an off-path attacker to block unauthenticated synchronization via a server mode packet with a spoofed source IP address, because transmissions are rescheduled even when a packet lacks a valid origin timestamp.

  • CVE-2020-8984HigMar 24, 2020
    risk 0.49cvss 7.5epss 0.00

    lib/NSSDropbox.php in ZendTo prior to 5.22-2 Beta allowed IP address spoofing via the X-Forwarded-For header.

  • CVE-2019-19019HigDec 2, 2019
    risk 0.49cvss 7.5epss 0.02

    An issue was discovered in TitanHQ WebTitan before 5.18. It contains a Remote Code Execution issue through which an attacker can execute arbitrary code as root. The issue stems from the hotfix download mechanism, which downloads a shell script via HTTP, and then executes it as…

  • CVE-2019-11777HigSep 11, 2019
    risk 0.49cvss 7.5epss 0.01

    In the Eclipse Paho Java client library version 1.2.0, when connecting to an MQTT server using TLS and setting a host name verifier, the result of that verification is not checked. This could allow one MQTT server to impersonate another and provide the client library with…

  • CVE-2019-5036HigAug 20, 2019
    risk 0.49cvss 7.5epss 0.00

    An exploitable denial-of-service vulnerability exists in the Weave error reporting functionality of the Nest Cam IQ Indoor, version 4620002. A specially crafted weave packets can cause an arbitrary Weave Exchange Session to close, resulting in a denial of service. An attacker…

  • CVE-2019-11723HigJul 23, 2019
    risk 0.49cvss 7.5epss 0.01

    A vulnerability exists during the installation of add-ons where the initial fetch ignored the origin attributes of the browsing context. This could leak cookies in private browsing mode or across different "containers" for people who use the Firefox Multi-Account Containers Web…

  • CVE-2018-14903HigAug 30, 2018
    risk 0.49cvss 7.5epss 0.01

    EPSON WF-2750 printers with firmware JP02I2 do not properly validate files before running updates, which allows remote attackers to cause a printer malfunction or send malicious data to the printer.

  • CVE-2018-5157HigJun 11, 2018
    risk 0.49cvss 7.5epss 0.02

    Same-origin protections for the PDF viewer can be bypassed, allowing a malicious site to intercept messages meant for the viewer. This could allow the site to retrieve PDF files restricted to viewing by an authenticated user on a third-party website. This vulnerability affects…

  • CVE-2017-7797HigJun 11, 2018
    risk 0.49cvss 7.5epss 0.01

    Response header name interning does not have same-origin protections and these headers are stored in a global registry. This allows stored header names to be available cross-origin. This vulnerability affects Firefox < 55.

  • CVE-2016-9902HigJun 11, 2018
    risk 0.49cvss 7.5epss 0.01

    The Pocket toolbar button, once activated, listens for events fired from it's own pages but does not verify the origin of incoming events. This allows content from other origins to fire events and inject content and commands into the Pocket context. Note: this issue does not…