VYPR

CWE-346

Origin Validation Error

ClassDraft

Description

The product does not properly verify that the source of data or communication is valid.

Hierarchy (View 1000)

Related attack patterns (CAPEC)

CAPEC-111 · CAPEC-141 · CAPEC-142 · CAPEC-160 · CAPEC-21 · CAPEC-384 · CAPEC-385 · CAPEC-386 · CAPEC-387 · CAPEC-388 · CAPEC-510 · CAPEC-59 · CAPEC-60 · CAPEC-75 · CAPEC-76 · CAPEC-89

CVEs mapped to this weakness (785)

page 20 of 40
  • CVE-2021-21209MedApr 26, 2021
    risk 0.42cvss 6.5epss 0.01

    Inappropriate implementation in storage in Google Chrome prior to 90.0.4430.72 allowed a remote attacker to leak cross-origin data via a crafted HTML page.

  • CVE-2021-28048MedApr 14, 2021
    risk 0.42cvss 6.5epss 0.01

    An overly permissive CORS policy in Devolutions Server before 2021.1 and Devolutions Server LTS before 2020.3.18 allows a remote attacker to leak cross-origin data via a crafted HTML page.

  • CVE-2021-23986MedMar 31, 2021
    risk 0.42cvss 6.5epss 0.00

    A malicious extension with the 'search' permission could have installed a new search engine whose favicon referenced a cross-origin URL. The response to this cross-origin request could have been read by the extension, allowing a same-origin policy bypass by the extension, which…

  • CVE-2021-21175MedMar 9, 2021
    risk 0.42cvss 6.5epss 0.01

    Inappropriate implementation in Site isolation in Google Chrome prior to 89.0.4389.72 allowed a remote attacker to leak cross-origin data via a crafted HTML page.

  • CVE-2021-21164MedMar 9, 2021
    risk 0.42cvss 6.5epss 0.01

    Insufficient data validation in Chrome on iOS in Google Chrome on iOS prior to 89.0.4389.72 allowed a remote attacker to leak cross-origin data via a crafted HTML page.

  • CVE-2021-21163MedMar 9, 2021
    risk 0.42cvss 6.5epss 0.01

    Insufficient data validation in Reader Mode in Google Chrome on iOS prior to 89.0.4389.72 allowed a remote attacker to leak cross-origin data via a crafted HTML page and a malicious server.

  • CVE-2020-15733MedDec 14, 2020
    risk 0.42cvss 6.5epss 0.01

    An Origin Validation Error vulnerability in the SafePay component of Bitdefender Antivirus Plus allows a web resource to misrepresent itself in the URL bar. This issue affects: Bitdefender Antivirus Plus versions prior to 25.0.7.29.

  • CVE-2019-8754MedOct 27, 2020
    risk 0.42cvss 6.5epss 0.00

    A cross-origin issue existed with "iframe" elements. This was addressed with improved tracking of security origins. This issue is fixed in macOS Catalina 10.15.1, Security Update 2019-001, and Security Update 2019-006. A malicious HTML document may be able to render iframes with…

  • CVE-2020-15682MedOct 22, 2020
    risk 0.42cvss 6.5epss 0.00

    When a link to an external protocol was clicked, a prompt was presented that allowed the user to choose what application to open it in. An attacker could induce that prompt to be associated with an origin they didn't control, resulting in a spoofing attack. This was fixed by…

  • CVE-2020-15773MedSep 18, 2020
    risk 0.42cvss 6.5epss 0.00

    An issue was discovered in Gradle Enterprise before 2020.2.4. Because of unrestricted cross-origin requests to read-only data in the Export API, an attacker can access data as a user (for the duration of the browser session) after previously explicitly authenticating with the…

  • CVE-2020-15652MedAug 10, 2020
    risk 0.42cvss 6.5epss 0.01

    By observing the stack trace for JavaScript errors in web workers, it was possible to leak the result of a cross-origin redirect. This applied only to content that can be parsed as script. This vulnerability affects Firefox < 79, Firefox ESR < 68.11, Firefox ESR < 78.1,…

  • CVE-2020-16168MedAug 7, 2020
    risk 0.42cvss 6.5epss 0.01

    Origin Validation Error in temi Robox OS prior to 120, temi Android app up to 1.3.7931 allows remote attackers to access the REST API and MQTT broker used by the temi and send it custom data/requests via unspecified vectors.

  • CVE-2019-5062MedDec 12, 2019
    risk 0.42cvss 6.5epss 0.01

    An exploitable denial-of-service vulnerability exists in the 802.11w security state handling for hostapd 2.6 connected clients with valid 802.11w sessions. By simulating an incomplete new association, an attacker can trigger a deauthentication against stations using 802.11w,…

  • CVE-2019-13740MedDec 10, 2019
    risk 0.42cvss 6.5epss 0.01

    Incorrect security UI in sharing in Google Chrome prior to 79.0.3945.79 allowed a remote attacker to perform domain spoofing via a crafted HTML page.

  • CVE-2019-13664MedNov 25, 2019
    risk 0.42cvss 6.5epss 0.01

    Insufficient policy enforcement in Blink in Google Chrome prior to 77.0.3865.75 allowed a remote attacker to bypass content security policy via a crafted HTML page.

  • CVE-2019-16275MedSep 12, 2019
    risk 0.42cvss 6.5epss 0.01

    hostapd before 2.10 and wpa_supplicant before 2.10 allow an incorrect indication of disconnection in certain situations because source address validation is mishandled. This is a denial of service that should have been prevented by PMF (aka management frame protection). The…

  • CVE-2019-16237HigSep 11, 2019
    risk 0.42cvss 7.5epss 0.01

    Dino before 2019-09-10 does not properly check the source of an MAM message in module/xep/0313_message_archive_management.vala.

  • CVE-2019-16235HigSep 11, 2019
    risk 0.42cvss 7.5epss 0.01

    Dino before 2019-09-10 does not properly check the source of a carbons message in module/xep/0280_message_carbons.vala.

  • CVE-2019-5834MedJun 27, 2019
    risk 0.42cvss 6.5epss 0.01

    Insufficient data validation in Blink in Google Chrome prior to 75.0.3770.80 allowed a remote attacker to perform domain spoofing via a crafted HTML page.

  • CVE-2018-18499MedFeb 28, 2019
    risk 0.42cvss 6.5epss 0.01

    A same-origin policy violation allowing the theft of cross-origin URL entries when using a meta http-equiv="refresh" on a page to cause a redirection to another site using performance.getEntries(). This is a same-origin policy violation and could allow for data theft. This…