VYPR

CWE-346

Origin Validation Error

ClassDraft

Description

The product does not properly verify that the source of data or communication is valid.

Hierarchy (View 1000)

Related attack patterns (CAPEC)

CAPEC-111 · CAPEC-141 · CAPEC-142 · CAPEC-160 · CAPEC-21 · CAPEC-384 · CAPEC-385 · CAPEC-386 · CAPEC-387 · CAPEC-388 · CAPEC-510 · CAPEC-59 · CAPEC-60 · CAPEC-75 · CAPEC-76 · CAPEC-89

CVEs mapped to this weakness (785)

page 34 of 40
  • CVE-2023-28794MedNov 6, 2023
    risk 0.28cvss 4.3epss 0.00

    Origin Validation Error vulnerability in Zscaler Client Connector on Linux allows Privilege Abuse. This issue affects Zscaler Client Connector for Linux: before 1.3.1.6.

  • CVE-2023-5859MedNov 1, 2023
    risk 0.28cvss 4.3epss 0.01

    Incorrect security UI in Picture In Picture in Google Chrome prior to 119.0.6045.105 allowed a remote attacker to perform domain spoofing via a crafted local HTML page. (Chromium security severity: Low)

  • CVE-2023-5858MedNov 1, 2023
    risk 0.28cvss 4.3epss 0.01

    Inappropriate implementation in WebApp Provider in Google Chrome prior to 119.0.6045.105 allowed a remote attacker to obfuscate security UI via a crafted HTML page. (Chromium security severity: Low)

  • CVE-2023-5853MedNov 1, 2023
    risk 0.28cvss 4.3epss 0.01

    Incorrect security UI in Downloads in Google Chrome prior to 119.0.6045.105 allowed a remote attacker to obfuscate security UI via a crafted HTML page. (Chromium security severity: Medium)

  • CVE-2023-5851MedNov 1, 2023
    risk 0.28cvss 4.3epss 0.01

    Inappropriate implementation in Downloads in Google Chrome prior to 119.0.6045.105 allowed a remote attacker to obfuscate security UI via a crafted HTML page. (Chromium security severity: Medium)

  • CVE-2023-5718MedOct 23, 2023
    risk 0.28cvss 4.3epss 0.00

    The Vue.js Devtools extension was found to leak screenshot data back to a malicious web page via the standard `postMessage()` API. By creating a malicious web page with an iFrame targeting a sensitive resource (i.e. a locally accessible file or sensitive website), and…

  • CVE-2023-29505MedAug 4, 2023
    risk 0.28cvss 4.3epss 0.01

    An issue was discovered in Zoho ManageEngine Network Configuration Manager 12.6.165. The WebSocket endpoint allows Cross-site WebSocket hijacking.

  • CVE-2022-4917MedJul 29, 2023
    risk 0.28cvss 4.3epss 0.00

    Incorrect security UI in Notifications in Google Chrome on Android prior to 103.0.5060.53 allowed a remote attacker to obscure the full screen notification via a crafted HTML page. (Chromium security severity: Low)

  • CVE-2023-30949MedJul 26, 2023
    risk 0.28cvss 4.3epss 0.00

    A missing origin validation in Slate sandbox could be exploited by a malicious user to modify the page's content, which could lead to phishing attacks.

  • CVE-2023-2886MedMay 25, 2023
    risk 0.28cvss 4.3epss 0.00

    Missing Origin Validation in WebSockets vulnerability in CBOT Chatbot allows Content Spoofing Via Application API Manipulation. This issue affects Chatbot: before Core: v4.0.3.4 Panel: v4.0.3.7.

  • CVE-2022-29915MedDec 22, 2022
    risk 0.28cvss 4.3epss 0.00

    The Performance API did not properly hide the fact whether a request cross-origin resource has observed redirects. This vulnerability affects Firefox < 100.

  • CVE-2022-1520MedDec 22, 2022
    risk 0.28cvss 4.3epss 0.00

    When viewing an email message A, which contains an attached message B, where B is encrypted or digitally signed or both, Thunderbird may show an incorrect encryption or signature status. After opening and viewing the attached message B, when returning to the display of message…

  • CVE-2022-41961MedDec 16, 2022
    risk 0.28cvss 4.3epss 0.00

    BigBlueButton is an open source web conferencing system. Versions prior to 2.4-rc-6 are subject to Ineffective user bans. The attacker could register multiple users, and join the meeting with one of them. When that user is banned, they could still join the meeting with the…

  • CVE-2021-43531MedDec 8, 2021
    risk 0.28cvss 4.3epss 0.00

    When a user loaded a Web Extensions context menu, the Web Extension could access the post-redirect URL of the element clicked. If the Web Extension lacked the WebRequest permission for the hosts involved in the redirect, this would be a same-origin-violation leaking data the Web…

  • CVE-2021-37967MedOct 8, 2021
    risk 0.28cvss 4.3epss 0.01

    Inappropriate implementation in Background Fetch API in Google Chrome prior to 94.0.4606.54 allowed a remote attacker who had compromised the renderer process to leak cross-origin data via a crafted HTML page.

  • CVE-2021-37966MedOct 8, 2021
    risk 0.28cvss 4.3epss 0.01

    Inappropriate implementation in Compositing in Google Chrome on Android prior to 94.0.4606.54 allowed a remote attacker to spoof the contents of the Omnibox (URL bar) via a crafted HTML page.

  • CVE-2021-30630MedOct 8, 2021
    risk 0.28cvss 4.3epss 0.01

    Inappropriate implementation in Blink in Google Chrome prior to 93.0.4577.82 allowed a remote attacker who had compromised the renderer process to leak cross-origin data via a crafted HTML page.

  • CVE-2021-30596MedAug 26, 2021
    risk 0.28cvss 4.3epss 0.02

    Incorrect security UI in Navigation in Google Chrome on Android prior to 92.0.4515.131 allowed a remote attacker to spoof the contents of the Omnibox (URL bar) via a crafted HTML page.

  • CVE-2021-21184MedMar 9, 2021
    risk 0.28cvss 4.3epss 0.01

    Inappropriate implementation in performance APIs in Google Chrome prior to 89.0.4389.72 allowed a remote attacker to leak cross-origin data via a crafted HTML page.

  • CVE-2021-21183MedMar 9, 2021
    risk 0.28cvss 4.3epss 0.01

    Inappropriate implementation in performance APIs in Google Chrome prior to 89.0.4389.72 allowed a remote attacker to leak cross-origin data via a crafted HTML page.