Vulnerabilities > Authentication Bypass by Spoofing

DATE CVE VULNERABILITY TITLE RISK
2019-11-25 CVE-2019-13703 Authentication Bypass by Spoofing vulnerability in multiple products
Insufficient policy enforcement in the Omnibox in Google Chrome on Android prior to 78.0.3904.70 allowed a remote attacker to spoof the contents of the Omnibox (URL bar) via a crafted HTML page.
network
low complexity
google opensuse CWE-290
4.3
2019-11-25 CVE-2019-13701 Authentication Bypass by Spoofing vulnerability in multiple products
Incorrect implementation in navigation in Google Chrome prior to 78.0.3904.70 allowed a remote attacker to spoof the contents of the Omnibox (URL bar) via a crafted HTML page.
network
low complexity
google opensuse CWE-290
4.3
2019-11-13 CVE-2019-0388 Authentication Bypass by Spoofing vulnerability in SAP UI
SAP UI5 HTTP Handler (corrected in SAP_UI versions 7.5, 7.51, 7.52, 7.53, 7.54 and SAP UI_700 version 2.0) allows an attacker to manipulate content due to insufficient URL validation.
network
low complexity
sap CWE-290
5.3
2019-11-12 CVE-2019-1234 Authentication Bypass by Spoofing vulnerability in Microsoft Azure Stack
A spoofing vulnerability exists when Azure Stack fails to validate certain requests, aka 'Azure Stack Spoofing Vulnerability'.
network
low complexity
microsoft CWE-290
7.5
2019-11-05 CVE-2013-5661 Authentication Bypass by Spoofing vulnerability in multiple products
Cache Poisoning issue exists in DNS Response Rate Limiting.
network
high complexity
isc nlnetlabs nic redhat CWE-290
5.9
2019-11-02 CVE-2019-18659 Authentication Bypass by Spoofing vulnerability in Ready Wireless Emergency Alerts
The Wireless Emergency Alerts (WEA) protocol allows remote attackers to spoof a Presidential Alert because cryptographic authentication is not used, as demonstrated by MessageIdentifier 4370 in LTE System Information Block 12 (aka SIB12).
network
low complexity
ready CWE-290
5.3
2019-10-10 CVE-2019-1357 Authentication Bypass by Spoofing vulnerability in Microsoft Edge and Internet Explorer
A spoofing vulnerability exists when Microsoft Browsers improperly handle browser cookies, aka 'Microsoft Browser Spoofing Vulnerability'.
network
low complexity
microsoft CWE-290
4.3
2019-10-10 CVE-2019-1318 Authentication Bypass by Spoofing vulnerability in Microsoft products
A spoofing vulnerability exists when Transport Layer Security (TLS) accesses non- Extended Master Secret (EMS) sessions, aka 'Microsoft Windows Transport Layer Security Spoofing Vulnerability'.
network
high complexity
microsoft CWE-290
5.9
2019-10-10 CVE-2019-0608 Authentication Bypass by Spoofing vulnerability in Microsoft Edge and Internet Explorer
A spoofing vulnerability exists when Microsoft Browsers does not properly parse HTTP content, aka 'Microsoft Browser Spoofing Vulnerability'.
network
low complexity
microsoft CWE-290
4.3
2019-10-09 CVE-2019-15022 Authentication Bypass by Spoofing vulnerability in Zingbox Inspector
A security vulnerability exists in Zingbox Inspector versions 1.294 and earlier, that allows for the Inspector to be susceptible to ARP spoofing.
network
low complexity
zingbox CWE-290
7.5