Vulnerabilities > Origin Validation Error

DATE CVE VULNERABILITY TITLE RISK
2021-12-08 CVE-2021-43531 Origin Validation Error vulnerability in Mozilla Firefox
When a user loaded a Web Extensions context menu, the Web Extension could access the post-redirect URL of the element clicked.
network
low complexity
mozilla CWE-346
4.3
2021-11-03 CVE-2021-38497 Origin Validation Error vulnerability in Mozilla Firefox
Through use of reportValidity() and window.open(), a plain-text validation message could have been overlaid on another origin, leading to possible user confusion and spoofing attacks.
network
low complexity
mozilla CWE-346
6.5
2021-10-26 CVE-2021-41158 Origin Validation Error vulnerability in Freeswitch
FreeSWITCH is a Software Defined Telecom Stack enabling the digital transformation from proprietary telecom switches to a software implementation that runs on any commodity hardware.
network
low complexity
freeswitch CWE-346
7.5
2021-10-08 CVE-2021-37966 Origin Validation Error vulnerability in multiple products
Inappropriate implementation in Compositing in Google Chrome on Android prior to 94.0.4606.54 allowed a remote attacker to spoof the contents of the Omnibox (URL bar) via a crafted HTML page.
network
low complexity
google fedoraproject debian CWE-346
4.3
2021-10-08 CVE-2021-37967 Origin Validation Error vulnerability in multiple products
Inappropriate implementation in Background Fetch API in Google Chrome prior to 94.0.4606.54 allowed a remote attacker who had compromised the renderer process to leak cross-origin data via a crafted HTML page.
network
low complexity
google fedoraproject debian CWE-346
4.3
2021-10-08 CVE-2021-30630 Origin Validation Error vulnerability in multiple products
Inappropriate implementation in Blink in Google Chrome prior to 93.0.4577.82 allowed a remote attacker who had compromised the renderer process to leak cross-origin data via a crafted HTML page.
network
low complexity
google fedoraproject CWE-346
4.3
2021-09-23 CVE-2021-41088 Origin Validation Error vulnerability in ELV Elvish
Elvish is a programming language and interactive shell, combined into one package.
network
low complexity
elv CWE-346
8.8
2021-09-13 CVE-2020-27969 Origin Validation Error vulnerability in Yandex Browser
Yandex Browser for Android 20.8.4 allows remote attackers to perform SOP bypass and addresss bar spoofing
network
low complexity
yandex CWE-346
7.3
2021-09-01 CVE-2021-39185 Origin Validation Error vulnerability in Typelevel Http4S
Http4s is a minimal, idiomatic Scala interface for HTTP services.
network
low complexity
typelevel CWE-346
critical
9.1
2021-09-01 CVE-2021-34435 Origin Validation Error vulnerability in Eclipse Theia
In Eclipse Theia 0.3.9 to 1.8.1, the "mini-browser" extension allows a user to preview HTML files in an iframe inside the IDE.
network
low complexity
eclipse CWE-346
8.8