Vulnerabilities > Origin Validation Error

DATE CVE VULNERABILITY TITLE RISK
2021-08-26 CVE-2021-30596 Origin Validation Error vulnerability in multiple products
Incorrect security UI in Navigation in Google Chrome on Android prior to 92.0.4515.131 allowed a remote attacker to spoof the contents of the Omnibox (URL bar) via a crafted HTML page.
network
low complexity
google fedoraproject CWE-346
4.3
2021-08-18 CVE-2021-39270 Origin Validation Error vulnerability in Pingidentity RSA Securid Integration KIT
In Ping Identity RSA SecurID Integration Kit before 3.2, user impersonation can occur.
network
low complexity
pingidentity CWE-346
7.5
2021-04-30 CVE-2021-21229 Origin Validation Error vulnerability in multiple products
Incorrect security UI in downloads in Google Chrome on Android prior to 90.0.4430.93 allowed a remote attacker to perform domain spoofing via a crafted HTML page.
network
low complexity
google debian fedoraproject CWE-346
6.5
2021-04-26 CVE-2021-21211 Origin Validation Error vulnerability in multiple products
Inappropriate implementation in Navigation in Google Chrome on iOS prior to 90.0.4430.72 allowed a remote attacker to leak cross-origin data via a crafted HTML page.
network
low complexity
google debian fedoraproject CWE-346
6.5
2021-04-26 CVE-2021-21209 Origin Validation Error vulnerability in multiple products
Inappropriate implementation in storage in Google Chrome prior to 90.0.4430.72 allowed a remote attacker to leak cross-origin data via a crafted HTML page.
network
low complexity
google debian fedoraproject CWE-346
6.5
2021-04-25 CVE-2021-31718 Origin Validation Error vulnerability in Npupnp Project Npupnp
The server in npupnp before 4.1.4 is affected by DNS rebinding in the embedded web server (including UPnP SOAP and GENA endpoints), leading to remote code execution.
network
low complexity
npupnp-project CWE-346
8.8
2021-04-23 CVE-2021-26291 Origin Validation Error vulnerability in multiple products
Apache Maven will follow repositories that are defined in a dependency’s Project Object Model (pom) which may be surprising to some users, resulting in potential risk if a malicious actor takes over that repository or is able to insert themselves into a position to pretend to be that repository.
network
low complexity
apache quarkus oracle CWE-346
critical
9.1
2021-04-14 CVE-2021-28048 Origin Validation Error vulnerability in Devolutions Server
An overly permissive CORS policy in Devolutions Server before 2021.1 and Devolutions Server LTS before 2020.3.18 allows a remote attacker to leak cross-origin data via a crafted HTML page.
network
low complexity
devolutions CWE-346
6.5
2021-04-12 CVE-2020-15734 Origin Validation Error vulnerability in Bitdefender Safepay 23.0.10.34
An Origin Validation Error vulnerability in Bitdefender Safepay allows an attacker to manipulate the browser's file upload capability into accessing other files in the same directory or sub-directories.
local
low complexity
bitdefender CWE-346
5.5
2021-03-31 CVE-2021-23986 Origin Validation Error vulnerability in Mozilla Firefox
A malicious extension with the 'search' permission could have installed a new search engine whose favicon referenced a cross-origin URL.
network
low complexity
mozilla CWE-346
6.5