Vulnerabilities > Origin Validation Error

DATE CVE VULNERABILITY TITLE RISK
2019-12-05 CVE-2019-19545 Origin Validation Error vulnerability in Norton Password Manager
Norton Password Manager, prior to 6.6.2.5, may be susceptible to a cross origin resource sharing (CORS) vulnerability, which is a type of issue that allows restricted resources on a web page to be requested from another domain outside the domain from which the first resource was served.
network
low complexity
norton CWE-346
6.3
2019-12-05 CVE-2019-18381 Origin Validation Error vulnerability in Norton Password Manager
Norton Password Manager, prior to 6.6.2.5, may be susceptible to a cross origin resource sharing (CORS) vulnerability, which is a type of issue that allows restricted resources on a web page to be requested from another domain outside the domain from which the first resource was served.
network
low complexity
norton CWE-346
6.3
2019-12-02 CVE-2019-19019 Origin Validation Error vulnerability in Titanhq Webtitan
An issue was discovered in TitanHQ WebTitan before 5.18.
network
high complexity
titanhq CWE-346
7.5
2019-11-29 CVE-2019-5227 Origin Validation Error vulnerability in Huawei products
P30, P30 Pro, Mate 20 smartphones with software of versions earlier than ELLE-AL00B 9.1.0.193(C00E190R2P1), versions earlier than VOGUE-AL00A 9.1.0.193(C00E190R2P1), versions earlier than Hima-AL00B 9.1.0.135(C00E133R2P1) and HiSuite with versions earlier than HiSuite 9.1.0.305 have a version downgrade vulnerability.
local
low complexity
huawei CWE-346
5.5
2019-11-29 CVE-2019-5226 Origin Validation Error vulnerability in Huawei products
P30, P30 Pro, Mate 20 smartphones with software of versions earlier than ELLE-AL00B 9.1.0.193(C00E190R2P1), versions earlier than VOGUE-AL00A 9.1.0.193(C00E190R2P1), versions earlier than Hima-AL00B 9.1.0.135(C00E133R2P1) and HiSuite with versions earlier than HiSuite 9.1.0.305 have a version downgrade vulnerability.
local
low complexity
huawei CWE-346
5.5
2019-11-25 CVE-2019-13664 Origin Validation Error vulnerability in Google Chrome
Insufficient policy enforcement in Blink in Google Chrome prior to 77.0.3865.75 allowed a remote attacker to bypass content security policy via a crafted HTML page.
network
low complexity
google CWE-346
6.5
2019-11-12 CVE-2019-1447 Origin Validation Error vulnerability in Microsoft Office Online Server
A spoofing vulnerability exists when Office Online does not validate origin in cross-origin communications handlers correctly, aka 'Microsoft Office Online Spoofing Vulnerability'.
network
low complexity
microsoft CWE-346
5.4
2019-11-12 CVE-2019-1445 Origin Validation Error vulnerability in Microsoft Office Online Server
A spoofing vulnerability exists when Office Online does not validate origin in cross-origin communications handlers correctly, aka 'Microsoft Office Online Spoofing Vulnerability'.
network
low complexity
microsoft CWE-346
5.4
2019-11-12 CVE-2019-1442 Origin Validation Error vulnerability in Microsoft Sharepoint Server 2019
A security feature bypass vulnerability exists when Microsoft Office does not validate URLs.An attacker could send a victim a specially crafted file, which could trick the victim into entering credentials, aka 'Microsoft Office Security Feature Bypass Vulnerability'.
local
low complexity
microsoft CWE-346
5.5
2019-11-12 CVE-2019-1413 Origin Validation Error vulnerability in Microsoft Edge
A security feature bypass vulnerability exists when Microsoft Edge improperly handles extension requests and fails to request host permission for all_urls, aka 'Microsoft Edge Security Feature Bypass Vulnerability'.
network
low complexity
microsoft CWE-346
4.3