Vulnerabilities > Origin Validation Error

DATE CVE VULNERABILITY TITLE RISK
2019-02-28 CVE-2018-12402 Origin Validation Error vulnerability in multiple products
The internal WebBrowserPersist code does not use correct origin context for a resource being saved.
network
low complexity
mozilla canonical CWE-346
6.5
2019-02-19 CVE-2019-5773 Origin Validation Error vulnerability in multiple products
Insufficient origin validation in IndexedDB in Google Chrome prior to 72.0.3626.81 allowed a remote attacker who had compromised the renderer process to bypass same origin policy via a crafted HTML page.
network
low complexity
google debian redhat fedoraproject CWE-346
6.5
2019-02-17 CVE-2019-7399 Origin Validation Error vulnerability in Amazon Fire OS
Amazon Fire OS before 5.3.6.4 allows a man-in-the-middle attack against HTTP requests for "Terms of Use" and Privacy pages.
network
high complexity
amazon CWE-346
7.4
2019-01-28 CVE-2018-20745 Origin Validation Error vulnerability in Yiiframework YII
Yii 2.x through 2.0.15.1 actively converts a wildcard CORS policy into reflecting an arbitrary Origin header value, which is incompatible with the CORS security design, and could lead to CORS misconfiguration security problems.
network
high complexity
yiiframework CWE-346
5.9
2019-01-28 CVE-2018-20744 Origin Validation Error vulnerability in GO Cors Project GO Cors
The Olivier Poitrey Go CORS handler through 1.3.0 actively converts a wildcard CORS policy into reflecting an arbitrary Origin header value, which is incompatible with the CORS security design, and could lead to CORS misconfiguration security problems.
network
high complexity
go-cors-project CWE-346
5.9
2019-01-09 CVE-2018-16072 Origin Validation Error vulnerability in Google Chrome
A missing origin check related to HLS manifests in Blink in Google Chrome prior to 69.0.3497.81 allowed a remote attacker to bypass same origin policy via a crafted HTML page.
network
low complexity
google CWE-346
6.5
2018-10-08 CVE-2018-5400 Origin Validation Error vulnerability in Auto-Maskin DCU 210E Firmware and RP 210E Firmware
The Auto-Maskin products utilize an undocumented custom protocol to set up Modbus communications with other devices without validating those devices.
network
low complexity
auto-maskin CWE-346
critical
9.1
2018-09-18 CVE-2018-6690 Origin Validation Error vulnerability in Mcafee Application Change Control
Accessing, modifying, or executing executable files vulnerability in Microsoft Windows client in McAfee Application and Change Control (MACC) 8.0.0 Hotfix 4 and earlier allows authenticated users to execute arbitrary code via file transfer from external system.
local
low complexity
mcafee CWE-346
7.1
2018-08-30 CVE-2018-14903 Origin Validation Error vulnerability in Epson Wf-2750 Firmware Jp02L2
EPSON WF-2750 printers with firmware JP02I2 do not properly validate files before running updates, which allows remote attackers to cause a printer malfunction or send malicious data to the printer.
network
low complexity
epson CWE-346
7.5
2018-08-02 CVE-2018-3834 Origin Validation Error vulnerability in Insteon HUB Firmware 1013
An exploitable permanent denial of service vulnerability exists in Insteon Hub running firmware version 1013.
network
high complexity
insteon CWE-346
7.4