Vulnerabilities > Origin Validation Error

DATE CVE VULNERABILITY TITLE RISK
2022-12-22 CVE-2022-38472 An attacker could have abused XSLT error handling to associate attacker-controlled content with another origin which was displayed in the address bar.
network
low complexity
CWE-346
6.5
2022-12-22 CVE-2022-42927 Origin Validation Error vulnerability in Mozilla Firefox
A same-origin policy violation could have allowed the theft of cross-origin URL entries, leaking the result of a redirect, via `performance.getEntries()`.
network
low complexity
mozilla CWE-346
8.1
2022-12-16 CVE-2022-41961 Origin Validation Error vulnerability in Bigbluebutton 2.4
BigBlueButton is an open source web conferencing system.
network
low complexity
bigbluebutton CWE-346
4.3
2022-11-23 CVE-2022-41924 Origin Validation Error vulnerability in Tailscale
A vulnerability identified in the Tailscale Windows client allows a malicious website to reconfigure the Tailscale daemon `tailscaled`, which can then be used to remotely execute code.
network
low complexity
tailscale CWE-346
critical
9.6
2022-10-13 CVE-2022-3457 Origin Validation Error vulnerability in Ikus-Soft Rdiffweb
Origin Validation Error in GitHub repository ikus060/rdiffweb prior to 2.5.0a5.
network
low complexity
ikus-soft CWE-346
critical
9.8
2022-10-10 CVE-2022-41749 Origin Validation Error vulnerability in Trendmicro Apex ONE 2019
An origin validation error vulnerability in Trend Micro Apex One agents could allow a local attacker to escalate privileges on affected installations.
local
low complexity
trendmicro CWE-346
7.8
2022-10-06 CVE-2022-41294 Origin Validation Error vulnerability in IBM Robotic Process Automation
IBM Robotic Process Automation 21.0.0, 21.0.1, 21.0.2, 21.0.3, and 21.0.4 is vulnerable to cross origin resource sharing using the bot api.
network
low complexity
ibm CWE-346
6.5
2022-07-26 CVE-2022-1497 Origin Validation Error vulnerability in Google Chrome
Inappropriate implementation in Input in Google Chrome prior to 101.0.4951.41 allowed a remote attacker to spoof the contents of cross-origin websites via a crafted HTML page.
network
low complexity
google CWE-346
6.5
2022-06-28 CVE-2022-23763 Origin Validation Error vulnerability in Douzone Neors
Origin validation error vulnerability in NeoRS’s ActiveX moudle allows attackers to download and execute arbitrary files.
network
douzone CWE-346
6.8
2022-06-24 CVE-2022-1747 Origin Validation Error vulnerability in Dominionvoting Imagecast X 5.5.10.30/5.5.10.32
The authentication mechanism used by voters to activate a voting session on the tested version of Dominion Voting Systems ImageCast X is susceptible to forgery.
local
low complexity
dominionvoting CWE-346
2.1