Vulnerabilities > Origin Validation Error

DATE CVE VULNERABILITY TITLE RISK
2022-12-22 CVE-2022-38472 Origin Validation Error vulnerability in Mozilla Thunderbird
An attacker could have abused XSLT error handling to associate attacker-controlled content with another origin which was displayed in the address bar.
network
low complexity
mozilla CWE-346
6.5
2022-12-22 CVE-2022-42927 Origin Validation Error vulnerability in Mozilla Firefox
A same-origin policy violation could have allowed the theft of cross-origin URL entries, leaking the result of a redirect, via `performance.getEntries()`.
network
low complexity
mozilla CWE-346
8.1
2022-11-23 CVE-2022-41924 Origin Validation Error vulnerability in Tailscale
A vulnerability identified in the Tailscale Windows client allows a malicious website to reconfigure the Tailscale daemon `tailscaled`, which can then be used to remotely execute code.
network
low complexity
tailscale CWE-346
critical
9.6
2022-10-10 CVE-2022-41749 Origin Validation Error vulnerability in Trendmicro Apex ONE 2019
An origin validation error vulnerability in Trend Micro Apex One agents could allow a local attacker to escalate privileges on affected installations.
local
low complexity
trendmicro CWE-346
7.8
2022-10-06 CVE-2022-41294 Origin Validation Error vulnerability in IBM Robotic Process Automation
IBM Robotic Process Automation 21.0.0, 21.0.1, 21.0.2, 21.0.3, and 21.0.4 is vulnerable to cross origin resource sharing using the bot api.
network
low complexity
ibm CWE-346
6.5
2022-09-19 CVE-2022-40140 Origin Validation Error vulnerability in Trendmicro Apex ONE 2019
An origin validation error vulnerability in Trend Micro Apex One and Apex One as a Service could allow a local attacker to cause a denial-of-service on affected installations.
local
low complexity
trendmicro CWE-346
5.5
2022-08-17 CVE-2022-23764 Origin Validation Error vulnerability in Teruten Webcube 1.0.5.5
The vulnerability causing from insufficient verification procedures for downloaded files during WebCube update.
network
low complexity
teruten CWE-346
critical
9.8
2022-07-26 CVE-2022-1497 Origin Validation Error vulnerability in Google Chrome
Inappropriate implementation in Input in Google Chrome prior to 101.0.4951.41 allowed a remote attacker to spoof the contents of cross-origin websites via a crafted HTML page.
network
low complexity
google CWE-346
6.5
2022-07-20 CVE-2022-26137 Origin Validation Error vulnerability in Atlassian products
A vulnerability in multiple Atlassian products allows a remote, unauthenticated attacker to cause additional Servlet Filters to be invoked when the application processes requests or responses.
network
low complexity
atlassian CWE-346
8.8
2022-06-28 CVE-2022-23763 Origin Validation Error vulnerability in Douzone Neors
Origin validation error vulnerability in NeoRS’s ActiveX moudle allows attackers to download and execute arbitrary files.
network
low complexity
douzone CWE-346
8.8