Vulnerabilities > Origin Validation Error
DATE | CVE | VULNERABILITY TITLE | RISK |
---|---|---|---|
2022-02-12 | CVE-2022-0120 | Origin Validation Error vulnerability in multiple products Inappropriate implementation in Passwords in Google Chrome prior to 97.0.4692.71 allowed a remote attacker to potentially leak cross-origin data via a malicious website. | 6.5 |
2022-01-25 | CVE-2022-23032 | Origin Validation Error vulnerability in F5 Big-Ip Access Policy Manager In all versions before 7.2.1.4, when proxy settings are configured in the network access resource of a BIG-IP APM system, connecting BIG-IP Edge Client on Mac and Windows is vulnerable to a DNS rebinding attack. | 5.0 |
2022-01-10 | CVE-2021-44458 | Origin Validation Error vulnerability in Mirantis Lens Linux users running Lens 5.2.6 and earlier could be compromised by visiting a malicious website. | 5.1 |
2022-01-10 | CVE-2021-45441 | Origin Validation Error vulnerability in Trendmicro products A origin validation error vulnerability in Trend Micro Apex One (on-prem and SaaS) could allow a local attacker drop and manipulate a specially crafted file to issue commands over a certain pipe and elevate to a higher level of privileges. | 7.2 |
2021-12-23 | CVE-2021-4024 | Origin Validation Error vulnerability in multiple products A flaw was found in podman. | 6.5 |
2021-12-14 | CVE-2021-44935 | Origin Validation Error vulnerability in Glfusion 1.7.9 glFusion CMS v1.7.9 is affected by an arbitrary user impersonation vulnerability in /public_html/comment.php. | 6.4 |
2021-12-13 | CVE-2021-39063 | Origin Validation Error vulnerability in IBM Spectrum Protect Plus IBM Spectrum Protect Plus 10.1.0.0 through 10.1.8.x uses Cross-Origin Resource Sharing (CORS) which could allow an attacker to carry out privileged actions and retrieve sensitive information due to a misconfiguration in access control headers. | 6.4 |
2021-12-08 | CVE-2021-38507 | Origin Validation Error vulnerability in multiple products The Opportunistic Encryption feature of HTTP2 (RFC 8164) allows a connection to be transparently upgraded to TLS while retaining the visual properties of an HTTP connection, including being same-origin with unencrypted connections on port 80. | 6.5 |
2021-12-08 | CVE-2021-43531 | Origin Validation Error vulnerability in Mozilla Firefox When a user loaded a Web Extensions context menu, the Web Extension could access the post-redirect URL of the element clicked. | 4.3 |
2021-11-03 | CVE-2021-38497 | Origin Validation Error vulnerability in Mozilla Firefox Through use of reportValidity() and window.open(), a plain-text validation message could have been overlaid on another origin, leading to possible user confusion and spoofing attacks. | 4.3 |