Skip to main content

CWE archive

CWE-346 CVEs

Programmatic archive

717 CVEs tagged with CWE-34667 Critical, 232 High, 387 Medium, 30 Low, 1 Unrated.

CVE-2019-9764

Published Mar 26, 2019

HashiCorp Consul 1.4.3 lacks server hostname verification for agent-to-agent TLS communication. In other words, the product behaves as if verify_server_hostname were set to false,…

CVSS 7.4 · High
Vendor/product tagsBeta · best-effort

CVE-2018-18494

Published Feb 28, 2019

A same-origin policy violation allowing the theft of cross-origin URL entries when using the Javascript location property to cause a redirection to another site using performance.…

CVSS 6.5 · Medium

CVE-2018-12402

Published Feb 28, 2019

The internal WebBrowserPersist code does not use correct origin context for a resource being saved. This manifests when sub-resources are loaded as part of "Save Page As..." funct…

CVSS 6.5 · Medium
Vendor/product tagsBeta · best-effort

CVE-2019-7399

Published Feb 17, 2019

Amazon Fire OS before 5.3.6.4 allows a man-in-the-middle attack against HTTP requests for "Terms of Use" and Privacy pages.

CVSS 7.4 · High
Vendor/product tagsBeta · best-effort

CVE-2018-20745

Published Jan 28, 2019

Yii 2.x through 2.0.15.1 actively converts a wildcard CORS policy into reflecting an arbitrary Origin header value, which is incompatible with the CORS security design, and could…

CVSS 5.9 · Medium
Vendor/product tagsBeta · best-effort

CVE-2018-20744

Published Jan 28, 2019

The Olivier Poitrey Go CORS handler through 1.3.0 actively converts a wildcard CORS policy into reflecting an arbitrary Origin header value, which is incompatible with the CORS se…

CVSS 5.9 · Medium
Vendor/product tagsBeta · best-effort

CVE-2018-16072

Published Jan 9, 2019

A missing origin check related to HLS manifests in Blink in Google Chrome prior to 69.0.3497.81 allowed a remote attacker to bypass same origin policy via a crafted HTML page.

CVSS 6.5 · Medium
Vendor/product tagsBeta · best-effort

CVE-2018-14903

Published Aug 30, 2018

EPSON WF-2750 printers with firmware JP02I2 do not properly validate files before running updates, which allows remote attackers to cause a printer malfunction or send malicious d…

CVSS 7.5 · High
Vendor/product tagsBeta · best-effort

CVE-2018-3834

Published Aug 2, 2018

An exploitable permanent denial of service vulnerability exists in Insteon Hub running firmware version 1013. The firmware upgrade functionality, triggered via PubNub, retrieves s…

CVSS 7.4 · High
Vendor/product tagsBeta · best-effort

CVE-2018-5157

Published Jun 11, 2018

Same-origin protections for the PDF viewer can be bypassed, allowing a malicious site to intercept messages meant for the viewer. This could allow the site to retrieve PDF files r…

CVSS 7.5 · High

CVE-2018-5116

Published Jun 11, 2018

WebExtensions with the "ActiveTab" permission are able to access frames hosted within the active tab even if the frames are cross-origin. Malicious extensions can inject frames fr…

CVSS 9.8 · Critical
Vendor/product tagsBeta · best-effort

CVE-2018-5109

Published Jun 11, 2018

An audio capture session can started under an incorrect origin from the site making the capture request. Users are still prompted to allow the request but the prompt can display t…

CVSS 5.3 · Medium
Vendor/product tagsBeta · best-effort

CVE-2017-7808

Published Jun 11, 2018

A content security policy (CSP) "frame-ancestors" directive containing origins with paths allows for comparisons against those paths instead of the origin. This results in a cross…

CVSS 5.3 · Medium
Vendor/product tagsBeta · best-effort

CVE-2017-7797

Published Jun 11, 2018

Response header name interning does not have same-origin protections and these headers are stored in a global registry. This allows stored header names to be available cross-origi…

CVSS 7.5 · High
Vendor/product tagsBeta · best-effort

CVE-2018-8112

Published May 9, 2018

A security feature bypass vulnerability exists when Microsoft Edge improperly handles requests of different origins, aka "Microsoft Edge Security Feature Bypass Vulnerability." Th…

CVSS 4.3 · Medium
Vendor/product tagsBeta · best-effort

CVE-2017-13274

Published Apr 4, 2018

In the getHost() function of UriTest.java, there is the possibility of incorrect web origin determination. This could lead to incorrect security decisions with no additional execu…

CVSS 9.8 · Critical
Vendor/product tagsBeta · best-effort
Showing 651-675 of 717 CVEsPage 27 of 29