Skip to main content

CWE archive

CWE-346 CVEs

Programmatic archive

717 CVEs tagged with CWE-34667 Critical, 232 High, 387 Medium, 30 Low, 1 Unrated.

CVE-2018-6654

Published Feb 6, 2018

The Grammarly extension before 2018-02-02 for Chrome allows remote attackers to discover authentication tokens via an 'action: "user"' request to iframe.gr_-ifr, because the expos…

CVSS 8.8 · High
Vendor/product tagsBeta · best-effort

CVE-2017-18016

Published Jan 11, 2018

Parity Browser 1.6.10 and earlier allows remote attackers to bypass the Same Origin Policy and obtain sensitive information by requesting other websites via the Parity web proxy e…

CVSS 5.3 · Medium
Vendor/product tagsBeta · best-effort

CVE-2017-1000455

Published Jan 2, 2018

GuixSD prior to Git commit 5e66574a128937e7f2fcf146d146225703ccfd5d used POSIX hard links incorrectly, leading the creation of setuid executables in "the store", violating a funda…

CVSS 5.5 · Medium
Vendor/product tagsBeta · best-effort

CVE-2017-0902

Published Aug 31, 2017

RubyGems version 2.6.12 and earlier is vulnerable to a DNS hijacking vulnerability that allows a MITM attacker to force the RubyGems client to download and install gems from a ser…

CVSS 8.1 · High

CVE-2017-8650

Published Aug 8, 2017

Microsoft Edge in Microsoft Windows 10 1703 allows an attacker to exploit a security feature bypass due to Microsoft Edge not properly enforcing same-origin policies, aka "Microso…

CVSS 5.4 · Medium
Vendor/product tagsBeta · best-effort

CVE-2017-7667

Published Jun 12, 2017

Apache NiFi before 0.7.4 and 1.x before 1.3.0 need to establish the response header telling browsers to only allow framing with the same origin.

CVSS 7.5 · High
Vendor/product tagsBeta · best-effort

CVE-2017-5646

Published May 26, 2017

For versions of Apache Knox from 0.2.0 to 0.11.0 - an authenticated user may use a specially crafted URL to impersonate another user while accessing WebHDFS through Apache Knox. T…

CVSS 6.8 · Medium
Vendor/product tagsBeta · best-effort

CVE-2017-8793

Published May 5, 2017

An issue was discovered on Accellion FTA devices before FTA_9_12_180. By sending a POST request to home/seos/courier/web/wmProgressstat.html.php with an attacker domain in the aca…

CVSS 8.8 · High
Vendor/product tagsBeta · best-effort

CVE-2017-6519

Published May 1, 2017

avahi-daemon in Avahi through 0.6.32 and 0.7 inadvertently responds to IPv6 unicast queries with source addresses that are not on-link, which allows remote attackers to cause a de…

CVSS 9.1 · Critical
Vendor/product tagsBeta · best-effort

CVE-2016-5168

Published Apr 21, 2017

Skia, as used in Google Chrome before 50.0.2661.94, allows remote attackers to bypass the Same Origin Policy and obtain sensitive information.

CVSS 7.5 · High
Vendor/product tagsBeta · best-effort

CVE-2017-5858

Published Feb 9, 2017

An incorrect implementation of "XEP-0280: Message Carbons" in multiple XMPP clients allows a remote attacker to impersonate any user, including contacts, in the vulnerable applica…

CVSS 5.9 · Medium
Vendor/product tagsBeta · best-effort

CVE-2017-5606

Published Feb 9, 2017

An incorrect implementation of "XEP-0280: Message Carbons" in multiple XMPP clients allows a remote attacker to impersonate any user, including contacts, in the vulnerable applica…

CVSS 5.9 · Medium
Vendor/product tagsBeta · best-effort

CVE-2017-5605

Published Feb 9, 2017

An incorrect implementation of "XEP-0280: Message Carbons" in multiple XMPP clients allows a remote attacker to impersonate any user, including contacts, in the vulnerable applica…

CVSS 5.9 · Medium
Vendor/product tagsBeta · best-effort

CVE-2017-5604

Published Feb 9, 2017

An incorrect implementation of "XEP-0280: Message Carbons" in multiple XMPP clients allows a remote attacker to impersonate any user, including contacts, in the vulnerable applica…

CVSS 5.9 · Medium
Vendor/product tagsBeta · best-effort

CVE-2017-5603

Published Feb 9, 2017

An incorrect implementation of "XEP-0280: Message Carbons" in multiple XMPP clients allows a remote attacker to impersonate any user, including contacts, in the vulnerable applica…

CVSS 5.9 · Medium
Vendor/product tagsBeta · best-effort

CVE-2017-5602

Published Feb 9, 2017

An incorrect implementation of "XEP-0280: Message Carbons" in multiple XMPP clients allows a remote attacker to impersonate any user, including contacts, in the vulnerable applica…

CVSS 5.9 · Medium
Vendor/product tagsBeta · best-effort

CVE-2017-5593

Published Feb 9, 2017

An incorrect implementation of "XEP-0280: Message Carbons" in multiple XMPP clients allows a remote attacker to impersonate any user, including contacts, in the vulnerable applica…

CVSS 5.9 · Medium
Vendor/product tagsBeta · best-effort

CVE-2017-5592

Published Feb 9, 2017

An incorrect implementation of "XEP-0280: Message Carbons" in multiple XMPP clients allows a remote attacker to impersonate any user, including contacts, in the vulnerable applica…

CVSS 5.9 · Medium
Vendor/product tagsBeta · best-effort

CVE-2017-5590

Published Feb 9, 2017

An incorrect implementation of "XEP-0280: Message Carbons" in multiple XMPP clients allows a remote attacker to impersonate any user, including contacts, in the vulnerable applica…

CVSS 5.9 · Medium
Vendor/product tagsBeta · best-effort

CVE-2017-5589

Published Feb 9, 2017

An incorrect implementation of "XEP-0280: Message Carbons" in multiple XMPP clients allows a remote attacker to impersonate any user, including contacts, in the vulnerable applica…

CVSS 5.9 · Medium
Vendor/product tagsBeta · best-effort
Showing 676-700 of 717 CVEsPage 28 of 29