Skip to main content

CWE archive

CWE-346 CVEs

Programmatic archive

627 CVEs tagged with CWE-34664 Critical, 217 High, 324 Medium, 21 Low, 1 Unrated.

CVE-2019-11723

Published Jul 23, 2019

A vulnerability exists during the installation of add-ons where the initial fetch ignored the origin attributes of the browsing context. This could leak cookies in private browsin…

CVSS 7.5 · High
Vendor/product tagsBeta · best-effort

CVE-2019-8282

Published Jun 7, 2019

Gemalto Admin Control Center, all versions prior to 7.92, uses cleartext HTTP to communicate with www3.safenet-inc.com to obtain language packs. This allows attacker to do man-in-…

CVSS 5.3 · Medium
Vendor/product tagsBeta · best-effort

CVE-2018-5409

Published May 8, 2019

The PrinterLogic Print Management software, versions up to and including 18.3.1.96, updates and executes the code without sufficiently verifying the origin and integrity of the co…

CVSS 9.8 · Critical
evidence mentions
1
Buzz score
11.9
Vendor/product tagsBeta · best-effort

CVE-2019-9808

Published Apr 26, 2019

If WebRTC permission is requested from documents with data: or blob: URLs, the permission notifications do not properly display the originating domain. The notification states "Un…

CVSS 5.3 · Medium
Vendor/product tagsBeta · best-effort

CVE-2019-9803

Published Apr 26, 2019

The Upgrade-Insecure-Requests (UIR) specification states that if UIR is enabled through Content Security Policy (CSP), navigation to a same-origin URL must be upgraded to HTTPS. F…

CVSS 7.4 · High
Vendor/product tagsBeta · best-effort

CVE-2019-9797

Published Apr 26, 2019

Cross-origin images can be read in violation of the same-origin policy by exporting an image after using createImageBitmap to read the image and then rendering the resulting bitma…

CVSS 5.3 · Medium
Vendor/product tagsBeta · best-effort

CVE-2019-9764

Published Mar 26, 2019

HashiCorp Consul 1.4.3 lacks server hostname verification for agent-to-agent TLS communication. In other words, the product behaves as if verify_server_hostname were set to false,…

CVSS 7.4 · High
Vendor/product tagsBeta · best-effort

CVE-2018-18494

Published Feb 28, 2019

A same-origin policy violation allowing the theft of cross-origin URL entries when using the Javascript location property to cause a redirection to another site using performance.…

CVSS 6.5 · Medium

CVE-2018-12402

Published Feb 28, 2019

The internal WebBrowserPersist code does not use correct origin context for a resource being saved. This manifests when sub-resources are loaded as part of "Save Page As..." funct…

CVSS 6.5 · Medium
Vendor/product tagsBeta · best-effort

CVE-2019-7399

Published Feb 17, 2019

Amazon Fire OS before 5.3.6.4 allows a man-in-the-middle attack against HTTP requests for "Terms of Use" and Privacy pages.

CVSS 7.4 · High
Vendor/product tagsBeta · best-effort

CVE-2018-20745

Published Jan 28, 2019

Yii 2.x through 2.0.15.1 actively converts a wildcard CORS policy into reflecting an arbitrary Origin header value, which is incompatible with the CORS security design, and could…

CVSS 5.9 · Medium
Vendor/product tagsBeta · best-effort

CVE-2018-20744

Published Jan 28, 2019

The Olivier Poitrey Go CORS handler through 1.3.0 actively converts a wildcard CORS policy into reflecting an arbitrary Origin header value, which is incompatible with the CORS se…

CVSS 5.9 · Medium
Vendor/product tagsBeta · best-effort

CVE-2018-16072

Published Jan 9, 2019

A missing origin check related to HLS manifests in Blink in Google Chrome prior to 69.0.3497.81 allowed a remote attacker to bypass same origin policy via a crafted HTML page.

CVSS 6.5 · Medium
Vendor/product tagsBeta · best-effort

CVE-2018-14903

Published Aug 30, 2018

EPSON WF-2750 printers with firmware JP02I2 do not properly validate files before running updates, which allows remote attackers to cause a printer malfunction or send malicious d…

CVSS 7.5 · High
Vendor/product tagsBeta · best-effort

CVE-2018-3834

Published Aug 2, 2018

An exploitable permanent denial of service vulnerability exists in Insteon Hub running firmware version 1013. The firmware upgrade functionality, triggered via PubNub, retrieves s…

CVSS 7.4 · High
Vendor/product tagsBeta · best-effort
Showing 551-575 of 627 CVEsPage 23 of 26