Vulnerabilities (CVE)

Filtered by CWE-1275
Total 24 CVE
CVE Vendors Products Updated CVSS v2 CVSS v3
CVE-2024-42212 1 Hcltech 1 Bigfix Compliance 2025-06-17 N/A 5.4 MEDIUM
HCL BigFix Compliance is affected by an improper or missing SameSite attribute. This can lead to Cross-Site Request Forgery (CSRF) attacks, where a malicious site could trick a user's browser into making unintended requests using authenticated sessions.
CVE-2024-6611 1 Mozilla 2 Firefox, Thunderbird 2025-04-04 N/A 9.8 CRITICAL
A nested iframe, triggering a cross-site navigation, could send SameSite=Strict or Lax cookies. This vulnerability affects Firefox < 128 and Thunderbird < 128.
CVE-2025-24387 1 Otrs 1 Otrs 2025-03-24 N/A 4.8 MEDIUM
A vulnerability in OTRS Application Server allows session hijacking due to missing attributes for sensitive cookie settings in HTTPS sessions. A request to an OTRS endpoint from a possible malicious web site, would send the authentication cookie, performing an unwanted read operation.   This issue affects: * OTRS 7.0.X * OTRS 8.0.X * OTRS 2023.X * OTRS 2024.X * OTRS 2025.x
CVE-2024-43173 1 Ibm 1 Concert 2024-10-25 N/A 3.7 LOW
IBM Concert 1.0.0 and 1.0.1 vulnerable to attacks that rely on the use of cookies without the SameSite attribute.