CWE-1021
400 CVEs • Abstraction: Base
Improper Restriction of Rendered UI Layers or Frames
The web application does not restrict or incorrectly restricts frame objects or UI layers that belong to another application or domain, which can lead to user confusion about which interface the user is interacting with.
CVEs (400)
CVE VENDORS PRODUCTS UPDATED PUBLISHED CVSS |
|---|
Insufficient data validation in UI in Google Chrome prior to 87.0.4280.66 allowed a remote attacker to spoof the contents of the Omnibox (URL bar) via a crafted HTML page. |
Vidyo 02-09-/D allows clickjacking via the portal/ URI. |
1Schneider Electric 1Easergy T300 Firmware Jun 17, 2026 Dec 11, 2020 N/A· v4 6.5 MEDIUM· v3 4.3 MEDIUM· v2 A CWE-1021: Improper Restriction of Rendered UI Layers or Frames vulnerability exists in Easergy T300 (firmware 2.7 and older), that would allow an attacker to trick a user into initiating an unintended action. |
Cross-origin iframes that contained a login form could have been recognized by the login autofill service, and populated. This could have been used in clickjacking attacks, as well as be read across partitions in dynamic...Show more |
1Mozilla 3Firefox Firefox EsrThunderbirdJun 17, 2026 Dec 9, 2020 N/A· v4 4.3 MEDIUM· v3 4.3 MEDIUM· v2 It was possible to cause the browser to enter fullscreen mode without displaying the security UI; thus making it possible to attempt a phishing attack or otherwise confuse the user. This vulnerability affects Firefox < 8...Show more |
1Apple 4Ipados Iphone OsSafari+1 moreJun 17, 2026 Dec 8, 2020 N/A· v4 4.3 MEDIUM· v3 4.3 MEDIUM· v2 The issue was addressed with improved UI handling. This issue is fixed in watchOS 7.0, Safari 14.0, iOS 14.0 and iPadOS 14.0. Visiting a malicious website may lead to address bar spoofing. |
An inconsistent user interface issue was addressed with improved state management. This issue is fixed in Safari 14.0. Visiting a malicious website may lead to address bar spoofing. |
A spoofing issue existed in the handling of URLs. This issue was addressed with improved input validation. This issue is fixed in macOS Big Sur 11.0.1, Safari 14.0.1. Visiting a malicious website may lead to address bar...Show more |
An inconsistent user interface issue was addressed with improved state management. This issue is fixed in macOS Big Sur 11.0.1, Safari 13.1.2. Visiting a malicious website may lead to address bar spoofing. |
Improper restriction of rendered UI layers or frames in EC-CUBE versions from 3.0.0 to 3.0.18 leads to clickjacking attacks. If a user accesses a specially crafted page while logged into the administrative page, unintend...Show more |
1Ibm 1App Connect Enterprise Certified Container Jun 17, 2026 Nov 3, 2020 N/A· v4 5.4 MEDIUM· v3 4.9 MEDIUM· v2 IBM App Connect Enterprise Certified Container 1.0.0, 1.0.1, 1.0.2, 1.0.3, and 1.0.4 could allow a remote attacker to hijack the clicking action of the victim. By persuading a victim to visit a malicious Web site, a remo...Show more |
The Reset button on the Account Settings page in Gophish before 0.11.0 allows attackers to cause a denial of service via a clickjacking attack |
This issue was addressed with improved iframe sandbox enforcement. This issue is fixed in Safari 13.0.1, iOS 13. Maliciously crafted web content may violate iframe sandboxing policy. |
1Raiseitsolutions 1Rits Browser Jun 17, 2026 Oct 20, 2020 N/A· v4 4.3 MEDIUM· v3 4.3 MEDIUM· v2 User Interface (UI) Misrepresentation of Critical Information vulnerability in the address bar of the Yandex Browser allows an attacker to obfuscate the true source of data as presented in the browser. This issue affects...Show more |
A vulnerability has been identified in Desigo Insight (All versions). The device does not properly set the X-Frame-Options HTTP Header which makes it vulnerable to Clickjacking attacks. This could allow an unauthenticate...Show more |
1Ibm 1Infosphere Information Server Jun 17, 2026 Sep 25, 2020 N/A· v4 6.1 MEDIUM· v3 4.3 MEDIUM· v2 IBM InfoSphere Information Server 11.7 could allow a remote attacker to hijack the clicking action of the victim. By persuading a victim to visit a malicious Web site, a remote attacker could exploit this vulnerability t...Show more |
1Gogogate 1Ismartgate Pro Firmware Jun 17, 2026 Sep 24, 2020 N/A· v4 8.1 HIGH· v3 4.3 MEDIUM· v2 ismartgate PRO 1.5.9 is vulnerable to clickjacking. |
3Debian FedoraprojectGoogle3Chrome Debian LinuxFedoraJun 17, 2026 Sep 21, 2020 N/A· v4 6.5 MEDIUM· v3 4.3 MEDIUM· v2 Incorrect security UI in media in Google Chrome prior to 84.0.4147.125 allowed a remote attacker to potentially obtain sensitive information via a crafted HTML page. |
In PackageInstaller, there is a possible permissions bypass due to a tapjacking vulnerability. This could lead to local escalation of privilege using an app set as the default Assist app with User execution privileges ne...Show more |
In manifest files of the SmartSpace package, there is a possible tapjacking vector due to a missing permission check. This could lead to local escalation of privilege and account hijacking with no additional execution pr...Show more |