CWE-1021
412 CVEs • Abstraction: Base
Improper Restriction of Rendered UI Layers or Frames
The web application does not restrict or incorrectly restricts frame objects or UI layers that belong to another application or domain, which can lead to user confusion about which interface the user is interacting with.
CVEs (412)
CVE VENDORS PRODUCTS UPDATED PUBLISHED CVSS |
|---|
An inconsistent user interface issue was addressed with improved state management. This issue is fixed in macOS Big Sur 11.0.1, Safari 13.1.2. Visiting a malicious website may lead to address bar spoofing. |
Improper restriction of rendered UI layers or frames in EC-CUBE versions from 3.0.0 to 3.0.18 leads to clickjacking attacks. If a user accesses a specially crafted page while logged into the administrative page, unintend...Show more |
1Ibm 1App Connect Enterprise Certified Container Jun 17, 2026 Nov 3, 2020 N/A· v4 5.4 MEDIUM· v3 4.9 MEDIUM· v2 IBM App Connect Enterprise Certified Container 1.0.0, 1.0.1, 1.0.2, 1.0.3, and 1.0.4 could allow a remote attacker to hijack the clicking action of the victim. By persuading a victim to visit a malicious Web site, a remo...Show more |
The Reset button on the Account Settings page in Gophish before 0.11.0 allows attackers to cause a denial of service via a clickjacking attack |
This issue was addressed with improved iframe sandbox enforcement. This issue is fixed in Safari 13.0.1, iOS 13. Maliciously crafted web content may violate iframe sandboxing policy. |
1Raiseitsolutions 1Rits Browser Jun 17, 2026 Oct 20, 2020 N/A· v4 4.3 MEDIUM· v3 4.3 MEDIUM· v2 User Interface (UI) Misrepresentation of Critical Information vulnerability in the address bar of the Yandex Browser allows an attacker to obfuscate the true source of data as presented in the browser. This issue affects...Show more |
A vulnerability has been identified in Desigo Insight (All versions). The device does not properly set the X-Frame-Options HTTP Header which makes it vulnerable to Clickjacking attacks. This could allow an unauthenticate...Show more |
1Ibm 1Infosphere Information Server Jun 17, 2026 Sep 25, 2020 N/A· v4 6.1 MEDIUM· v3 4.3 MEDIUM· v2 IBM InfoSphere Information Server 11.7 could allow a remote attacker to hijack the clicking action of the victim. By persuading a victim to visit a malicious Web site, a remote attacker could exploit this vulnerability t...Show more |
1Gogogate 1Ismartgate Pro Firmware Jun 17, 2026 Sep 24, 2020 N/A· v4 8.1 HIGH· v3 4.3 MEDIUM· v2 ismartgate PRO 1.5.9 is vulnerable to clickjacking. |
3Debian FedoraprojectGoogle3Chrome Debian LinuxFedoraJun 17, 2026 Sep 21, 2020 N/A· v4 6.5 MEDIUM· v3 4.3 MEDIUM· v2 Incorrect security UI in media in Google Chrome prior to 84.0.4147.125 allowed a remote attacker to potentially obtain sensitive information via a crafted HTML page. |
In PackageInstaller, there is a possible permissions bypass due to a tapjacking vulnerability. This could lead to local escalation of privilege using an app set as the default Assist app with User execution privileges ne...Show more |
In manifest files of the SmartSpace package, there is a possible tapjacking vector due to a missing permission check. This could lead to local escalation of privilege and account hijacking with no additional execution pr...Show more |
In onCreate of BluetoothPairingDialog.java, there is a possible tapjacking vector due to an insecure default value. This could lead to local escalation of privilege and untrusted devices accessing contact lists with no a...Show more |
In onCreate of RequestPermissionActivity.java, there is a possible tapjacking vector due to an insecure default value. This could lead to local escalation of privilege allowing an attacker to set Bluetooth discoverabilit...Show more |
This affects the package MintegralAdSDK from 0.0.0. The SDK distributed by the company contains malicious functionality that tracks any URL opened by the app and reports it back to the company, along with performing adve...Show more |
1Ibm 1Security Guardium Insights Jun 17, 2026 Aug 24, 2020 N/A· v4 5.4 MEDIUM· v3 3.5 LOW· v2 IBM Security Guardium Insights 2.0.1 could allow a remote attacker to hijack the clicking action of the victim. By persuading a victim to visit a malicious Web site, a remote attacker could exploit this vulnerability to...Show more |
1Teradici 1Pcoip Management Console Jun 17, 2026 Aug 11, 2020 N/A· v4 6.1 MEDIUM· v3 4.3 MEDIUM· v2 The web server in the Teradici Managament console versions 20.04 and 20.01.1 did not properly set the X-Frame-Options HTTP header, which could allow an attacker to trick a user into clicking a malicious link via clickjac...Show more |
1Mozilla 2Firefox ThunderbirdJun 17, 2026 Aug 10, 2020 N/A· v4 6.5 MEDIUM· v3 4.3 MEDIUM· v2 Using object or embed tags, it was possible to frame other websites, even if they disallowed framing using the X-Frame-Options header. This vulnerability affects Thunderbird < 78 and Firefox < 78.0.2. |
1Ibm 1Planning Analytics Local Jun 17, 2026 Jul 29, 2020 N/A· v4 5.4 MEDIUM· v3 5.8 MEDIUM· v2 IBM Planning Analytics Local 2.0.0 through 2.0.9.1 could allow a remote attacker to hijack the clicking action of the victim. By persuading a victim to visit a malicious Web site, a remote attacker could exploit this vul...Show more |
"HCL AppScan Enterprise advisory API documentation is susceptible to clickjacking, which could allow an attacker to embed the contents of untrusted web pages in a frame." |