CWE-1021
400 CVEs • Abstraction: Base
Improper Restriction of Rendered UI Layers or Frames
The web application does not restrict or incorrectly restricts frame objects or UI layers that belong to another application or domain, which can lead to user confusion about which interface the user is interacting with.
CVEs (400)
CVE VENDORS PRODUCTS UPDATED PUBLISHED CVSS |
|---|
In onCreate of BluetoothPairingDialog.java, there is a possible tapjacking vector due to an insecure default value. This could lead to local escalation of privilege and untrusted devices accessing contact lists with no a...Show more |
In onCreate of RequestPermissionActivity.java, there is a possible tapjacking vector due to an insecure default value. This could lead to local escalation of privilege allowing an attacker to set Bluetooth discoverabilit...Show more |
This affects the package MintegralAdSDK from 0.0.0. The SDK distributed by the company contains malicious functionality that tracks any URL opened by the app and reports it back to the company, along with performing adve...Show more |
1Ibm 1Security Guardium Insights Jun 17, 2026 Aug 24, 2020 N/A· v4 5.4 MEDIUM· v3 3.5 LOW· v2 IBM Security Guardium Insights 2.0.1 could allow a remote attacker to hijack the clicking action of the victim. By persuading a victim to visit a malicious Web site, a remote attacker could exploit this vulnerability to...Show more |
1Teradici 1Pcoip Management Console Jun 17, 2026 Aug 11, 2020 N/A· v4 6.1 MEDIUM· v3 4.3 MEDIUM· v2 The web server in the Teradici Managament console versions 20.04 and 20.01.1 did not properly set the X-Frame-Options HTTP header, which could allow an attacker to trick a user into clicking a malicious link via clickjac...Show more |
1Mozilla 2Firefox ThunderbirdJun 17, 2026 Aug 10, 2020 N/A· v4 6.5 MEDIUM· v3 4.3 MEDIUM· v2 Using object or embed tags, it was possible to frame other websites, even if they disallowed framing using the X-Frame-Options header. This vulnerability affects Thunderbird < 78 and Firefox < 78.0.2. |
1Ibm 1Planning Analytics Local Jun 17, 2026 Jul 29, 2020 N/A· v4 5.4 MEDIUM· v3 5.8 MEDIUM· v2 IBM Planning Analytics Local 2.0.0 through 2.0.9.1 could allow a remote attacker to hijack the clicking action of the victim. By persuading a victim to visit a malicious Web site, a remote attacker could exploit this vul...Show more |
"HCL AppScan Enterprise advisory API documentation is susceptible to clickjacking, which could allow an attacker to embed the contents of untrusted web pages in a frame." |
IBM Security Secret Server 10.7 could allow a remote attacker to hijack the clicking action of the victim. By persuading a victim to visit a malicious Web site, a remote attacker could exploit this vulnerability to hijac...Show more |
1Ibm 2Spectrum Protect Client Spectrum Protect For Space ManagementJun 17, 2026 Jun 15, 2020 N/A· v4 5.4 MEDIUM· v3 3.5 LOW· v2 IBM Spectrum Protect Client 8.1.7.0 through 8.1.9.1 (Linux and Windows), 8.1.9.0 trough 8.1.9.1 (AIX) and IBM Spectrum Protect for Space Management 8.1.7.0 through 8.1.9.1 (Linux), 8.1.9.0 through 8.1.9.1 (AIX) web user...Show more |
IBM API Connect V2018.4.1.0 through 2018.4.1.10 could allow a remote attacker to hijack the clicking action of the victim. By persuading a victim to visit a malicious Web site, a remote attacker could exploit this vulner...Show more |
When following a link that opened an intent://-schemed URL, causing a custom tab to be opened, Firefox for Android could be tricked into displaying the incorrect URI. <br> *Note: This issue only affects Firefox for Andro...Show more |
Zulip Server before 2.1.3 allows reverse tabnabbing via the Markdown functionality. |
1Westerndigital 2Ibi My Cloud HomeJun 17, 2026 Apr 15, 2020 N/A· v4 4.7 MEDIUM· v3 4.3 MEDIUM· v2 Western Digital My Cloud Home and ibi devices before 2.2.0 allow clickjacking on sign-in pages. |
2Quarkus Redhat2Keycloak QuarkusJun 17, 2026 Apr 6, 2020 N/A· v4 5.4 MEDIUM· v3 5.8 MEDIUM· v2 A vulnerability was found in all versions of Keycloak where, the pages on the Admin Console area of the application are completely missing general HTTP security headers in HTTP-responses. This does not directly lead to a...Show more |
For ABB eSOMS versions 4.0 to 6.0.2, the X-Frame-Options header is not configured in HTTP response. This can potentially allow 'ClickJacking' attacks where an attacker can frame parts of the application on a malicious we...Show more |
In onCreate of SettingsHomepageActivity, there is a possible tapjacking attack. This could lead to local escalation of privilege in Settings with no additional execution privileges needed. User interaction is needed for...Show more |
There is an improper restriction of rendered UI layers or frames vulnerability in Micro Focus Service Manager Release Control versions 9.50 and 9.60. The vulnerability may result in the ability of malicious users to perf...Show more |
Parts of the Puppet Enterprise Console 3.x were found to be susceptible to clickjacking and CSRF (Cross-Site Request Forgery) attacks. This would allow an attacker to redirect user input to an untrusted site or hijack a...Show more |
Mozilla Firefox before 25 allows modification of anonymous content of pluginProblem.xml binding |