← Back
CWE-1021

400 CVEs • Abstraction: Base

Improper Restriction of Rendered UI Layers or Frames

The web application does not restrict or incorrectly restricts frame objects or UI layers that belong to another application or domain, which can lead to user confusion about which interface the user is interacting with.

JSON object

Loading...

CVEs (400)

CVE
VENDORS
PRODUCTS
UPDATED
PUBLISHED
CVSS
1Google
1Android
Jun 17, 2026
Sep 17, 2020
N/A· v4
7.8 HIGH· v3
7.2 HIGH· v2
In onCreate of BluetoothPairingDialog.java, there is a possible tapjacking vector due to an insecure default value. This could lead to local escalation of privilege and untrusted devices accessing contact lists with no a...Show more
In onCreate of BluetoothPairingDialog.java, there is a possible tapjacking vector due to an insecure default value. This could lead to local escalation of privilege and untrusted devices accessing contact lists with no additional execution privileges needed. User interaction is needed for exploitation.Product: AndroidVersions: Android-8.0 Android-8.1 Android-9 Android-10 Android-11Android ID: A-155648639Show less
1Google
1Android
Jun 17, 2026
Sep 17, 2020
N/A· v4
5.5 MEDIUM· v3
4.3 MEDIUM· v2
In onCreate of RequestPermissionActivity.java, there is a possible tapjacking vector due to an insecure default value. This could lead to local escalation of privilege allowing an attacker to set Bluetooth discoverabilit...Show more
In onCreate of RequestPermissionActivity.java, there is a possible tapjacking vector due to an insecure default value. This could lead to local escalation of privilege allowing an attacker to set Bluetooth discoverability with User execution privileges needed. User interaction is needed for exploitation.Product: AndroidVersions: Android-8.0 Android-8.1 Android-9 Android-10 Android-11Android ID: A-155650356Show less
1Mintegral
1Mintegraladsdk
Jun 17, 2026
Aug 24, 2020
N/A· v4
8.1 HIGH· v3
5.8 MEDIUM· v2
This affects the package MintegralAdSDK from 0.0.0. The SDK distributed by the company contains malicious functionality that tracks any URL opened by the app and reports it back to the company, along with performing adve...Show more
This affects the package MintegralAdSDK from 0.0.0. The SDK distributed by the company contains malicious functionality that tracks any URL opened by the app and reports it back to the company, along with performing advertisement attribution fraud. Mintegral can remotely activate hooks on the UIApplication, openURL, SKStoreProductViewController, loadProductWithParameters and NSURLProtocol methods along with anti-debug and proxy detection protection. If those hooks are active MintegralAdSDK sends obfuscated data about every opened URL in an application to their servers. Note that the malicious functionality is enabled even if the SDK was not enabled to serve ads.Show less
1Ibm
1Security Guardium Insights
Jun 17, 2026
Aug 24, 2020
N/A· v4
5.4 MEDIUM· v3
3.5 LOW· v2
IBM Security Guardium Insights 2.0.1 could allow a remote attacker to hijack the clicking action of the victim. By persuading a victim to visit a malicious Web site, a remote attacker could exploit this vulnerability to...Show more
IBM Security Guardium Insights 2.0.1 could allow a remote attacker to hijack the clicking action of the victim. By persuading a victim to visit a malicious Web site, a remote attacker could exploit this vulnerability to hijack the victim's click actions and possibly launch further attacks against the victim. IBM X-Force ID: 174401.Show less
1Teradici
1Pcoip Management Console
Jun 17, 2026
Aug 11, 2020
N/A· v4
6.1 MEDIUM· v3
4.3 MEDIUM· v2
The web server in the Teradici Managament console versions 20.04 and 20.01.1 did not properly set the X-Frame-Options HTTP header, which could allow an attacker to trick a user into clicking a malicious link via clickjac...Show more
The web server in the Teradici Managament console versions 20.04 and 20.01.1 did not properly set the X-Frame-Options HTTP header, which could allow an attacker to trick a user into clicking a malicious link via clickjacking.Show less
1Mozilla
2Firefox
Thunderbird
Jun 17, 2026
Aug 10, 2020
N/A· v4
6.5 MEDIUM· v3
4.3 MEDIUM· v2
Using object or embed tags, it was possible to frame other websites, even if they disallowed framing using the X-Frame-Options header. This vulnerability affects Thunderbird < 78 and Firefox < 78.0.2.
1Ibm
1Planning Analytics Local
Jun 17, 2026
Jul 29, 2020
N/A· v4
5.4 MEDIUM· v3
5.8 MEDIUM· v2
IBM Planning Analytics Local 2.0.0 through 2.0.9.1 could allow a remote attacker to hijack the clicking action of the victim. By persuading a victim to visit a malicious Web site, a remote attacker could exploit this vul...Show more
IBM Planning Analytics Local 2.0.0 through 2.0.9.1 could allow a remote attacker to hijack the clicking action of the victim. By persuading a victim to visit a malicious Web site, a remote attacker could exploit this vulnerability to hijack the victim's click actions and possibly launch further attacks against the victim. IBM X-Force ID: 185716.Show less
1Hcltech
1Appscan
Jun 17, 2026
Jul 7, 2020
N/A· v4
4.3 MEDIUM· v3
4.3 MEDIUM· v2
"HCL AppScan Enterprise advisory API documentation is susceptible to clickjacking, which could allow an attacker to embed the contents of untrusted web pages in a frame."
1Ibm
1Security Secret Server
Jun 17, 2026
Jun 24, 2020
N/A· v4
4.3 MEDIUM· v3
4.3 MEDIUM· v2
IBM Security Secret Server 10.7 could allow a remote attacker to hijack the clicking action of the victim. By persuading a victim to visit a malicious Web site, a remote attacker could exploit this vulnerability to hijac...Show more
IBM Security Secret Server 10.7 could allow a remote attacker to hijack the clicking action of the victim. By persuading a victim to visit a malicious Web site, a remote attacker could exploit this vulnerability to hijack the victim's click actions and possibly launch further attacks against the victim. IBM X-Force ID: 177511.Show less
1Ibm
2Spectrum Protect Client
Spectrum Protect For Space Management
Jun 17, 2026
Jun 15, 2020
N/A· v4
5.4 MEDIUM· v3
3.5 LOW· v2
IBM Spectrum Protect Client 8.1.7.0 through 8.1.9.1 (Linux and Windows), 8.1.9.0 trough 8.1.9.1 (AIX) and IBM Spectrum Protect for Space Management 8.1.7.0 through 8.1.9.1 (Linux), 8.1.9.0 through 8.1.9.1 (AIX) web user...Show more
IBM Spectrum Protect Client 8.1.7.0 through 8.1.9.1 (Linux and Windows), 8.1.9.0 trough 8.1.9.1 (AIX) and IBM Spectrum Protect for Space Management 8.1.7.0 through 8.1.9.1 (Linux), 8.1.9.0 through 8.1.9.1 (AIX) web user interfaces could allow a remote attacker to hijack the clicking action of the victim. By persuading a victim to visit a malicious Web site, a remote attacker could exploit this vulnerability to hijack the victim's click actions and possibly launch further attacks against the victim. IBM X-Force ID: 179488.Show less
1Ibm
1Api Connect
Jun 17, 2026
May 12, 2020
N/A· v4
5.4 MEDIUM· v3
3.5 LOW· v2
IBM API Connect V2018.4.1.0 through 2018.4.1.10 could allow a remote attacker to hijack the clicking action of the victim. By persuading a victim to visit a malicious Web site, a remote attacker could exploit this vulner...Show more
IBM API Connect V2018.4.1.0 through 2018.4.1.10 could allow a remote attacker to hijack the clicking action of the victim. By persuading a victim to visit a malicious Web site, a remote attacker could exploit this vulnerability to hijack the victim's click actions and possibly launch further attacks against the victim. IBM X-Force ID: 174859.Show less
1Mozilla
1Firefox Esr
Jun 17, 2026
Apr 24, 2020
N/A· v4
4.7 MEDIUM· v3
4.3 MEDIUM· v2
When following a link that opened an intent://-schemed URL, causing a custom tab to be opened, Firefox for Android could be tricked into displaying the incorrect URI. <br> *Note: This issue only affects Firefox for Andro...Show more
When following a link that opened an intent://-schemed URL, causing a custom tab to be opened, Firefox for Android could be tricked into displaying the incorrect URI. <br> *Note: This issue only affects Firefox for Android. Other operating systems are unaffected.*. This vulnerability affects Firefox ESR < 68.7.Show less
1Zulip
1Zulip Server
Jun 17, 2026
Apr 20, 2020
N/A· v4
6.1 MEDIUM· v3
5.8 MEDIUM· v2
Zulip Server before 2.1.3 allows reverse tabnabbing via the Markdown functionality.
1Westerndigital
2Ibi
My Cloud Home
Jun 17, 2026
Apr 15, 2020
N/A· v4
4.7 MEDIUM· v3
4.3 MEDIUM· v2
Western Digital My Cloud Home and ibi devices before 2.2.0 allow clickjacking on sign-in pages.
2Quarkus
Redhat
2Keycloak
Quarkus
Jun 17, 2026
Apr 6, 2020
N/A· v4
5.4 MEDIUM· v3
5.8 MEDIUM· v2
A vulnerability was found in all versions of Keycloak where, the pages on the Admin Console area of the application are completely missing general HTTP security headers in HTTP-responses. This does not directly lead to a...Show more
A vulnerability was found in all versions of Keycloak where, the pages on the Admin Console area of the application are completely missing general HTTP security headers in HTTP-responses. This does not directly lead to a security issue, yet it might aid attackers in their efforts to exploit other problems. The flaws unnecessarily make the servers more prone to Clickjacking, channel downgrade attacks and other similar client-based attack vectors.Show less
1Hitachienergy
1Esoms
Jun 17, 2026
Apr 2, 2020
N/A· v4
6.5 MEDIUM· v3
4.3 MEDIUM· v2
For ABB eSOMS versions 4.0 to 6.0.2, the X-Frame-Options header is not configured in HTTP response. This can potentially allow 'ClickJacking' attacks where an attacker can frame parts of the application on a malicious we...Show more
For ABB eSOMS versions 4.0 to 6.0.2, the X-Frame-Options header is not configured in HTTP response. This can potentially allow 'ClickJacking' attacks where an attacker can frame parts of the application on a malicious web site, revealing sensitive user information such as authentication credentials.Show less
1Google
1Android
Jun 17, 2026
Mar 10, 2020
N/A· v4
7.8 HIGH· v3
4.4 MEDIUM· v2
In onCreate of SettingsHomepageActivity, there is a possible tapjacking attack. This could lead to local escalation of privilege in Settings with no additional execution privileges needed. User interaction is needed for...Show more
In onCreate of SettingsHomepageActivity, there is a possible tapjacking attack. This could lead to local escalation of privilege in Settings with no additional execution privileges needed. User interaction is needed for exploitation.Product: AndroidVersions: Android-10Android ID: A-138442483Show less
1Microfocus
1Service Manager
Jun 17, 2026
Mar 9, 2020
N/A· v4
5.4 MEDIUM· v3
4.9 MEDIUM· v2
There is an improper restriction of rendered UI layers or frames vulnerability in Micro Focus Service Manager Release Control versions 9.50 and 9.60. The vulnerability may result in the ability of malicious users to perf...Show more
There is an improper restriction of rendered UI layers or frames vulnerability in Micro Focus Service Manager Release Control versions 9.50 and 9.60. The vulnerability may result in the ability of malicious users to perform UI redress attacks.Show less
1Puppet
1Puppet Enterprise
Nov 21, 2024
Feb 27, 2020
N/A· v4
8.8 HIGH· v3
6.8 MEDIUM· v2
Parts of the Puppet Enterprise Console 3.x were found to be susceptible to clickjacking and CSRF (Cross-Site Request Forgery) attacks. This would allow an attacker to redirect user input to an untrusted site or hijack a...Show more
Parts of the Puppet Enterprise Console 3.x were found to be susceptible to clickjacking and CSRF (Cross-Site Request Forgery) attacks. This would allow an attacker to redirect user input to an untrusted site or hijack a user session.Show less
1Mozilla
1Firefox
Nov 21, 2024
Feb 18, 2020
N/A· v4
4.3 MEDIUM· v3
4.3 MEDIUM· v2
Mozilla Firefox before 25 allows modification of anonymous content of pluginProblem.xml binding