CWE-1021
412 CVEs • Abstraction: Base
Improper Restriction of Rendered UI Layers or Frames
The web application does not restrict or incorrectly restricts frame objects or UI layers that belong to another application or domain, which can lead to user confusion about which interface the user is interacting with.
CVEs (412)
CVE VENDORS PRODUCTS UPDATED PUBLISHED CVSS |
|---|
IBM Security Secret Server 10.7 could allow a remote attacker to hijack the clicking action of the victim. By persuading a victim to visit a malicious Web site, a remote attacker could exploit this vulnerability to hijac...Show more |
1Ibm 2Spectrum Protect Client Spectrum Protect For Space ManagementJun 17, 2026 Jun 15, 2020 N/A· v4 5.4 MEDIUM· v3 3.5 LOW· v2 IBM Spectrum Protect Client 8.1.7.0 through 8.1.9.1 (Linux and Windows), 8.1.9.0 trough 8.1.9.1 (AIX) and IBM Spectrum Protect for Space Management 8.1.7.0 through 8.1.9.1 (Linux), 8.1.9.0 through 8.1.9.1 (AIX) web user...Show more |
IBM API Connect V2018.4.1.0 through 2018.4.1.10 could allow a remote attacker to hijack the clicking action of the victim. By persuading a victim to visit a malicious Web site, a remote attacker could exploit this vulner...Show more |
When following a link that opened an intent://-schemed URL, causing a custom tab to be opened, Firefox for Android could be tricked into displaying the incorrect URI. <br> *Note: This issue only affects Firefox for Andro...Show more |
Zulip Server before 2.1.3 allows reverse tabnabbing via the Markdown functionality. |
1Westerndigital 2Ibi My Cloud HomeJun 17, 2026 Apr 15, 2020 N/A· v4 4.7 MEDIUM· v3 4.3 MEDIUM· v2 Western Digital My Cloud Home and ibi devices before 2.2.0 allow clickjacking on sign-in pages. |
2Quarkus Redhat2Keycloak QuarkusJun 17, 2026 Apr 6, 2020 N/A· v4 5.4 MEDIUM· v3 5.8 MEDIUM· v2 A vulnerability was found in all versions of Keycloak where, the pages on the Admin Console area of the application are completely missing general HTTP security headers in HTTP-responses. This does not directly lead to a...Show more |
For ABB eSOMS versions 4.0 to 6.0.2, the X-Frame-Options header is not configured in HTTP response. This can potentially allow 'ClickJacking' attacks where an attacker can frame parts of the application on a malicious we...Show more |
In onCreate of SettingsHomepageActivity, there is a possible tapjacking attack. This could lead to local escalation of privilege in Settings with no additional execution privileges needed. User interaction is needed for...Show more |
There is an improper restriction of rendered UI layers or frames vulnerability in Micro Focus Service Manager Release Control versions 9.50 and 9.60. The vulnerability may result in the ability of malicious users to perf...Show more |
Parts of the Puppet Enterprise Console 3.x were found to be susceptible to clickjacking and CSRF (Cross-Site Request Forgery) attacks. This would allow an attacker to redirect user input to an untrusted site or hijack a...Show more |
Mozilla Firefox before 25 allows modification of anonymous content of pluginProblem.xml binding |
It is possible for a malicious application to construct a TYPE_TOAST window manually and make that window clickable. This could lead to a local escalation of privilege with no additional execution privileges needed. User...Show more |
1Siemens 8Scalance X 200irt Firmware Scalance X 300 FirmwareScalance Xb 200 Firmware+5 moreJun 17, 2026 Feb 11, 2020 N/A· v4 5.4 MEDIUM· v3 4.3 MEDIUM· v2 A vulnerability has been identified in SCALANCE S602 (All versions < V4.1), SCALANCE S612 (All versions < V4.1), SCALANCE S623 (All versions < V4.1), SCALANCE S627-2M (All versions < V4.1), SCALANCE X-200 switch family (...Show more |
NetApp Snap Creator Framework before 4.3P1 allows remote authenticated users to conduct clickjacking attacks via unspecified vectors. |
1Cisco 1Linksys E4200 Firmware Nov 21, 2024 Feb 5, 2020 N/A· v4 4.3 MEDIUM· v3 4.3 MEDIUM· v2 Cisco Linksys E4200 1.0.05 Build 7 devices contain a Clickjacking Vulnerability which allows remote attackers to obtain sensitive information. |
1Brother 1Mfc 9970cdw Firmware Nov 21, 2024 Feb 5, 2020 N/A· v4 6.5 MEDIUM· v3 4.3 MEDIUM· v2 Brother MFC-9970CDW 1.10 devices with Firmware L contain a Frameable response (Clickjacking) vulnerability which could allow remote attackers to obtain sensitive information. |
1Ibm 1Security Directory Server Jun 17, 2026 Feb 4, 2020 N/A· v4 6.1 MEDIUM· v3 4.3 MEDIUM· v2 IBM Security Directory Server 6.4.0 could allow a remote attacker to hijack the clicking action of the victim. By persuading a victim to visit a malicious Web site, a remote attacker could exploit this vulnerability to h...Show more |
REST API endpoints in Jenkins 2.218 and earlier, LTS 2.204.1 and earlier were vulnerable to clickjacking attacks. |
Splunk before 5.0.4 lacks X-Frame-Options which can allow Clickjacking |