CWE-1021
400 CVEs • Abstraction: Base
Improper Restriction of Rendered UI Layers or Frames
The web application does not restrict or incorrectly restricts frame objects or UI layers that belong to another application or domain, which can lead to user confusion about which interface the user is interacting with.
CVEs (400)
CVE VENDORS PRODUCTS UPDATED PUBLISHED CVSS |
|---|
It is possible for a malicious application to construct a TYPE_TOAST window manually and make that window clickable. This could lead to a local escalation of privilege with no additional execution privileges needed. User...Show more |
1Siemens 8Scalance X 200irt Firmware Scalance X 300 FirmwareScalance Xb 200 Firmware+5 moreJun 17, 2026 Feb 11, 2020 N/A· v4 5.4 MEDIUM· v3 4.3 MEDIUM· v2 A vulnerability has been identified in SCALANCE S602 (All versions < V4.1), SCALANCE S612 (All versions < V4.1), SCALANCE S623 (All versions < V4.1), SCALANCE S627-2M (All versions < V4.1), SCALANCE X-200 switch family (...Show more |
NetApp Snap Creator Framework before 4.3P1 allows remote authenticated users to conduct clickjacking attacks via unspecified vectors. |
1Cisco 1Linksys E4200 Firmware Nov 21, 2024 Feb 5, 2020 N/A· v4 4.3 MEDIUM· v3 4.3 MEDIUM· v2 Cisco Linksys E4200 1.0.05 Build 7 devices contain a Clickjacking Vulnerability which allows remote attackers to obtain sensitive information. |
1Brother 1Mfc 9970cdw Firmware Nov 21, 2024 Feb 5, 2020 N/A· v4 6.5 MEDIUM· v3 4.3 MEDIUM· v2 Brother MFC-9970CDW 1.10 devices with Firmware L contain a Frameable response (Clickjacking) vulnerability which could allow remote attackers to obtain sensitive information. |
1Ibm 1Security Directory Server Jun 17, 2026 Feb 4, 2020 N/A· v4 6.1 MEDIUM· v3 4.3 MEDIUM· v2 IBM Security Directory Server 6.4.0 could allow a remote attacker to hijack the clicking action of the victim. By persuading a victim to visit a malicious Web site, a remote attacker could exploit this vulnerability to h...Show more |
REST API endpoints in Jenkins 2.218 and earlier, LTS 2.204.1 and earlier were vulnerable to clickjacking attacks. |
Splunk before 5.0.4 lacks X-Frame-Options which can allow Clickjacking |
1Ibm 1Financial Transaction Manager For Multiplatform Jun 17, 2026 Dec 20, 2019 N/A· v4 6.1 MEDIUM· v3 4.3 MEDIUM· v2 IBM Financial Transaction Manager 3.0 could allow a remote attacker to hijack the clicking action of the victim. By persuading a victim to visit a malicious Web site, a remote attacker could exploit this vulnerability to...Show more |
Intesync Solismed 3.3sp allows Clickjacking. |
Insufficient data validation in Blink in Google Chrome prior to 76.0.3809.87 allowed a remote attacker to bypass anti-clickjacking policy via a crafted HTML page. |
1Ibm 1Smartcloud Analytics Log Analysis Jun 17, 2026 Nov 22, 2019 N/A· v4 6.1 MEDIUM· v3 4.3 MEDIUM· v2 IBM SmartCloud Analytics 1.3.1 through 1.3.5 could allow a remote attacker to hijack the clicking action of the victim. By persuading a victim to visit a malicious Web site, a remote attacker could exploit this vulnerabi...Show more |
vBulletin before 5.5.4 allows clickjacking. |
1Ibm 1Websphere Extreme Scale Jun 17, 2026 Sep 30, 2019 N/A· v4 6.1 MEDIUM· v3 5.8 MEDIUM· v2 IBM WebSphere eXtreme Scale 8.6 Admin Console could allow a remote attacker to hijack the clicking action of the victim. By persuading a victim to visit a malicious Web site, a remote attacker could exploit this vulnerab...Show more |
1Cisco 5Hyperflex Hx220c Af M5 Firmware Hyperflex Hx220c Edge M5 FirmwareHyperflex Hx220c M5 Firmware+2 moreJun 17, 2026 Sep 18, 2019 N/A· v4 6.1 MEDIUM· v3 4.3 MEDIUM· v2 A vulnerability in the web-based interface of Cisco HyperFlex Software could allow an unauthenticated, remote attacker to execute a cross-frame scripting (XFS) attack on an affected device. This vulnerability is due to i...Show more |
1Ibm 1Application Performance Management Jun 17, 2026 Sep 17, 2019 N/A· v4 6.1 MEDIUM· v3 4.3 MEDIUM· v2 IBM Cloud Application Performance Management 8.1.4 could allow a remote attacker to hijack the clicking action of the victim. By persuading a victim to visit a malicious Web site, a remote attacker could exploit this vul...Show more |
LogMeIn LastPass before 4.33.0 allows attackers to construct a crafted web site that captures the credentials for a victim's account on a previously visited web site, because do_popupregister can be bypassed via clickjac...Show more |
A clickjacking vulnerability was found in Limesurvey before 3.17.14. |
In ChangeDefaultDialerDialog.java, there is a possible escalation of privilege due to an overlay attack. This could lead to local escalation of privilege, granting privileges to a local app without the user's informed co...Show more |
Clickjack vulnerability in Adminstrator web console in McAfee Web Gateway (MWG) 7.8.2.x prior to 7.8.2.12 allows remote attackers to conduct clickjacking attacks via a crafted web page that contains an iframe via does no...Show more |