CWE-1021
400 CVEs • Abstraction: Base
Improper Restriction of Rendered UI Layers or Frames
The web application does not restrict or incorrectly restricts frame objects or UI layers that belong to another application or domain, which can lead to user confusion about which interface the user is interacting with.
CVEs (400)
CVE VENDORS PRODUCTS UPDATED PUBLISHED CVSS |
|---|
1Ibm 1Websphere Application Server Jun 17, 2026 Jul 30, 2019 N/A· v4 5.4 MEDIUM· v3 3.5 LOW· v2 IBM WebSphere Application Server - Liberty Admin Center could allow a remote attacker to hijack the clicking action of the victim. By persuading a victim to visit a malicious Web site, a remote attacker could send a spec...Show more |
1Pivotal Software 1Cloud Foundry Uaa Jun 17, 2026 Jul 18, 2019 N/A· v4 5.4 MEDIUM· v3 4.3 MEDIUM· v2 Cloud Foundry UAA, versions prior to v73.4.0, does not set an X-FRAME-OPTIONS header on various endpoints. A remote user can perform clickjacking attacks on UAA's frontend sites. |
Mailvelope prior to 3.1.0 is vulnerable to a clickjacking attack against the settings page. As the settings page is intended to be accessible from web applications, the browser's extension isolation mechanisms are disabl...Show more |
1Bcnquark 1Quarking Password Manager Jun 17, 2026 Jun 24, 2019 N/A· v4 4.3 MEDIUM· v3 4.3 MEDIUM· v2 BCN Quark Quarking Password Manager 3.1.84 suffers from a clickjacking vulnerability caused by allowing * within web_accessible_resources. An attacker can take advantage of this vulnerability and cause significant harm. |
1Sap 1Netweaver Process Integration Jun 17, 2026 Jun 12, 2019 N/A· v4 4.3 MEDIUM· v3 4.3 MEDIUM· v2 Java Server Pages (JSPs) provided by the SAP NetWeaver Process Integration (SAP_XIESR and SAP_XITOOL: 7.10 to 7.11, 7.20, 7.30, 7.31, 7.40, 7.50) do not restrict or incorrectly restrict frame objects or UI layers that be...Show more |
There is a Clickjacking vulnerability in Huawei HG255s product. An attacker may trick user to click a link and affect the integrity of a device by exploiting this vulnerability. |
1Ibm 1Security Information Queue Jun 17, 2026 Jun 6, 2019 N/A· v4 6.1 MEDIUM· v3 4.3 MEDIUM· v2 IBM Security Information Queue (ISIQ) 1.0.0, 1.0.1, and 1.0.2 could allow a remote attacker to hijack the clicking action of the victim. By persuading a victim to visit a malicious Web site, a remote attacker could explo...Show more |
1Ca 2Risk Authentication Strong AuthenticationJun 17, 2026 May 28, 2019 N/A· v4 4.3 MEDIUM· v3 4.0 MEDIUM· v2 A UI redress vulnerability in the administrative user interface of CA Technologies CA Strong Authentication 9.0.x, 8.2.x, 8.1.x, 8.0.x, 7.1.x and CA Risk Authentication 9.0.x, 8.2.x, 8.1.x, 8.0.x, 3.1.x may allow a remot...Show more |
IBM BigFix Platform 9.2 and 9.5 could allow a low-privilege user to manipulate the UI into exposing interface elements and information normally restricted to administrators. IBM X-Force ID: 156570. |
1Ibm 1Spectrum Protect Backup Archive Client Nov 21, 2024 Apr 8, 2019 N/A· v4 6.1 MEDIUM· v3 4.3 MEDIUM· v2 IBM Tivoli Storage Manager (IBM Spectrum Protect 7.1 and 8.1) could allow a remote attacker to hijack the clicking action of the victim. By persuading a victim to visit a malicious Web site, a remote attacker could explo...Show more |
Improper restriction of rendered UI layers or frames vulnerability in SSOOauth.cgi in Synology SSO Server before 2.1.3-0129 allows remote attackers to conduct clickjacking attacks via unspecified vectors. |
When the RSS Feed preview about:feeds page is framed within another page, it can be used in concert with scripted content for a clickjacking attack that confuses users into downloading and executing an executable file fr...Show more |
4Debian FedoraprojectGoogle+1 more6Chrome Debian LinuxEnterprise Linux Desktop+3 moreJun 17, 2026 Feb 19, 2019 N/A· v4 6.5 MEDIUM· v3 4.3 MEDIUM· v2 Insufficient protection of permission UI in WebAPKs in Google Chrome on Android prior to 72.0.3626.81 allowed an attacker who convinced the user to install a malicious application to access privacy/security sensitive web...Show more |
1Cybozu 1Remote Service Manager Nov 21, 2024 Jan 9, 2019 N/A· v4 6.5 MEDIUM· v3 5.8 MEDIUM· v2 Improper countermeasure against clickjacking attack in client certificates management screen was discovered in Cybozu Remote Service 3.0.0 to 3.1.8, that allows remote attackers to trick a user to delete the registered c...Show more |
3Debian GoogleRedhat5Chrome Debian LinuxEnterprise Linux Desktop+2 moreJun 17, 2026 Jan 9, 2019 N/A· v4 4.3 MEDIUM· v3 4.3 MEDIUM· v2 Eliding from the wrong side in an infobar in DevTools in Google Chrome prior to 68.0.3440.75 allowed an attacker who convinced a user to install a malicious extension to Hide Chrome Security UI via a crafted Chrome Exten...Show more |
The X-Frame-Options headers were applied inconsistently on some HTTP responses, resulting in duplicate or missing security headers. Some browsers would interpret these results incorrectly, allowing clickjacking attacks....Show more |
1Ibm 1Security Access Manager Nov 21, 2024 Dec 13, 2018 N/A· v4 6.1 MEDIUM· v3 4.3 MEDIUM· v2 IBM Security Access Manager Appliance 9.0.1.0, 9.0.2.0, 9.0.3.0, 9.0.4.0, and 9.0.5.0 could allow a remote attacker to hijack the clicking action of the victim. By persuading a victim to visit a malicious Web site, a rem...Show more |
In functionality implemented in System UI, there are insufficient protections implemented around overlay windows. This could lead to local escalation of privilege with no additional execution privileges needed. User inte...Show more |
In computeFocusedWindow of RootWindowContainer.java, and related functions, there is possible interception of keypresses due to focus being on the wrong window. This could lead to local escalation of privilege revealing...Show more |
1Rainmachine 1Rainmachine Web Application Jun 17, 2026 Nov 1, 2018 N/A· v4 6.5 MEDIUM· v3 4.3 MEDIUM· v2 A missing X-Frame-Options header in the Green Electronics RainMachine Mini-8 (2nd Generation) and Touch HD 12 web application could be used by a remote attacker for clickjacking, as demonstrated by triggering an API page...Show more |