CWE-1021
412 CVEs • Abstraction: Base
Improper Restriction of Rendered UI Layers or Frames
The web application does not restrict or incorrectly restricts frame objects or UI layers that belong to another application or domain, which can lead to user confusion about which interface the user is interacting with.
CVEs (412)
CVE VENDORS PRODUCTS UPDATED PUBLISHED CVSS |
|---|
IBM BigFix Platform 9.2 and 9.5 could allow a low-privilege user to manipulate the UI into exposing interface elements and information normally restricted to administrators. IBM X-Force ID: 156570. |
1Ibm 1Spectrum Protect Backup Archive Client Nov 21, 2024 Apr 8, 2019 N/A· v4 6.1 MEDIUM· v3 4.3 MEDIUM· v2 IBM Tivoli Storage Manager (IBM Spectrum Protect 7.1 and 8.1) could allow a remote attacker to hijack the clicking action of the victim. By persuading a victim to visit a malicious Web site, a remote attacker could explo...Show more |
Improper restriction of rendered UI layers or frames vulnerability in SSOOauth.cgi in Synology SSO Server before 2.1.3-0129 allows remote attackers to conduct clickjacking attacks via unspecified vectors. |
When the RSS Feed preview about:feeds page is framed within another page, it can be used in concert with scripted content for a clickjacking attack that confuses users into downloading and executing an executable file fr...Show more |
4Debian FedoraprojectGoogle+1 more6Chrome Debian LinuxEnterprise Linux Desktop+3 moreJun 17, 2026 Feb 19, 2019 N/A· v4 6.5 MEDIUM· v3 4.3 MEDIUM· v2 Insufficient protection of permission UI in WebAPKs in Google Chrome on Android prior to 72.0.3626.81 allowed an attacker who convinced the user to install a malicious application to access privacy/security sensitive web...Show more |
1Cybozu 1Remote Service Manager Nov 21, 2024 Jan 9, 2019 N/A· v4 6.5 MEDIUM· v3 5.8 MEDIUM· v2 Improper countermeasure against clickjacking attack in client certificates management screen was discovered in Cybozu Remote Service 3.0.0 to 3.1.8, that allows remote attackers to trick a user to delete the registered c...Show more |
3Debian GoogleRedhat5Chrome Debian LinuxEnterprise Linux Desktop+2 moreJun 17, 2026 Jan 9, 2019 N/A· v4 4.3 MEDIUM· v3 4.3 MEDIUM· v2 Eliding from the wrong side in an infobar in DevTools in Google Chrome prior to 68.0.3440.75 allowed an attacker who convinced a user to install a malicious extension to Hide Chrome Security UI via a crafted Chrome Exten...Show more |
The X-Frame-Options headers were applied inconsistently on some HTTP responses, resulting in duplicate or missing security headers. Some browsers would interpret these results incorrectly, allowing clickjacking attacks....Show more |
1Ibm 1Security Access Manager Nov 21, 2024 Dec 13, 2018 N/A· v4 6.1 MEDIUM· v3 4.3 MEDIUM· v2 IBM Security Access Manager Appliance 9.0.1.0, 9.0.2.0, 9.0.3.0, 9.0.4.0, and 9.0.5.0 could allow a remote attacker to hijack the clicking action of the victim. By persuading a victim to visit a malicious Web site, a rem...Show more |
In functionality implemented in System UI, there are insufficient protections implemented around overlay windows. This could lead to local escalation of privilege with no additional execution privileges needed. User inte...Show more |
In computeFocusedWindow of RootWindowContainer.java, and related functions, there is possible interception of keypresses due to focus being on the wrong window. This could lead to local escalation of privilege revealing...Show more |
1Rainmachine 1Rainmachine Web Application Jun 17, 2026 Nov 1, 2018 N/A· v4 6.5 MEDIUM· v3 4.3 MEDIUM· v2 A missing X-Frame-Options header in the Green Electronics RainMachine Mini-8 (2nd Generation) and Touch HD 12 web application could be used by a remote attacker for clickjacking, as demonstrated by triggering an API page...Show more |
1Cisco 1Hyperflex Hx Data Platform Nov 21, 2024 Oct 5, 2018 N/A· v4 4.7 MEDIUM· v3 4.3 MEDIUM· v2 A vulnerability in the web UI of Cisco HyperFlex Software could allow an unauthenticated, remote attacker to affect the integrity of a device via a clickjacking attack. The vulnerability is due to insufficient input vali...Show more |
TP-Link TL-WR841N v13 00000001 0.9.1 4.16 v0001.0 Build 180119 Rel.65243n devices allow clickjacking. |
1Cisco 1Unified Communications Manager Nov 21, 2024 Jun 7, 2018 N/A· v4 6.1 MEDIUM· v3 4.3 MEDIUM· v2 A vulnerability in the web UI of Cisco Unified Communications Manager (Unified CM) could allow an unauthenticated, remote attacker to conduct a cross-frame scripting (XFS) attack against the user of the web UI of an affe...Show more |
1Ibm 1Infosphere Information Server Nov 21, 2024 Jun 5, 2018 N/A· v4 6.1 MEDIUM· v3 4.3 MEDIUM· v2 IBM InfoSphere Information Server 9.1, 11.3, 11.5, and 11.7 is vulnerable to cross-frame scripting which is a vulnerability that allows an attacker to load Information Server components inside an HTML iframe tag on a mal...Show more |
In PrestaShop through 1.7.2.5, a UI-Redressing/Clickjacking vulnerability was found that might lead to state-changing impact in the context of a user or an admin, because the generateHtaccess function in classes/Tools.ph...Show more |
An issue was discovered in Adobe Connect 9.6.2 and earlier versions. A UI Redress (or Clickjacking) vulnerability exists. This issue has been resolved by adding a feature that enables Connect administrators to protect us...Show more |
1Intel 1Active Management Technology Firmware May 13, 2026 Jun 14, 2017 N/A· v4 6.5 MEDIUM· v3 4.3 MEDIUM· v2 Insufficient clickjacking protection in the Web User Interface of Intel AMT firmware versions before 9.1.40.1000, 9.5.60.1952, 10.0.50.1004, 11.0.0.1205, and 11.6.25.1129 potentially allowing a remote attacker to hijack...Show more |
1Mcafee 1Network Data Loss Prevention May 13, 2026 May 17, 2017 N/A· v4 4.5 MEDIUM· v3 3.5 LOW· v2 Clickjacking vulnerability in the server in McAfee Network Data Loss Prevention (NDLP) 9.3.x allows remote authenticated users to inject arbitrary web script or HTML via HTTP response header. |