CWE-1021
412 CVEs • Abstraction: Base
Improper Restriction of Rendered UI Layers or Frames
The web application does not restrict or incorrectly restricts frame objects or UI layers that belong to another application or domain, which can lead to user confusion about which interface the user is interacting with.
CVEs (412)
CVE VENDORS PRODUCTS UPDATED PUBLISHED CVSS |
|---|
1Gfi 2Kerio Connect Kerio Connect ClientMay 13, 2026 May 2, 2017 N/A· v4 6.5 MEDIUM· v3 4.3 MEDIUM· v2 Kerio Connect 8.0.0 through 9.2.2, and Kerio Connect Client desktop application for Windows and Mac 9.2.0 through 9.2.2, when e-mail preview is enabled, allows remote attackers to conduct clickjacking attacks via a craft...Show more |
An elevation of privilege vulnerability in the System UI could enable a local malicious application to create a UI overlay covering the entire screen. This issue is rated as Moderate because it is a local bypass of user...Show more |
Google Chrome prior to 56.0.2924.76 for Linux, Windows and Mac, failed to prevent alerts from being displayed by swapped out frames, which allowed a remote attacker to show alerts on a page they don't control via a craft...Show more |
Blink in Google Chrome prior to 56.0.2924.76 for Linux, Windows and Mac, and 56.0.2924.87 for Android, failed to prevent certain UI elements from being displayed by non-visible pages, which allowed a remote attacker to s...Show more |
The Framework UI permission-dialog implementation in Android 6.x before 2016-06-01 allows attackers to conduct tapjacking attacks and access arbitrary private-storage files by creating a partially overlapping window, aka...Show more |
6Canonical DebianGoogle+3 more11Chrome Debian LinuxEnterprise Linux Desktop+8 moreMay 6, 2026 Apr 19, 2015 N/A· v4 N/A· v3 4.3 MEDIUM· v2 Google Chrome before 42.0.2311.90 does not properly consider the interaction of page navigation with the handling of touch events and gesture events, which allows remote attackers to trigger unintended UI actions via a c...Show more |
5Canonical MozillaOpensuse+2 more8Firefox Linux Enterprise DesktopLinux Enterprise Server+5 moreApr 29, 2026 Feb 6, 2014 N/A· v4 N/A· v3 5.0 MEDIUM· v2 Mozilla Firefox before 27.0 and SeaMonkey before 2.24 allow remote attackers to bypass the Same Origin Policy and obtain sensitive information by using an IFRAME element in conjunction with certain timing measurements in...Show more |
5Canonical MozillaOpensuse+2 more8Firefox Linux Enterprise DesktopLinux Enterprise Server+5 moreApr 29, 2026 Feb 6, 2014 N/A· v4 N/A· v3 4.3 MEDIUM· v2 The file-download implementation in Mozilla Firefox before 27.0 and SeaMonkey before 2.24 does not properly restrict the timing of button selections, which allows remote attackers to conduct clickjacking attacks, and tri...Show more |
7Canonical FedoraprojectMozilla+4 more16Enterprise Linux Desktop Enterprise Linux EusEnterprise Linux Server+13 moreApr 29, 2026 Dec 11, 2013 N/A· v4 N/A· v3 4.3 MEDIUM· v2 Mozilla Firefox before 26.0 and SeaMonkey before 2.23 do not properly consider the sandbox attribute of an IFRAME element during processing of a contained OBJECT element, which allows remote attackers to bypass intended...Show more |
Microsoft Internet Explorer 6, 7, and 8 does not enforce intended domain restrictions on content access, which allows remote attackers to obtain sensitive information or conduct clickjacking attacks via a crafted web sit...Show more |
Unspecified vulnerability in Opera before 9.5 allows remote attackers to spoof the contents of trusted frames on the same parent page by modifying the location, which can facilitate phishing attacks. |
A design error in Opera 8.01 and earlier allows user-assisted attackers to execute arbitrary code by overlaying a malicious new window above a file download dialog box, then tricking the user into double-clicking on the...Show more |