VYPR

CWE-1021

Improper Restriction of Rendered UI Layers or Frames

BaseIncomplete

Description

The web application does not restrict or incorrectly restricts frame objects or UI layers that belong to another application or domain.

Hierarchy (View 1000)

Children

none

Related attack patterns (CAPEC)

CAPEC-103 · CAPEC-181 · CAPEC-222 · CAPEC-504 · CAPEC-506 · CAPEC-587 · CAPEC-654

CVEs mapped to this weakness (406)

page 1 of 21
  • CVE-2021-43048CriNov 16, 2021
    risk 0.64cvss 9.8epss 0.01

    The Interior Server and Gateway Server components of TIBCO Software Inc.'s TIBCO PartnerExpress contain a vulnerability that theoretically allows an unauthenticated attacker with network access to execute a clickjacking attack on the affected system. A successful attack using…

  • CVE-2021-23274CriMar 23, 2021
    risk 0.64cvss 9.8epss 0.01

    The Config UI component of TIBCO Software Inc.'s TIBCO API Exchange Gateway and TIBCO API Exchange Gateway Distribution for TIBCO Silver Fabric contains a vulnerability that theoretically allows an unauthenticated attacker with network access to execute a clickjacking attack on…

  • CVE-2021-21132CriFeb 9, 2021
    risk 0.64cvss 9.6epss 0.23

    Inappropriate implementation in DevTools in Google Chrome prior to 88.0.4324.96 allowed a remote attacker to potentially perform a sandbox escape via a crafted Chrome Extension.

  • CVE-2016-2496CriJun 13, 2016
    risk 0.64cvss 9.8epss 0.01

    The Framework UI permission-dialog implementation in Android 6.x before 2016-06-01 allows attackers to conduct tapjacking attacks and access arbitrary private-storage files by creating a partially overlapping window, aka internal bug 26677796.

  • CVE-2021-21111CriJan 8, 2021
    risk 0.62cvss 9.6epss 0.01

    Insufficient policy enforcement in WebUI in Google Chrome prior to 87.0.4280.141 allowed an attacker who convinced a user to install a malicious extension to potentially perform a sandbox escape via a crafted Chrome Extension.

  • CVE-2024-10004CriOct 15, 2024
    risk 0.59cvss 9.1epss 0.00

    Opening an external link to an HTTP website when Firefox iOS was previously closed and had an HTTPS tab open could in some cases result in the padlock icon showing an HTTPS indicator incorrectly This vulnerability affects Firefox for iOS < 131.2.

  • CVE-2023-41897HigOct 19, 2023
    risk 0.57cvss 8.8epss 0.01

    Home assistant is an open source home automation. Home Assistant server does not set any HTTP security headers, including the X-Frame-Options header, which specifies whether the web page is allowed to be framed. The omission of this and correlating headers facilitates covert…

  • CVE-2021-22866HigMay 14, 2021
    risk 0.57cvss 8.8epss 0.01

    A UI misrepresentation vulnerability was identified in GitHub Enterprise Server that allowed more permissions to be granted during a GitHub App's user-authorization web flow than was displayed to the user during approval. To exploit this vulnerability, an attacker would need to…

  • CVE-2015-5686HigFeb 27, 2020
    risk 0.57cvss 8.8epss 0.00

    Parts of the Puppet Enterprise Console 3.x were found to be susceptible to clickjacking and CSRF (Cross-Site Request Forgery) attacks. This would allow an attacker to redirect user input to an untrusted site or hijack a user session.

  • CVE-2018-18496HigFeb 28, 2019
    risk 0.57cvss 8.8epss 0.01

    When the RSS Feed preview about:feeds page is framed within another page, it can be used in concert with scripted content for a clickjacking attack that confuses users into downloading and executing an executable file from a temporary directory. *Note: This issue only affects…

  • CVE-2026-0007HigMar 2, 2026
    risk 0.56cvss 8.6epss 0.00

    In writeToParcel of WindowInfo.cpp, there is a possible way to trick a user into accepting a permission due to a tapjacking/overlay attack. This could lead to local escalation of privilege with no additional execution privileges needed. User interaction is not needed for…

  • CVE-2024-11700HigNov 26, 2024
    risk 0.53cvss 8.1epss 0.00

    Malicious websites may have been able to perform user intent confirmation through tapjacking. This could have led to users unknowingly approving the launch of external applications, potentially exposing them to underlying vulnerabilities. This vulnerability affects Firefox < 133…

  • CVE-2024-7523HigAug 6, 2024
    risk 0.53cvss 8.1epss 0.00

    A select option could partially obscure security prompts. This could be used by a malicious site to trick a user into granting permissions. *This issue only affects Android versions of Firefox.* This vulnerability affects Firefox < 129.

  • CVE-2024-33377HigJun 14, 2024
    risk 0.53cvss 8.1epss 0.00

    LB-LINK BL-W1210M v2.0 was discovered to contain a clickjacking vulnerability via the Administrator login page. Attackers can cause victim users to perform arbitrary operations via interaction with crafted elements on the web page.

  • CVE-2021-44683HigMar 25, 2022
    risk 0.53cvss 8.2epss 0.01

    The DuckDuckGo browser 7.64.4 on iOS allows Address Bar Spoofing due to mishandling of the JavaScript window.open function (used to open a secondary browser window). This could be exploited by tricking users into supplying sensitive information such as credentials, because the…

  • CVE-2021-23976HigFeb 26, 2021
    risk 0.53cvss 8.1epss 0.01

    When accepting a malicious intent from other installed apps, Firefox for Android accepted manifests from arbitrary file paths and allowed declaring webapp manifests for other origins. This could be used to gain fullscreen access for UI spoofing and could also lead to…

  • CVE-2020-13119HigSep 24, 2020
    risk 0.53cvss 8.1epss 0.01

    ismartgate PRO 1.5.9 is vulnerable to clickjacking.

  • CVE-2019-16371HigSep 16, 2019
    risk 0.53cvss 8.2epss 0.01

    LogMeIn LastPass before 4.33.0 allows attackers to construct a crafted web site that captures the credentials for a victim's account on a previously visited web site, because do_popupregister can be bypassed via clickjacking.

  • CVE-2021-0433HigApr 13, 2021
    risk 0.52cvss 8.0epss 0.01

    In onCreate of DeviceChooserActivity.java, there is a possible way to bypass user consent when pairing a Bluetooth device due to a tapjacking/overlay attack. This could lead to local escalation of privilege and pairing malicious devices with no additional execution privileges…

  • CVE-2026-28577HigJun 1, 2026
    risk 0.51cvss 7.8epss 0.00

    In addWindow of WindowManagerService.java, there is a possible tapjacking issue due to a tapjacking/overlay attack. This could lead to local escalation of privilege with no additional execution privileges needed. User interaction is not needed for exploitation.