VYPR

CWE-1021

Improper Restriction of Rendered UI Layers or Frames

BaseIncomplete

Description

The web application does not restrict or incorrectly restricts frame objects or UI layers that belong to another application or domain.

Hierarchy (View 1000)

Children

none

Related attack patterns (CAPEC)

CAPEC-103 · CAPEC-181 · CAPEC-222 · CAPEC-504 · CAPEC-506 · CAPEC-587 · CAPEC-654

CVEs mapped to this weakness (406)

page 5 of 21
  • CVE-2021-0506HigJun 21, 2021
    risk 0.47cvss 7.3epss 0.00

    In ActivityPicker.java, there is a possible bypass of user interaction in intent resolution due to a tapjacking/overlay attack. This could lead to local escalation of privilege with User execution privileges needed. User interaction is needed for exploitation.Product:…

  • CVE-2021-0446HigApr 13, 2021
    risk 0.47cvss 7.3epss 0.00

    In ImportVCardActivity, there is a possible way to bypass user consent due to a tapjacking/overlay attack. This could lead to local escalation of privilege with User execution privileges needed. User interaction is needed for exploitation.Product: AndroidVersions:…

  • CVE-2021-0333HigFeb 10, 2021
    risk 0.47cvss 7.3epss 0.00

    In onCreate of BluetoothPermissionActivity.java, there is a possible permissions bypass due to a tapjacking overlay that obscures the phonebook permissions dialog when a Bluetooth device is connecting. This could lead to local escalation of privilege with User execution…

  • CVE-2021-0331HigFeb 10, 2021
    risk 0.47cvss 7.3epss 0.00

    In onCreate of NotificationAccessConfirmationActivity.java, there is a possible overlay attack due to an insecure default value. This could lead to local escalation of privilege and notification access with User execution privileges needed. User interaction is needed for…

  • CVE-2021-0314HigFeb 10, 2021
    risk 0.47cvss 7.3epss 0.00

    In onCreate of UninstallerActivity, there is a possible way to uninstall an all without informed user consent due to a tapjacking/overlay attack. This could lead to local escalation of privilege with User execution privileges needed. User interaction is needed for…

  • CVE-2021-0315HigJan 11, 2021
    risk 0.47cvss 7.3epss 0.00

    In onCreate of GrantCredentialsPermissionActivity.java, there is a possible way to convince the user to grant an app access to an account due to a tapjacking/overlay attack. This could lead to local escalation of privilege with User execution privileges needed. User interaction…

  • CVE-2019-2125HigAug 20, 2019
    risk 0.47cvss 7.3epss 0.00

    In ChangeDefaultDialerDialog.java, there is a possible escalation of privilege due to an overlay attack. This could lead to local escalation of privilege, granting privileges to a local app without the user's informed consent, with no additional privileges needed. User…

  • CVE-2026-70486HigAug 4, 2026
    risk 0.46cvss 8.2epss 0.00

    Open WebUI is an extensible, feature-rich, and user-friendly self-hosted AI platform. From 0.9.0 until 0.11.0, the terminal file-preview serveUrl iframe branch always granted allow-same-origin together with allow-scripts for HTML files served from the application origin. Any…

  • CVE-2025-1940HigMar 4, 2025
    risk 0.46cvss 7.1epss 0.00

    A select option could partially obscure the confirmation prompt shown before launching external apps. This could be used to trick a user in to launching an external app unexpectedly. *This issue only affects Android versions of Firefox.*. This vulnerability was fixed in Firefox…

  • CVE-2021-34087HigJan 10, 2022
    risk 0.46cvss 7.1epss 0.01

    In Ultimaker S3 3D printer, Ultimaker S5 3D printer, Ultimaker 3 3D printer S-line through 6.3 and Ultimaker 3 through 5.2.16, the local webserver can be used for clickjacking. This includes the settings page.

  • CVE-2021-0963HigDec 15, 2021
    risk 0.46cvss 7.1epss 0.00

    In onCreate of KeyChainActivity.java, there is a possible way to use an app certificate stored in keychain due to a tapjacking/overlay attack. This could lead to local escalation of privilege with no additional execution privileges needed. User interaction is needed for…

  • CVE-2020-7705HigAug 24, 2020
    risk 0.46cvss 7.1epss 0.01

    This affects the package MintegralAdSDK from 0.0.0. The SDK distributed by the company contains malicious functionality that tracks any URL opened by the app and reports it back to the company, along with performing advertisement attribution fraud. Mintegral can remotely…

  • CVE-2019-3639HigAug 14, 2019
    risk 0.46cvss 7.1epss 0.01

    Clickjack vulnerability in Adminstrator web console in McAfee Web Gateway (MWG) 7.8.2.x prior to 7.8.2.12 allows remote attackers to conduct clickjacking attacks via a crafted web page that contains an iframe via does not send an X-Frame-Options HTTP header.

  • CVE-2017-16775HigApr 1, 2019
    risk 0.46cvss 7.1epss 0.01

    Improper restriction of rendered UI layers or frames vulnerability in SSOOauth.cgi in Synology SSO Server before 2.1.3-0129 allows remote attackers to conduct clickjacking attacks via unspecified vectors.

  • CVE-2022-22552MedJan 21, 2022
    risk 0.45cvss 6.9epss 0.01

    Dell EMC AppSync versions 3.9 to 4.3 contain a clickjacking vulnerability in AppSync. A remote unauthenticated attacker could potentially exploit this vulnerability to trick the victim into executing state changing operations.

  • CVE-2025-24874MedFeb 11, 2025
    risk 0.44cvss 6.8epss 0.00

    SAP Commerce (Backoffice) uses the deprecated X-FRAME-OPTIONS header to protect against clickjacking. While this protection remains effective now, it may not be the case in the future as browsers might discontinue support for this header in favor of the frame-ancestors CSP…

  • CVE-2024-7404MedNov 14, 2024
    risk 0.44cvss 6.8epss 0.01

    An issue was discovered in GitLab CE/EE affecting all versions starting from 17.2 prior to 17.3.7, starting from 17.4 prior to 17.4.4 and starting from 17.5 prior to 17.5.2, which could have allowed an attacker gaining full API access as the victim via the Device OAuth flow.

  • CVE-2024-2177MedJul 9, 2024
    risk 0.44cvss 6.8epss 0.01

    A Cross Window Forgery vulnerability exists within GitLab CE/EE affecting all versions from 16.3 prior to 16.11.5, 17.0 prior to 17.0.3, and 17.1 prior to 17.1.1. This condition allows for an attacker to abuse the OAuth authentication flow via a crafted payload.

  • CVE-2021-21139MedFeb 9, 2021
    risk 0.43cvss 6.5epss 0.05

    Inappropriate implementation in iframe sandbox in Google Chrome prior to 88.0.4324.96 allowed a remote attacker to bypass navigation restrictions via a crafted HTML page.

  • CVE-2026-16397MedJul 21, 2026
    risk 0.42cvss 6.5epss 0.00

    Clickjacking issue in the WebExtensions component in Firefox for Android. This vulnerability was fixed in Firefox 153.