VYPR

CWE-449

The UI Performs the Wrong Action

BaseIncomplete

Description

The UI performs the wrong action with respect to the user's request.

Hierarchy (View 1000)

Parents

Children

none

CVEs mapped to this weakness (14)

  • CVE-2023-43585HigDec 13, 2023
    risk 0.46cvss 7.1epss 0.01

    Improper access control in Zoom Mobile App for iOS and Zoom SDKs for iOS before version 5.16.5 may allow an authenticated user to conduct a disclosure of information via network access.

  • CVE-2023-39215HigSep 12, 2023
    risk 0.46cvss 7.1epss 0.01

    Improper authentication in Zoom clients may allow an authenticated user to conduct a denial of service via network access.

  • CVE-2023-36535HigAug 8, 2023
    risk 0.46cvss 7.1epss 0.01

    Client-side enforcement of server-side security in Zoom clients before 5.14.10 may allow an authenticated user to enable information disclosure via network access.

  • CVE-2023-39209MedAug 8, 2023
    risk 0.38cvss 5.9epss 0.01

    Improper input validation in Zoom Desktop Client for Windows before 5.15.5 may allow an authenticated user to enable an information disclosure via network access.

  • CVE-2025-26643MedMar 7, 2025
    risk 0.35cvss 5.4epss 0.01

    The UI performs the wrong action in Microsoft Edge (Chromium-based) allows an unauthorized attacker to perform spoofing over a network.

  • CVE-2025-56139MedSep 3, 2025
    risk 0.34cvss 5.3epss 0.00

    LinkedIn Mobile Application for Android version 4.1.1087.2 fails to update link preview metadata (image, title, description) when a user replaces the original URL in a post or comment before publishing. As a result, the stale preview remains visible while the clickable link…

  • CVE-2024-24698MedFeb 14, 2024
    risk 0.32cvss 4.9epss 0.01

    Improper authentication in some Zoom clients may allow a privileged user to conduct a disclosure of information via local access.

  • CVE-2025-13637MedDec 2, 2025
    risk 0.28cvss 4.3epss 0.00

    Inappropriate implementation in Downloads in Google Chrome prior to 143.0.7499.41 allowed a remote attacker who convinced a user to engage in specific UI gestures to bypass download protections via a crafted HTML page. (Chromium security severity: Low)

  • CVE-2025-49736MedAug 12, 2025
    risk 0.28cvss 4.3epss 0.00

    The ui performs the wrong action in Microsoft Edge for Android allows an unauthorized attacker to perform spoofing over a network.

  • CVE-2025-21404MedFeb 6, 2025
    risk 0.28cvss 4.3epss 0.01

    Microsoft Edge (Chromium-based) Spoofing Vulnerability

  • CVE-2024-49041MedDec 6, 2024
    risk 0.28cvss 4.3epss 0.01

    Microsoft Edge (Chromium-based) Spoofing Vulnerability

  • CVE-2024-43577MedOct 18, 2024
    risk 0.28cvss 4.3epss 0.00

    Microsoft Edge (Chromium-based) Spoofing Vulnerability

  • CVE-2024-38083MedJun 13, 2024
    risk 0.28cvss 4.3epss 0.00

    Microsoft Edge (Chromium-based) Spoofing Vulnerability

  • CVE-2023-43588LowNov 15, 2023
    risk 0.23cvss 3.5epss 0.01

    Insufficient control flow management in some Zoom clients may allow an authenticated user to conduct an information disclosure via network access.