Vulnerabilities > Improper Restriction of Rendered UI Layers or Frames

DATE CVE VULNERABILITY TITLE RISK
2022-03-10 CVE-2021-41657 Improper Restriction of Rendered UI Layers or Frames vulnerability in Smartbear Collaborator 6.1.6102
SmartBear CodeCollaborator v6.1.6102 was discovered to contain a vulnerability in the web UI which would allow an attacker to conduct a clickjacking attack.
network
low complexity
smartbear CWE-1021
6.1
2022-02-24 CVE-2021-39038 Improper Restriction of Rendered UI Layers or Frames vulnerability in IBM Websphere Application Server
IBM WebSphere Application Server 9.0 and IBM WebSphere Application Server Liberty 17.0.0.3 through 22.0.0.2 could allow a remote attacker to hijack the clicking action of the victim.
network
low complexity
ibm CWE-1021
5.4
2022-02-12 CVE-2022-0110 Improper Restriction of Rendered UI Layers or Frames vulnerability in multiple products
Incorrect security UI in Autofill in Google Chrome prior to 97.0.4692.71 allowed a remote attacker to spoof the contents of the Omnibox (URL bar) via a crafted HTML page.
network
low complexity
google fedoraproject CWE-1021
4.3
2022-02-11 CVE-2021-39669 Improper Restriction of Rendered UI Layers or Frames vulnerability in Google Android 11.0/12.0
In onCreate of InstallCaCertificateWarning.java, there is a possible way to mislead an user about CA installation circumstances due to a tapjacking/overlay attack.
local
low complexity
google CWE-1021
7.8
2022-01-28 CVE-2021-22819 Improper Restriction of Rendered UI Layers or Frames vulnerability in Schneider-Electric products
A CWE-1021 Improper Restriction of Rendered UI Layers or Frames vulnerability exists that could cause unintended modifications of the product settings or user accounts when deceiving the user to use the web interface rendered within iframes.
network
low complexity
schneider-electric CWE-1021
4.3
2022-01-21 CVE-2022-22552 Improper Restriction of Rendered UI Layers or Frames vulnerability in Dell EMC Appsync 3.9.0.0/4.2.0.0/4.3.0.0
Dell EMC AppSync versions 3.9 to 4.3 contain a clickjacking vulnerability in AppSync.
network
low complexity
dell CWE-1021
6.1
2022-01-14 CVE-2021-1036 Improper Restriction of Rendered UI Layers or Frames vulnerability in Google Android
In LocationSettingsActivity of AndroidManifest.xml, there is a possible EoP due to a tapjacking/overlay attack.
local
low complexity
google CWE-1021
7.8
2022-01-10 CVE-2021-34087 Improper Restriction of Rendered UI Layers or Frames vulnerability in Ultimaker products
In Ultimaker S3 3D printer, Ultimaker S5 3D printer, Ultimaker 3 3D printer S-line through 6.3 and Ultimaker 3 through 5.2.16, the local webserver can be used for clickjacking.
network
low complexity
ultimaker CWE-1021
7.1
2021-12-15 CVE-2021-0954 Improper Restriction of Rendered UI Layers or Frames vulnerability in Google Android 10.0/11.0
In ResolverActivity, there is a possible user interaction bypass due to a tapjacking/overlay attack.
local
low complexity
google CWE-1021
7.3
2021-12-15 CVE-2021-0963 Improper Restriction of Rendered UI Layers or Frames vulnerability in Google Android
In onCreate of KeyChainActivity.java, there is a possible way to use an app certificate stored in keychain due to a tapjacking/overlay attack.
local
low complexity
google CWE-1021
7.1