Vulnerabilities > Improper Restriction of Rendered UI Layers or Frames

DATE CVE VULNERABILITY TITLE RISK
2021-08-05 CVE-2021-33596 Improper Restriction of Rendered UI Layers or Frames vulnerability in F-Secure Safe
Showing the legitimate URL in the address bar while loading the content from other domain.
network
low complexity
f-secure CWE-1021
4.1
2021-07-26 CVE-2021-20560 Improper Restriction of Rendered UI Layers or Frames vulnerability in IBM Sterling Connect Direct User Interface 1.4.1.1/1.5.0.2
IBM Sterling Connect:Direct Browser User Interface 1.4.1.1 and 1.5.0.2 could allow a remote attacker to hijack the clicking action of the victim.
network
low complexity
ibm CWE-1021
5.4
2021-07-14 CVE-2021-0586 Improper Restriction of Rendered UI Layers or Frames vulnerability in Google Android
In onCreate of DevicePickerFragment.java, there is a possible way to trick the user to select an unwanted bluetooth device due to a tapjacking/overlay attack.
local
low complexity
google CWE-1021
7.8
2021-07-14 CVE-2021-0603 Improper Restriction of Rendered UI Layers or Frames vulnerability in Google Android 11.0
In onCreate of ContactSelectionActivity.java, there is a possible way to get access to contacts without permission due to a tapjacking/overlay attack.
local
low complexity
google CWE-1021
7.8
2021-06-28 CVE-2021-35300 Improper Restriction of Rendered UI Layers or Frames vulnerability in Zammad
Text injection/Content Spoofing in 404 page in Zammad 1.0.x up to 4.0.0 could allow remote attackers to manipulate users into visiting the attackers' page.
network
low complexity
zammad CWE-1021
4.3
2021-06-22 CVE-2021-0537 Improper Restriction of Rendered UI Layers or Frames vulnerability in Google Android 11.0
In onCreate of WiFiInstaller.java, there is a possible way to install a malicious Hotspot 2.0 configuration due to a tapjacking/overlay attack.
local
low complexity
google CWE-1021
7.3
2021-06-22 CVE-2021-0538 Improper Restriction of Rendered UI Layers or Frames vulnerability in Google Android 11.0
In onCreate of EmergencyCallbackModeExitDialog.java, there is a possible exit of emergency callback mode due to a tapjacking/overlay attack.
local
low complexity
google CWE-1021
7.3
2021-06-22 CVE-2021-0569 Improper Restriction of Rendered UI Layers or Frames vulnerability in Google Android 11.0
In onStart of ContactsDumpActivity.java, there is possible access to contacts due to a tapjacking/overlay attack.
local
low complexity
google CWE-1021
5.0
2021-06-21 CVE-2021-0506 Improper Restriction of Rendered UI Layers or Frames vulnerability in Google Android
In ActivityPicker.java, there is a possible bypass of user interaction in intent resolution due to a tapjacking/overlay attack.
local
low complexity
google CWE-1021
7.3
2021-06-21 CVE-2021-0523 Improper Restriction of Rendered UI Layers or Frames vulnerability in Google Android 10.0/11.0
In onCreate of WifiScanModeActivity.java, there is a possible way to enable Wi-Fi scanning without user consent due to a tapjacking/overlay attack.
local
low complexity
google CWE-1021
7.3