Vulnerabilities > Improper Restriction of Rendered UI Layers or Frames

DATE CVE VULNERABILITY TITLE RISK
2020-01-23 CVE-2013-6772 Improper Restriction of Rendered UI Layers or Frames vulnerability in Splunk
Splunk before 5.0.4 lacks X-Frame-Options which can allow Clickjacking
network
low complexity
splunk CWE-1021
4.3
2019-12-20 CVE-2019-4742 Improper Restriction of Rendered UI Layers or Frames vulnerability in IBM Financial Transaction Manager for Multiplatform 3.0.0.0
IBM Financial Transaction Manager 3.0 could allow a remote attacker to hijack the clicking action of the victim.
network
low complexity
ibm CWE-1021
6.1
2019-12-12 CVE-2019-15930 Improper Restriction of Rendered UI Layers or Frames vulnerability in Intesync Solismed 3.3
Intesync Solismed 3.3sp allows Clickjacking.
network
low complexity
intesync CWE-1021
4.3
2019-11-25 CVE-2019-5861 Improper Restriction of Rendered UI Layers or Frames vulnerability in Google Chrome
Insufficient data validation in Blink in Google Chrome prior to 76.0.3809.87 allowed a remote attacker to bypass anti-clickjacking policy via a crafted HTML page.
network
low complexity
google CWE-1021
4.3
2019-11-22 CVE-2019-4215 Improper Restriction of Rendered UI Layers or Frames vulnerability in IBM Smartcloud Analytics LOG Analysis
IBM SmartCloud Analytics 1.3.1 through 1.3.5 could allow a remote attacker to hijack the clicking action of the victim.
network
low complexity
ibm CWE-1021
6.1
2019-10-04 CVE-2019-17131 Improper Restriction of Rendered UI Layers or Frames vulnerability in Vbulletin
vBulletin before 5.5.4 allows clickjacking.
network
low complexity
vbulletin CWE-1021
4.3
2019-09-30 CVE-2019-4109 Improper Restriction of Rendered UI Layers or Frames vulnerability in IBM Websphere Extreme Scale
IBM WebSphere eXtreme Scale 8.6 Admin Console could allow a remote attacker to hijack the clicking action of the victim.
network
low complexity
ibm CWE-1021
6.1
2019-09-18 CVE-2019-1975 Improper Restriction of Rendered UI Layers or Frames vulnerability in Cisco products
A vulnerability in the web-based interface of Cisco HyperFlex Software could allow an unauthenticated, remote attacker to execute a cross-frame scripting (XFS) attack on an affected device.
network
low complexity
cisco CWE-1021
6.1
2019-09-17 CVE-2019-4086 Improper Restriction of Rendered UI Layers or Frames vulnerability in IBM Application Performance Management 8.1.4
IBM Cloud Application Performance Management 8.1.4 could allow a remote attacker to hijack the clicking action of the victim.
network
low complexity
ibm CWE-1021
6.1
2019-09-16 CVE-2019-16371 Improper Restriction of Rendered UI Layers or Frames vulnerability in Logmein Lastpass
LogMeIn LastPass before 4.33.0 allows attackers to construct a crafted web site that captures the credentials for a victim's account on a previously visited web site, because do_popupregister can be bypassed via clickjacking.
network
low complexity
logmein CWE-1021
8.2