Vulnerabilities > Improper Restriction of Rendered UI Layers or Frames

DATE CVE VULNERABILITY TITLE RISK
2020-04-02 CVE-2019-19001 Improper Restriction of Rendered UI Layers or Frames vulnerability in Hitachienergy Esoms 4.0/6.0/6.0.2
For ABB eSOMS versions 4.0 to 6.0.2, the X-Frame-Options header is not configured in HTTP response.
network
low complexity
hitachienergy CWE-1021
6.5
2020-03-10 CVE-2020-0051 Improper Restriction of Rendered UI Layers or Frames vulnerability in Google Android 10.0
In onCreate of SettingsHomepageActivity, there is a possible tapjacking attack.
local
low complexity
google CWE-1021
7.8
2020-03-09 CVE-2020-9517 Improper Restriction of Rendered UI Layers or Frames vulnerability in Microfocus Service Manager 9.50/9.60
There is an improper restriction of rendered UI layers or frames vulnerability in Micro Focus Service Manager Release Control versions 9.50 and 9.60.
network
low complexity
microfocus CWE-1021
5.4
2020-02-27 CVE-2015-5686 Improper Restriction of Rendered UI Layers or Frames vulnerability in Puppet Enterprise
Parts of the Puppet Enterprise Console 3.x were found to be susceptible to clickjacking and CSRF (Cross-Site Request Forgery) attacks.
network
low complexity
puppet CWE-1021
8.8
2020-02-18 CVE-2013-5594 Improper Restriction of Rendered UI Layers or Frames vulnerability in Mozilla Firefox
Mozilla Firefox before 25 allows modification of anonymous content of pluginProblem.xml binding
network
low complexity
mozilla CWE-1021
4.3
2020-02-13 CVE-2020-0014 Improper Restriction of Rendered UI Layers or Frames vulnerability in Google Android
It is possible for a malicious application to construct a TYPE_TOAST window manually and make that window clickable.
local
low complexity
google CWE-1021
5.5
2020-02-11 CVE-2016-5710 Improper Restriction of Rendered UI Layers or Frames vulnerability in Netapp Snap Creator Framework
NetApp Snap Creator Framework before 4.3P1 allows remote authenticated users to conduct clickjacking attacks via unspecified vectors.
network
low complexity
netapp CWE-1021
4.6
2020-02-05 CVE-2013-2682 Improper Restriction of Rendered UI Layers or Frames vulnerability in Cisco Linksys E4200 Firmware 1.0.05
Cisco Linksys E4200 1.0.05 Build 7 devices contain a Clickjacking Vulnerability which allows remote attackers to obtain sensitive information.
network
low complexity
cisco CWE-1021
4.3
2020-02-05 CVE-2013-2675 Improper Restriction of Rendered UI Layers or Frames vulnerability in Brother Mfc-9970Cdw Firmware 1.10
Brother MFC-9970CDW 1.10 devices with Firmware L contain a Frameable response (Clickjacking) vulnerability which could allow remote attackers to obtain sensitive information.
network
low complexity
brother CWE-1021
6.5
2020-02-04 CVE-2019-4548 Improper Restriction of Rendered UI Layers or Frames vulnerability in IBM Security Directory Server
IBM Security Directory Server 6.4.0 could allow a remote attacker to hijack the clicking action of the victim.
network
low complexity
ibm CWE-1021
6.1