Vulnerabilities > Improper Restriction of Rendered UI Layers or Frames

DATE CVE VULNERABILITY TITLE RISK
2022-12-22 CVE-2022-45418 If a custom mouse cursor is specified in CSS, under certain circumstances the cursor could have been drawn over the browser UI, resulting in potential user confusion or spoofing attacks.
network
low complexity
CWE-1021
6.1
2022-12-22 CVE-2022-45420 Use tables inside of an iframe, an attacker could have caused iframe contents to be rendered outside the boundaries of the iframe, resulting in potential user confusion or spoofing attacks.
network
low complexity
CWE-1021
6.5
2022-12-16 CVE-2022-20520 Improper Restriction of Rendered UI Layers or Frames vulnerability in Google Android 13.0
In onCreate of various files, there is a possible tapjacking/overlay attack.
local
low complexity
google CWE-1021
7.8
2022-12-16 CVE-2022-20553 Improper Restriction of Rendered UI Layers or Frames vulnerability in Google Android 13.0
In onCreate of LogAccessDialogActivity.java, there is a possible way to bypass a permission check due to a tapjacking/overlay attack.
local
low complexity
google CWE-1021
6.5
2022-12-15 CVE-2022-46695 Improper Restriction of Rendered UI Layers or Frames vulnerability in Apple products
A spoofing issue existed in the handling of URLs.
network
low complexity
apple CWE-1021
6.5
2022-12-13 CVE-2022-20442 Improper Restriction of Rendered UI Layers or Frames vulnerability in Google Android 10.0/11.0/12.0
In onCreate of ReviewPermissionsActivity.java, there is a possible way to grant permissions for a separate app with API level < 23 due to a tapjacking/overlay attack.
local
low complexity
google CWE-1021
7.3
2022-12-13 CVE-2022-20501 Improper Restriction of Rendered UI Layers or Frames vulnerability in Google Android
In onCreate of EnableAccountPreferenceActivity.java, there is a possible way to mislead the user into enabling a malicious phone account due to a tapjacking/overlay attack.
local
low complexity
google CWE-1021
7.3
2022-12-13 CVE-2022-46061 Improper Restriction of Rendered UI Layers or Frames vulnerability in Aerocms Project Aerocms 0.0.1
AeroCMS v0.0.1 is vulnerable to ClickJacking.
network
low complexity
aerocms-project CWE-1021
6.1
2022-12-12 CVE-2022-34318 Improper Restriction of Rendered UI Layers or Frames vulnerability in IBM Cics TX 11.1
IBM CICS TX 11.1 could allow a remote attacker to hijack the clicking action of the victim.
network
low complexity
ibm CWE-1021
6.1
2022-12-08 CVE-2022-3260 Improper Restriction of Rendered UI Layers or Frames vulnerability in Redhat Openshift 4.9
The response header has not enabled X-FRAME-OPTIONS, Which helps prevents against Clickjacking attack..
network
low complexity
redhat CWE-1021
4.8