Vulnerabilities > Improper Restriction of Rendered UI Layers or Frames

DATE CVE VULNERABILITY TITLE RISK
2022-12-08 CVE-2022-3260 Improper Restriction of Rendered UI Layers or Frames vulnerability in Redhat Openshift 4.9
The response header has not enabled X-FRAME-OPTIONS, Which helps prevents against Clickjacking attack..
network
low complexity
redhat CWE-1021
4.8
2022-11-01 CVE-2022-42799 Improper Restriction of Rendered UI Layers or Frames vulnerability in multiple products
The issue was addressed with improved UI handling.
network
low complexity
apple fedoraproject debian CWE-1021
6.1
2022-10-27 CVE-2022-36182 Improper Restriction of Rendered UI Layers or Frames vulnerability in Hashicorp Boundary
Hashicorp Boundary v0.8.0 is vulnerable to Clickjacking which allow for the interception of login credentials, re-direction of users to malicious sites, or causing users to perform malicious actions on the site.
network
low complexity
hashicorp CWE-1021
6.1
2022-10-06 CVE-2022-22503 Improper Restriction of Rendered UI Layers or Frames vulnerability in IBM products
IBM Robotic Process Automation 21.0.0 could allow a remote attacker to hijack the clicking action of the victim.
network
low complexity
ibm CWE-1021
6.1
2022-09-08 CVE-2022-36736 Improper Restriction of Rendered UI Layers or Frames vulnerability in Jitsi 2.10.5550
Jitsi-2.10.5550 was discovered to contain a vulnerability in its web UI which allows attackers to perform a clickjacking attack via a crafted HTTP request.
network
low complexity
jitsi CWE-1021
6.1
2022-08-10 CVE-2022-20852 Improper Restriction of Rendered UI Layers or Frames vulnerability in Cisco Webex Meetings
Multiple vulnerabilities in the web interface of Cisco Webex Meetings could allow a remote attacker to conduct a cross-site scripting (XSS) attack or a frame hijacking attack against a user of the web interface.
network
low complexity
cisco CWE-1021
6.5
2022-07-23 CVE-2022-1138 Improper Restriction of Rendered UI Layers or Frames vulnerability in Google Chrome
Inappropriate implementation in Web Cursor in Google Chrome prior to 100.0.4896.60 allowed a remote attacker who had compromised the renderer process to obscure the contents of the Omnibox (URL bar) via a crafted HTML page.
network
low complexity
google CWE-1021
6.5
2022-07-13 CVE-2022-20212 Improper Restriction of Rendered UI Layers or Frames vulnerability in Google Android 10.0/11.0
In wifi.RequestToggleWifiActivity of AndroidManifest.xml, there is a possible EoP due to a tapjacking/overlay attack.
4.4
2022-07-13 CVE-2022-20226 Improper Restriction of Rendered UI Layers or Frames vulnerability in Google Android 12.0/12.1
In finishDrawingWindow of WindowManagerService.java, there is a possible tapjacking due to improper input validation.
3.3
2022-07-07 CVE-2022-28889 Improper Restriction of Rendered UI Layers or Frames vulnerability in Apache Druid
In Apache Druid 0.22.1 and earlier, the server did not set appropriate headers to prevent clickjacking.
network
apache CWE-1021
4.3