CWE-1021

Improper Restriction of Rendered UI Layers or Frames

Parent: CWE-441 - Unintended Proxy or Intermediary ('Confused Deputy')

The web application does not restrict or incorrectly restricts frame objects or UI layers that belong to another application or domain.

376 vulnerabilities with CWE-1021
CVE-2021-0433 HIGH
Android - Privilege Escalation
CVSS 8.0
CVE-2021-1403 HIGH
Cisco Ios XE - Denial of Service
CVSS 7.4
CVE-2021-23274 CRITICAL
TIBCO API Exchange Gateway < - SSRF
CVSS 9.8
CVE-2021-0386 HIGH
Android - Privilege Escalation
CVSS 7.8
CVE-2021-0391 HIGH
Android - Info Disclosure
CVSS 7.8
CVE-2021-23955 MEDIUM
Firefox < 85 - Info Disclosure
CVSS 6.1
CVE-2021-23976 HIGH
Firefox <86 - Cross-Origin
CVSS 8.1
CVE-2021-27375 MEDIUM
Traefik <2.4.5 - XSS
CVSS 5.3
CVE-2021-0333 HIGH
Android - Privilege Escalation
CVSS 7.3
CVE-2021-0331 HIGH
Android - Privilege Escalation
CVSS 7.3
CVE-2021-0314 HIGH
Android - Privilege Escalation
CVSS 7.3
CVE-2021-0305 HIGH
Android <10 - Privilege Escalation
CVSS 7.8
CVE-2021-0302 HIGH
Android <10 - Privilege Escalation
CVSS 7.8
CVE-2021-21444 MEDIUM
SAP Business Objects BI Platform - XSS
CVSS 6.1
CVE-2021-21139 MEDIUM
Google Chrome <88.0.4324.96 - CSRF
CVSS 6.5
CVE-2021-21132 CRITICAL
Google Chrome <88.0.4324.96 - RCE
CVSS 9.6
CVE-2021-0315 HIGH
Android <11 - Privilege Escalation
CVSS 7.3
CVE-2021-21111 CRITICAL
Google Chrome <87.0.4280.141 - Privilege Escalation
CVSS 9.6
CVE-2020-10743 MEDIUM
OpenShift Container Platform - CSRF
CVSS 4.3
CVE-2020-4547 MEDIUM
IBM Jazz Foundation - CSRF
CVSS 5.4
CVE-2020-27059 HIGH
Android <11 - Privilege Escalation
CVSS 7.8
CVE-2020-5020 MEDIUM
IBM Spectrum Protect Plus <10.1.6 - CSRF
CVSS 6.1
CVE-2020-16033 MEDIUM
Google Chrome <87.0.4280.66 - XSS
CVSS 4.3
CVE-2020-16032 MEDIUM
Google Chrome <87.0.4280.66 - XSS
CVSS 4.3
CVE-2020-16031 MEDIUM
Google Chrome <87.0.4280.66 - XSS
CVSS 4.3
Details
Vulnerabilities 376