CWE-1021

Improper Restriction of Rendered UI Layers or Frames

Parent: CWE-441 - Unintended Proxy or Intermediary ('Confused Deputy')

The web application does not restrict or incorrectly restricts frame objects or UI layers that belong to another application or domain.

401 vulnerabilities with CWE-1021
CVE-2018-0355 MEDIUM
Cisco Unified Communications Manager - Cross-Frame Scripting via Insufficient HTML iframe Protection
CVSS 6.1
CVE-2018-1432 MEDIUM
IBM InfoSphere Information Server <11.7 - XSS
CVSS 6.1
CVE-2018-7491 HIGH
PrestaShop < 1.7.2.5 - UI-Redressing/Clickjacking via Missing X-Frame-Options and CSP Headers
CVSS 7.5
CVE-2017-20041 MEDIUM
UC Browser 11.2.5.932 - Improper Restriction of Rendered UI Layers via Title Argument
CVSS 5.4
CVE-2017-16775 HIGH
Synology SSO Server <2.1.3-0129 - CSRF
CVSS 7.1
CVE-2017-11290 MEDIUM
Adobe Connect <= 9.6.2 - UI Redressing
CVSS 6.1
CVE-2017-5697 MEDIUM
Intel AMT Firmware < 9.1.40.1000, 9.5.60.1952, 10.0.50.1004, 11.0.0.1205, 11.6.25.1129 - Clickjacking
CVSS 6.5
CVE-2017-4015 MEDIUM
McAfee Network Data Loss Prevention 9.3.x - Authenticated Clickjacking via HTTP Response Header
CVSS 4.5
CVE-2017-7440 MEDIUM
Kerio Connect 8.0.0-9.2.2 and Kerio Connect Client 9.2.0-9.2.2 - Clickjacking via Email Preview
CVSS 6.5
CVE-2017-0492 MEDIUM
Android 7.1.1 - Privilege Escalation
CVSS 5.5
CVE-2017-5026 MEDIUM
Google Chrome < 56.0.2924.76 - Unauthenticated UI Layer Spoofing via Swapped Frame Alerts
CVSS 4.3
CVE-2017-5016 MEDIUM
Google Chrome <56.0.2924.76-56.0.2924.87 - Info Disclosure
CVSS 6.5
CVE-2016-5710 MEDIUM
NetApp Snap Creator Framework <4.3P1 - CSRF
CVSS 4.6
CVE-2016-2496 CRITICAL
Android 6.x - Tapjacking Attack via Overlapping Window
CVSS 9.8
CVE-2015-5686 HIGH
Puppet Enterprise Console 3.x - CSRF
CVSS 8.8
CVE-2015-1241
Google Chrome <42.0.2311.90 - Info Disclosure
CVE-2014-1483
Mozilla Firefox <27.0 & SeaMonkey <2.24 - CSRF
CVE-2014-1480
Mozilla Firefox <27.0 & SeaMonkey <2.24 - CSRF
CVE-2013-5594 MEDIUM
Mozilla Firefox <25 - Info Disclosure
CVSS 4.3
CVE-2013-2682 MEDIUM
Cisco Linksys E4200 <1.0.05 Build 7 - Info Disclosure
CVSS 4.3
CVE-2013-2675 MEDIUM
Brother MFC-9970CDW Firmware L - Clickjacking via Frameable Response
CVSS 6.5
CVE-2013-6772 MEDIUM
Splunk < 5.0.4 - Clickjacking via Missing X-Frame-Options Header
CVSS 4.3
CVE-2013-5614
Mozilla Firefox <26.0 & SeaMonkey <2.23 - XSS
CVE-2011-1244
Microsoft Internet Explorer 6, 7, and 8 - Information Disclosure via Frame Tag
CVE-2008-2716
Opera < 9.5 - Frame Spoofing via Location Modification
Details
Vulnerabilities 401