CWE-1021

Improper Restriction of Rendered UI Layers or Frames

Parent: CWE-441 - Unintended Proxy or Intermediary ('Confused Deputy')

The web application does not restrict or incorrectly restricts frame objects or UI layers that belong to another application or domain.

376 vulnerabilities with CWE-1021
CVE-2021-27414 MEDIUM
Hitachi ABB Power Grids Ellipse EAM <9.0.25 - CSRF
CVSS 5.5
CVE-2021-46708 MEDIUM
swagger-ui-dist <4.1.3 - CSRF
CVSS 6.1
CVE-2021-41657 MEDIUM
SmartBear CodeCollaborator <6.1.6102 - CSRF
CVSS 6.1
CVE-2021-3660 MEDIUM
Cockpit - CSRF
CVSS 4.3
CVE-2021-39038 MEDIUM
IBM WebSphere Application Server <22.0.0.2 - CSRF
CVSS 5.4
CVE-2021-39669 HIGH
Android <12 - Privilege Escalation
CVSS 7.8
CVE-2021-22819 MEDIUM
EVlink <R8 V3.4.0.2 - XSS
CVSS 4.3
CVE-2021-1036 HIGH
Android - Privilege Escalation
CVSS 7.8
CVE-2021-34087 HIGH
Ultimaker <6.3-5.2.16 - CSRF
CVSS 7.1
CVE-2021-1040 HIGH
Android - Privilege Escalation
CVSS 7.8
CVE-2021-1039 HIGH
Android - Privilege Escalation
CVSS 7.8
CVE-2021-1038 MEDIUM
Android - DoS
CVSS 5.5
CVE-2021-1016 HIGH
Android -12 - Privilege Escalation
CVSS 7.3
CVE-2021-1006 MEDIUM
Android - Info Disclosure
CVSS 4.4
CVE-2021-0992 LOW
Android <12 - Privilege Escalation
CVSS 3.3
CVE-2021-0963 HIGH
Android - Privilege Escalation
CVSS 7.1
CVE-2021-0954 HIGH
Android <11 - Privilege Escalation
CVSS 7.3
CVE-2021-39054 MEDIUM
IBM Spectrum Copy Data Management <2.2.13 - CSRF
CVSS 5.4
CVE-2021-40834 MEDIUM
F-Secure SAFE Browser - Info Disclosure
CVSS 4.3
CVE-2021-43546 MEDIUM
Thunderbird <91.4.0-Firefox <95 - Info Disclosure
CVSS 4.3
CVE-2021-38509 MEDIUM
Firefox < 94, Thunderbird < 91.3, Firefox ESR < 91.3 - XSS
CVSS 4.3
CVE-2021-38508 MEDIUM
Firefox <94, Thunderbird <91.3, Firefox ESR <91.3 - CSRF
CVSS 4.3
CVE-2021-38506 MEDIUM
Firefox <94 - Info Disclosure
CVSS 4.3
CVE-2021-43048 CRITICAL
TIBCO PartnerExpress <6.2.1 - SSRF
CVSS 9.8
CVE-2021-35237 MEDIUM
Kiwi Syslog Server - XSS
CVSS 5.0
Details
Vulnerabilities 376