CWE-451

User Interface (UI) Misrepresentation of Critical Information

Parent: CWE-684 - Incorrect Provision of Specified Functionality

The user interface (UI) does not properly represent critical information to the user, allowing the information - or its source - to be obscured or spoofed. This is often a component in phishing attacks.

230 vulnerabilities with CWE-451
CVE-2023-0130 MEDIUM
Google Chrome < 109.0.5414.74 - URL Spoofing via Fullscreen API
CVSS 6.5
CVE-2022-45404 MEDIUM
Firefox ESR < 102.5, Thunderbird < 102.5, Firefox < 107 - SSRF
CVSS 6.5
CVE-2022-34479 MEDIUM
Firefox <102, Firefox ESR <91.11, Thunderbird <102, Thunderbird <91...
CVSS 6.5
CVE-2022-26383 MEDIUM
Firefox < 98.0, Firefox ESR < 91.7, and Thunderbird < 91.7 - Fullscreen Notification Bypass via Popup Resizing
CVSS 4.3
CVE-2022-22762 MEDIUM
Firefox < 97.0 - User Interface Misrepresentation via JavaScript Alert Overlay
CVSS 4.3
CVE-2022-20530 MEDIUM
Android 13 - Unauthenticated Information Disclosure via Misleading Permission String
CVSS 5.3
CVE-2022-38163 LOW
F-Secure SAFE Browser <19.0 - Spoof
CVSS 3.5
CVE-2022-3313 MEDIUM
Google Chrome < 106.0.5249.62 - Security UI Spoofing via Full Screen Mode
CVSS 6.5
CVE-2022-39258 HIGH
mailcow < 2022-09 - Open Redirect via Spoofed Swagger Authorize Link
CVSS 8.1
CVE-2022-32816 MEDIUM
iPadOS < 15.6 - User Interface Spoofing via Malicious Website Framing
CVSS 6.5
CVE-2022-2800 MEDIUM
SourceCodester Gym Management System - XSS
CVSS 4.3
CVE-2022-23646 MEDIUM
Next.js 10.0.0-12.0.9 - User Interface Misrepresentation via SVG Image Host Configuration
CVSS 5.9
CVE-2021-27773 MEDIUM
Hcltech HCL Sametime Meeting Chat - Clickjacking
CVSS 4.2
CVE-2021-27414 MEDIUM
Hitachi ABB Power Grids Ellipse EAM <9.0.25 - CSRF
CVSS 5.5
CVE-2021-41598 HIGH
GitHub Enterprise Server - Info Disclosure
CVSS 8.8
CVE-2021-33593 MEDIUM
Whale < 1.14.0 - Address Bar Spoofing via UI Misrepresentation
CVSS 5.3
CVE-2021-22866 HIGH
GitHub Enterprise Server - Privilege Escalation
CVSS 8.8
CVE-2020-9236 HIGH
Huawei FusionCompute - User Interface Misrepresentation of Critical Information
CVSS 8.8
CVE-2020-7371 MEDIUM
Yandex Browser <3.3.9 - Info Disclosure
CVSS 4.3
CVE-2020-7370 MEDIUM
Bolt Browser < 1.4 - Address Bar Spoofing
CVSS 4.3
CVE-2020-7369 MEDIUM
Yandex Browser < 20.8.4 - Address Bar Spoofing
CVSS 4.3
CVE-2020-7364 MEDIUM
UCWeb UC Browser <13.0.8 - Info Disclosure
CVSS 4.3
CVE-2020-7363 MEDIUM
UCWeb UC Browser <13.0.8 - Info Disclosure
CVSS 4.3
CVE-2020-10775 MEDIUM
ovirt-engine <4.4 - Open Redirect
CVSS 5.3
CVE-2019-25718 HIGH
Drger Infinity Explorer C700 - Privilege Escalation via Kiosk Mode Dialog Interaction
CVSS 8.4
Details
Vulnerabilities 230