Skip to main content

CWE archive

CWE-1021 CVEs

Programmatic archive

399 CVEs tagged with CWE-10217 Critical, 90 High, 283 Medium, 19 Low, 0 Unrated.

CVE-2021-39038

Published Feb 24, 2022

IBM WebSphere Application Server 9.0 and IBM WebSphere Application Server Liberty 17.0.0.3 through 22.0.0.2 could allow a remote attacker to hijack the clicking action of the vict…

CVSS 5.4 · Medium
Vendor/product tagsBeta · best-effort

CVE-2022-0110

Published Feb 12, 2022

Incorrect security UI in Autofill in Google Chrome prior to 97.0.4692.71 allowed a remote attacker to spoof the contents of the Omnibox (URL bar) via a crafted HTML page.

CVSS 4.3 · Medium
Vendor/product tagsBeta · best-effort

CVE-2021-39669

Published Feb 11, 2022

In onCreate of InstallCaCertificateWarning.java, there is a possible way to mislead an user about CA installation circumstances due to a tapjacking/overlay attack. This could lead…

CVSS 7.8 · High
Vendor/product tagsBeta · best-effort

CVE-2022-22552

Published Jan 21, 2022

Dell EMC AppSync versions 3.9 to 4.3 contain a clickjacking vulnerability in AppSync. A remote unauthenticated attacker could potentially exploit this vulnerability to trick the v…

CVSS 6.9 · Medium
Vendor/product tagsBeta · best-effort

CVE-2021-1036

Published Jan 14, 2022

In LocationSettingsActivity of AndroidManifest.xml, there is a possible EoP due to a tapjacking/overlay attack. This could lead to local escalation of privilege with no additional…

CVSS 7.8 · High
Vendor/product tagsBeta · best-effort

CVE-2021-1040

Published Dec 15, 2021

In onCreate of BluetoothPairingSelectionFragment.java, there is a possible EoP due to a tapjacking/overlay attack. This could lead to local escalation of privilege with no additio…

CVSS 7.8 · High
Vendor/product tagsBeta · best-effort

CVE-2021-1039

Published Dec 15, 2021

In NotificationAccessActivity of AndroidManifest.xml, there is a possible EoP due to a tapjacking/overlay attack. This could lead to local escalation of privilege with no addition…

CVSS 7.8 · High
Vendor/product tagsBeta · best-effort

CVE-2021-1038

Published Dec 15, 2021

In UserDetailsActivity of AndroidManifest.xml, there is a possible DoS due to a tapjacking/overlay attack. This could lead to local denial of service with no additional execution…

CVSS 5.5 · Medium
Vendor/product tagsBeta · best-effort

CVE-2021-1016

Published Dec 15, 2021

In onCreate of UsbPermissionActivity.java, there is a possible way to grant an app access to USB without informed user consent due to a tapjacking/overlay attack. This could lead…

CVSS 7.3 · High
Vendor/product tagsBeta · best-effort

CVE-2021-1006

Published Dec 15, 2021

In several functions of DatabaseManager.java, there is a possible leak of Bluetooth MAC addresses due to log information disclosure. This could lead to local information disclosur…

CVSS 4.4 · Medium
Vendor/product tagsBeta · best-effort

CVE-2021-0992

Published Dec 15, 2021

In onCreate of PaymentDefaultDialog.java, there is a possible way to change a default payment app without user consent due to tapjack overlay. This could lead to local escalation…

CVSS 3.3 · Low
Vendor/product tagsBeta · best-effort

CVE-2021-0963

Published Dec 15, 2021

In onCreate of KeyChainActivity.java, there is a possible way to use an app certificate stored in keychain due to a tapjacking/overlay attack. This could lead to local escalation…

CVSS 7.1 · High
Vendor/product tagsBeta · best-effort

CVE-2021-0954

Published Dec 15, 2021

In ResolverActivity, there is a possible user interaction bypass due to a tapjacking/overlay attack. This could lead to local escalation of privilege with User execution privilege…

CVSS 7.3 · High
Vendor/product tagsBeta · best-effort

CVE-2021-40834

Published Dec 10, 2021

A user interface overlay vulnerability was discovered in F-secure SAFE Browser for Android. When user click on a specially crafted seemingly legitimate URL SAFE browser goes into…

CVSS 4.3 · Medium
Vendor/product tagsBeta · best-effort

CVE-2021-43048

Published Nov 16, 2021

The Interior Server and Gateway Server components of TIBCO Software Inc.'s TIBCO PartnerExpress contain a vulnerability that theoretically allows an unauthenticated attacker with…

CVSS 9.8 · Critical
Vendor/product tagsBeta · best-effort

CVE-2021-35237

Published Oct 29, 2021

A missing HTTP header (X-Frame-Options) in Kiwi Syslog Server has left customers vulnerable to click jacking. Clickjacking is an attack that occurs when an attacker uses a transpa…

CVSS 5.0 · Medium
Vendor/product tagsBeta · best-effort
Showing 226-250 of 399 CVEsPage 10 of 16