Skip to main content

CWE archive

CWE-1021 CVEs

Programmatic archive

399 CVEs tagged with CWE-10217 Critical, 90 High, 283 Medium, 19 Low, 0 Unrated.

CVE-2022-3034

Published Dec 22, 2022

When receiving an HTML email that specified to load an <code>iframe</code> element from a remote location, a request to the remote document was sent. However, Thunderbird didn't d…

CVSS 4.3 · Medium
evidence mentions
1
Buzz score
11.9
Vendor/product tagsBeta · best-effort

CVE-2022-20553

Published Dec 16, 2022

In onCreate of LogAccessDialogActivity.java, there is a possible way to bypass a permission check due to a tapjacking/overlay attack. This could lead to local escalation of privil…

CVSS 6.5 · Medium
Vendor/product tagsBeta · best-effort

CVE-2022-20520

Published Dec 16, 2022

In onCreate of various files, there is a possible tapjacking/overlay attack. This could lead to local escalation of privilege or denial of server with User execution privileges ne…

CVSS 7.8 · High
Vendor/product tagsBeta · best-effort

CVE-2022-20501

Published Dec 13, 2022

In onCreate of EnableAccountPreferenceActivity.java, there is a possible way to mislead the user into enabling a malicious phone account due to a tapjacking/overlay attack. This c…

CVSS 7.3 · High
Vendor/product tagsBeta · best-effort

CVE-2022-20442

Published Dec 13, 2022

In onCreate of ReviewPermissionsActivity.java, there is a possible way to grant permissions for a separate app with API level < 23 due to a tapjacking/overlay attack. This could l…

CVSS 7.3 · High
Vendor/product tagsBeta · best-effort

CVE-2022-34318

Published Dec 12, 2022

IBM CICS TX 11.1 could allow a remote attacker to hijack the clicking action of the victim. By persuading a victim to visit a malicious Web site, a remote attacker could exploit t…

CVSS 5.4 · Medium
Vendor/product tagsBeta · best-effort

CVE-2022-3260

Published Dec 8, 2022

The response header has not enabled X-FRAME-OPTIONS, Which helps prevents against Clickjacking attack.. Some browsers would interpret these results incorrectly, allowing clickjack…

CVSS 4.8 · Medium
Vendor/product tagsBeta · best-effort

CVE-2022-36182

Published Oct 27, 2022

Hashicorp Boundary v0.8.0 is vulnerable to Clickjacking which allow for the interception of login credentials, re-direction of users to malicious sites, or causing users to perfor…

CVSS 6.1 · Medium
Vendor/product tagsBeta · best-effort

CVE-2022-3167

Published Sep 8, 2022

Improper Restriction of Rendered UI Layers or Frames in GitHub repository ikus060/rdiffweb prior to 2.4.1.

CVSS 8.8 · High
Vendor/product tagsBeta · best-effort

CVE-2022-36736

Published Sep 8, 2022

Jitsi-2.10.5550 was discovered to contain a vulnerability in its web UI which allows attackers to perform a clickjacking attack via a crafted HTTP request. NOTE: this is disputed…

CVSS 6.1 · Medium
Vendor/product tagsBeta · best-effort

CVE-2022-2965

Published Aug 23, 2022

Improper Restriction of Rendered UI Layers or Frames in GitHub repository notrinos/notrinoserp prior to 0.7.

CVSS 4.3 · Medium
Vendor/product tagsBeta · best-effort

CVE-2022-20331

Published Aug 12, 2022

In the Framework, there is a possible way to enable a work profile without user consent due to a tapjacking/overlay attack. This could lead to local escalation of privilege with n…

CVSS 7.8 · High
Vendor/product tagsBeta · best-effort

CVE-2022-20852

Published Aug 10, 2022

Multiple vulnerabilities in the web interface of Cisco Webex Meetings could allow a remote attacker to conduct a cross-site scripting (XSS) attack or a frame hijacking attack agai…

CVSS 5.4 · Medium
Vendor/product tagsBeta · best-effort

CVE-2022-20820

Published Aug 10, 2022

Multiple vulnerabilities in the web interface of Cisco Webex Meetings could allow a remote attacker to conduct a cross-site scripting (XSS) attack or a frame hijacking attack agai…

CVSS 5.4 · Medium
Vendor/product tagsBeta · best-effort

CVE-2022-2734

Published Aug 9, 2022

Improper Restriction of Rendered UI Layers or Frames in GitHub repository openemr/openemr prior to 7.0.0.1.

CVSS 5.4 · Medium
Vendor/product tagsBeta · best-effort

CVE-2022-33727

Published Aug 5, 2022

A vulnerable code in onCreate of SecDevicePickerDialog prior to SMR Aug-2022 Release 1, allows attackers to trick the user to select an unwanted bluetooth device via tapjacking/ov…

CVSS 4.8 · Medium
Vendor/product tagsBeta · best-effort
Showing 176-200 of 399 CVEsPage 8 of 16