Skip to main content

CWE archive

CWE-1021 CVEs

Programmatic archive

399 CVEs tagged with CWE-10217 Critical, 90 High, 283 Medium, 19 Low, 0 Unrated.

CVE-2022-33723

Published Aug 5, 2022

A vulnerable code in onCreate of BluetoothScanDialog prior to SMR Aug-2022 Release 1, allows attackers to trick the user to select an unwanted bluetooth device via tapjacking/over…

CVSS 4.8 · Medium
Vendor/product tagsBeta · best-effort

CVE-2022-34162

Published Aug 1, 2022

IBM CICS TX 11.1 could allow a remote attacker to hijack the clicking action of the victim. By persuading a victim to visit a malicious Web site, a remote attacker could exploit t…

CVSS 6.1 · Medium
Vendor/product tagsBeta · best-effort

CVE-2022-1138

Published Jul 23, 2022

Inappropriate implementation in Web Cursor in Google Chrome prior to 100.0.4896.60 allowed a remote attacker who had compromised the renderer process to obscure the contents of th…

CVSS 6.5 · Medium
Vendor/product tagsBeta · best-effort

CVE-2022-20226

Published Jul 13, 2022

In finishDrawingWindow of WindowManagerService.java, there is a possible tapjacking due to improper input validation. This could lead to local escalation of privilege with User ex…

CVSS 3.9 · Low
evidence mentions
1
Buzz score
11.9
Vendor/product tagsBeta · best-effort

CVE-2022-20212

Published Jul 13, 2022

In wifi.RequestToggleWifiActivity of AndroidManifest.xml, there is a possible EoP due to a tapjacking/overlay attack. This could lead to local escalation of privilege with no addi…

CVSS 7.8 · High
Vendor/product tagsBeta · best-effort

CVE-2022-28889

Published Jul 7, 2022

In Apache Druid 0.22.1 and earlier, the server did not set appropriate headers to prevent clickjacking. Druid 0.23.0 and later prevent clickjacking using the Content-Security-Poli…

CVSS 4.3 · Medium
Vendor/product tagsBeta · best-effort

CVE-2021-39691

Published Jun 15, 2022

In WindowManager, there is a possible tapjacking attack due to an incorrect window flag when processing user input. This could lead to local escalation of privilege with no additi…

CVSS 7.3 · High
Vendor/product tagsBeta · best-effort

CVE-2017-20041

Published Jun 13, 2022

A vulnerability was found in Ucweb UC Browser 11.2.5.932. It has been classified as critical. Affected is an unknown function of the component HTML Handler. The manipulation of th…

CVSS 5.4 · Medium
Vendor/product tagsBeta · best-effort

CVE-2021-39796

Published Apr 12, 2022

In HarmfulAppWarningActivity of HarmfulAppWarningActivity.java, there is a possible way to trick victim to install harmful app due to a tapjacking/overlay attack. This could lead…

CVSS 7.3 · High
Vendor/product tagsBeta · best-effort

CVE-2022-28649

Published Apr 5, 2022

In JetBrains YouTrack before 2022.1.43563 it was possible to include an iframe from a third-party domain in the issue description

CVSS 4.6 · Medium
Vendor/product tagsBeta · best-effort

CVE-2022-0455

Published Apr 5, 2022

Inappropriate implementation in Full Screen Mode in Google Chrome on Android prior to 98.0.4758.80 allowed a remote attacker to spoof the contents of the Omnibox (URL bar) via a c…

CVSS 6.5 · Medium
evidence mentions
2
Buzz score
17.5
Vendor/product tagsBeta · best-effort

CVE-2021-44683

Published Mar 25, 2022

The DuckDuckGo browser 7.64.4 on iOS allows Address Bar Spoofing due to mishandling of the JavaScript window.open function (used to open a secondary browser window). This could be…

CVSS 8.2 · High
Vendor/product tagsBeta · best-effort

CVE-2021-39702

Published Mar 16, 2022

In onCreate of RequestManageCredentials.java, there is a possible way for a third party app to install certificates without user approval due to a tapjacking/overlay attack. This…

CVSS 7.8 · High
Vendor/product tagsBeta · best-effort

CVE-2021-39692

Published Mar 16, 2022

In onCreate of SetupLayoutActivity.java, there is a possible way to setup a work profile bypassing user consent due to a tapjacking/overlay attack. This could lead to local escala…

CVSS 7.8 · High
Vendor/product tagsBeta · best-effort

CVE-2022-24733

Published Mar 14, 2022

Sylius is an open source eCommerce platform. Prior to versions 1.9.10, 1.10.11, and 1.11.2, it is possible for a page controlled by an attacker to load the website within an ifram…

CVSS 6.1 · Medium
Vendor/product tagsBeta · best-effort

CVE-2021-46708

Published Mar 11, 2022

The swagger-ui-dist package before 4.1.3 for Node.js could allow a remote attacker to hijack the clicking action of the victim. By persuading a victim to visit a malicious Web sit…

CVSS 6.1 · Medium
Vendor/product tagsBeta · best-effort

CVE-2021-41657

Published Mar 10, 2022

SmartBear CodeCollaborator v6.1.6102 was discovered to contain a vulnerability in the web UI which would allow an attacker to conduct a clickjacking attack.

CVSS 6.1 · Medium
Vendor/product tagsBeta · best-effort
Showing 201-225 of 399 CVEsPage 9 of 16