Skip to main content

CWE archive

CWE-1021 CVEs

Programmatic archive

404 CVEs tagged with CWE-10217 Critical, 94 High, 283 Medium, 20 Low, 0 Unrated.

CVE-2020-16033

Published Jan 8, 2021

Inappropriate implementation in WebUSB in Google Chrome prior to 87.0.4280.66 allowed a remote attacker to spoof security UI via a crafted HTML page.

CVSS 4.3 · Medium
Vendor/product tagsBeta · best-effort

CVE-2020-16032

Published Jan 8, 2021

Insufficient data validation in sharing in Google Chrome prior to 87.0.4280.66 allowed a remote attacker to spoof the contents of the Omnibox (URL bar) via a crafted HTML page.

CVSS 4.3 · Medium
Vendor/product tagsBeta · best-effort

CVE-2020-16031

Published Jan 8, 2021

Insufficient data validation in UI in Google Chrome prior to 87.0.4280.66 allowed a remote attacker to spoof the contents of the Omnibox (URL bar) via a crafted HTML page.

CVSS 4.3 · Medium
Vendor/product tagsBeta · best-effort

CVE-2020-26962

Published Dec 9, 2020

Cross-origin iframes that contained a login form could have been recognized by the login autofill service, and populated. This could have been used in clickjacking attacks, as wel…

CVSS 6.1 · Medium
Vendor/product tagsBeta · best-effort

CVE-2020-9987

Published Dec 8, 2020

An inconsistent user interface issue was addressed with improved state management. This issue is fixed in Safari 14.0. Visiting a malicious website may lead to address bar spoofin…

CVSS 4.3 · Medium
Vendor/product tagsBeta · best-effort

CVE-2020-9945

Published Dec 8, 2020

A spoofing issue existed in the handling of URLs. This issue was addressed with improved input validation. This issue is fixed in macOS Big Sur 11.0.1, Safari 14.0.1. Visiting a m…

CVSS 4.3 · Medium
Vendor/product tagsBeta · best-effort

CVE-2020-9942

Published Dec 8, 2020

An inconsistent user interface issue was addressed with improved state management. This issue is fixed in macOS Big Sur 11.0.1, Safari 13.1.2. Visiting a malicious website may lea…

CVSS 4.3 · Medium
Vendor/product tagsBeta · best-effort

CVE-2020-5679

Published Dec 3, 2020

Improper restriction of rendered UI layers or frames in EC-CUBE versions from 3.0.0 to 3.0.18 leads to clickjacking attacks. If a user accesses a specially crafted page while logg…

CVSS 6.1 · Medium
Vendor/product tagsBeta · best-effort

CVE-2020-24711

Published Oct 28, 2020

The Reset button on the Account Settings page in Gophish before 0.11.0 allows attackers to cause a denial of service via a clickjacking attack

CVSS 6.5 · Medium
Vendor/product tagsBeta · best-effort

CVE-2019-8771

Published Oct 27, 2020

This issue was addressed with improved iframe sandbox enforcement. This issue is fixed in Safari 13.0.1, iOS 13. Maliciously crafted web content may violate iframe sandboxing poli…

CVSS 6.1 · Medium
Vendor/product tagsBeta · best-effort

CVE-2020-7371

Published Oct 20, 2020

User Interface (UI) Misrepresentation of Critical Information vulnerability in the address bar of the Yandex Browser allows an attacker to obfuscate the true source of data as pre…

CVSS 4.3 · Medium
Vendor/product tagsBeta · best-effort

CVE-2020-15793

Published Oct 15, 2020

A vulnerability has been identified in Desigo Insight (All versions). The device does not properly set the X-Frame-Options HTTP Header which makes it vulnerable to Clickjacking at…

CVSS 5.4 · Medium
Vendor/product tagsBeta · best-effort

CVE-2020-4727

Published Sep 25, 2020

IBM InfoSphere Information Server 11.7 could allow a remote attacker to hijack the clicking action of the victim. By persuading a victim to visit a malicious Web site, a remote at…

CVSS 6.1 · Medium
Vendor/product tagsBeta · best-effort

CVE-2020-0366

Published Sep 17, 2020

In PackageInstaller, there is a possible permissions bypass due to a tapjacking vulnerability. This could lead to local escalation of privilege using an app set as the default Ass…

CVSS 7.8 · High
Vendor/product tagsBeta · best-effort

CVE-2020-0387

Published Sep 17, 2020

In manifest files of the SmartSpace package, there is a possible tapjacking vector due to a missing permission check. This could lead to local escalation of privilege and account…

CVSS 7.8 · High
Vendor/product tagsBeta · best-effort

CVE-2020-0394

Published Sep 17, 2020

In onCreate of BluetoothPairingDialog.java, there is a possible tapjacking vector due to an insecure default value. This could lead to local escalation of privilege and untrusted…

CVSS 7.8 · High
Vendor/product tagsBeta · best-effort
Showing 301-325 of 404 CVEsPage 13 of 17