Skip to main content

CWE archive

CWE-1021 CVEs

Programmatic archive

404 CVEs tagged with CWE-10217 Critical, 94 High, 283 Medium, 20 Low, 0 Unrated.

CVE-2020-0386

Published Sep 17, 2020

In onCreate of RequestPermissionActivity.java, there is a possible tapjacking vector due to an insecure default value. This could lead to local escalation of privilege allowing an…

CVSS 5.5 · Medium
Vendor/product tagsBeta · best-effort

CVE-2020-7705

Published Aug 24, 2020

This affects the package MintegralAdSDK from 0.0.0. The SDK distributed by the company contains malicious functionality that tracks any URL opened by the app and reports it back t…

CVSS 7.1 · High
Vendor/product tagsBeta · best-effort

CVE-2020-13174

Published Aug 11, 2020

The web server in the Teradici Managament console versions 20.04 and 20.01.1 did not properly set the X-Frame-Options HTTP header, which could allow an attacker to trick a user in…

CVSS 6.1 · Medium
Vendor/product tagsBeta · best-effort

CVE-2020-15648

Published Aug 10, 2020

Using object or embed tags, it was possible to frame other websites, even if they disallowed framing using the X-Frame-Options header. This vulnerability affects Thunderbird < 78…

CVSS 6.5 · Medium
Vendor/product tagsBeta · best-effort

CVE-2020-4644

Published Jul 29, 2020

IBM Planning Analytics Local 2.0.0 through 2.0.9.1 could allow a remote attacker to hijack the clicking action of the victim. By persuading a victim to visit a malicious Web site,…

CVSS 5.4 · Medium
Vendor/product tagsBeta · best-effort

CVE-2019-4323

Published Jul 7, 2020

"HCL AppScan Enterprise advisory API documentation is susceptible to clickjacking, which could allow an attacker to embed the contents of untrusted web pages in a frame."

CVSS 4.3 · Medium
Vendor/product tagsBeta · best-effort

CVE-2020-4322

Published Jun 24, 2020

IBM Security Secret Server 10.7 could allow a remote attacker to hijack the clicking action of the victim. By persuading a victim to visit a malicious Web site, a remote attacker…

CVSS 4.3 · Medium
Vendor/product tagsBeta · best-effort

CVE-2020-4195

Published May 12, 2020

IBM API Connect V2018.4.1.0 through 2018.4.1.10 could allow a remote attacker to hijack the clicking action of the victim. By persuading a victim to visit a malicious Web site, a…

CVSS 5.4 · Medium
Vendor/product tagsBeta · best-effort

CVE-2020-6827

Published Apr 24, 2020

When following a link that opened an intent://-schemed URL, causing a custom tab to be opened, Firefox for Android could be tricked into displaying the incorrect URI. <br> *Note:…

CVSS 4.7 · Medium
evidence mentions
3
Buzz score
25.4
Vendor/product tagsBeta · best-effort

CVE-2020-1728

Published Apr 6, 2020

A vulnerability was found in all versions of Keycloak where, the pages on the Admin Console area of the application are completely missing general HTTP security headers in HTTP-re…

CVSS 4.8 · Medium
Vendor/product tagsBeta · best-effort

CVE-2019-19001

Published Apr 2, 2020

For ABB eSOMS versions 4.0 to 6.0.2, the X-Frame-Options header is not configured in HTTP response. This can potentially allow 'ClickJacking' attacks where an attacker can frame p…

CVSS 6.5 · Medium
Vendor/product tagsBeta · best-effort

CVE-2020-0051

Published Mar 10, 2020

In onCreate of SettingsHomepageActivity, there is a possible tapjacking attack. This could lead to local escalation of privilege in Settings with no additional execution privilege…

CVSS 7.8 · High
Vendor/product tagsBeta · best-effort

CVE-2020-9517

Published Mar 9, 2020

There is an improper restriction of rendered UI layers or frames vulnerability in Micro Focus Service Manager Release Control versions 9.50 and 9.60. The vulnerability may result…

CVSS 5.4 · Medium
Vendor/product tagsBeta · best-effort

CVE-2015-5686

Published Feb 27, 2020

Parts of the Puppet Enterprise Console 3.x were found to be susceptible to clickjacking and CSRF (Cross-Site Request Forgery) attacks. This would allow an attacker to redirect use…

CVSS 8.8 · High
Vendor/product tagsBeta · best-effort

CVE-2013-5594

Published Feb 18, 2020

Mozilla Firefox before 25 allows modification of anonymous content of pluginProblem.xml binding

CVSS 4.3 · Medium
Vendor/product tagsBeta · best-effort

CVE-2020-0014

Published Feb 13, 2020

It is possible for a malicious application to construct a TYPE_TOAST window manually and make that window clickable. This could lead to a local escalation of privilege with no add…

CVSS 5.5 · Medium
evidence mentions
1
Buzz score
11.9
Vendor/product tagsBeta · best-effort

CVE-2016-5710

Published Feb 11, 2020

NetApp Snap Creator Framework before 4.3P1 allows remote authenticated users to conduct clickjacking attacks via unspecified vectors.

CVSS 4.6 · Medium
Vendor/product tagsBeta · best-effort

CVE-2019-4548

Published Feb 4, 2020

IBM Security Directory Server 6.4.0 could allow a remote attacker to hijack the clicking action of the victim. By persuading a victim to visit a malicious Web site, a remote attac…

CVSS 6.1 · Medium
Vendor/product tagsBeta · best-effort
Showing 326-350 of 404 CVEsPage 14 of 17