Total
280 CVE
CVE | Vendors | Products | Updated | CVSS v2 | CVSS v3 |
---|---|---|---|---|---|
CVE-2020-0014 | 1 Google | 1 Android | 2024-02-28 | 4.3 MEDIUM | 5.5 MEDIUM |
It is possible for a malicious application to construct a TYPE_TOAST window manually and make that window clickable. This could lead to a local escalation of privilege with no additional execution privileges needed. User action is needed for exploitation.Product: AndroidVersions: Android-8.0 Android-8.1 Android-9 Android-10Android ID: A-128674520 | |||||
CVE-2013-2682 | 1 Cisco | 2 Linksys E4200, Linksys E4200 Firmware | 2024-02-28 | 4.3 MEDIUM | 4.3 MEDIUM |
Cisco Linksys E4200 1.0.05 Build 7 devices contain a Clickjacking Vulnerability which allows remote attackers to obtain sensitive information. | |||||
CVE-2013-6772 | 1 Splunk | 1 Splunk | 2024-02-28 | 4.3 MEDIUM | 4.3 MEDIUM |
Splunk before 5.0.4 lacks X-Frame-Options which can allow Clickjacking | |||||
CVE-2019-15930 | 1 Intesync | 1 Solismed | 2024-02-28 | 4.3 MEDIUM | 4.3 MEDIUM |
Intesync Solismed 3.3sp allows Clickjacking. | |||||
CVE-2020-2105 | 1 Jenkins | 1 Jenkins | 2024-02-28 | 4.3 MEDIUM | 5.4 MEDIUM |
REST API endpoints in Jenkins 2.218 and earlier, LTS 2.204.1 and earlier were vulnerable to clickjacking attacks. | |||||
CVE-2019-4548 | 1 Ibm | 1 Security Directory Server | 2024-02-28 | 4.3 MEDIUM | 6.1 MEDIUM |
IBM Security Directory Server 6.4.0 could allow a remote attacker to hijack the clicking action of the victim. By persuading a victim to visit a malicious Web site, a remote attacker could exploit this vulnerability to hijack the victim's click actions and possibly launch further attacks against the victim. IBM X-Force ID: 165950. | |||||
CVE-2019-4109 | 1 Ibm | 1 Websphere Extreme Scale | 2024-02-28 | 5.8 MEDIUM | 6.1 MEDIUM |
IBM WebSphere eXtreme Scale 8.6 Admin Console could allow a remote attacker to hijack the clicking action of the victim. By persuading a victim to visit a malicious Web site, a remote attacker could exploit this vulnerability to hijack the victim's click actions and possibly launch further attacks against the victim. IBM X-Force ID: 158102. | |||||
CVE-2019-4215 | 1 Ibm | 1 Smartcloud Analytics Log Analysis | 2024-02-28 | 4.3 MEDIUM | 6.1 MEDIUM |
IBM SmartCloud Analytics 1.3.1 through 1.3.5 could allow a remote attacker to hijack the clicking action of the victim. By persuading a victim to visit a malicious Web site, a remote attacker could exploit this vulnerability to hijack the victim's click actions and possibly launch further attacks against the victim. IBM X-Force ID: 159186. | |||||
CVE-2016-5710 | 1 Netapp | 1 Snap Creator Framework | 2024-02-28 | 3.5 LOW | 4.6 MEDIUM |
NetApp Snap Creator Framework before 4.3P1 allows remote authenticated users to conduct clickjacking attacks via unspecified vectors. | |||||
CVE-2019-5861 | 1 Google | 1 Chrome | 2024-02-28 | 4.3 MEDIUM | 4.3 MEDIUM |
Insufficient data validation in Blink in Google Chrome prior to 76.0.3809.87 allowed a remote attacker to bypass anti-clickjacking policy via a crafted HTML page. | |||||
CVE-2019-4742 | 1 Ibm | 1 Financial Transaction Manager For Multiplatform | 2024-02-28 | 4.3 MEDIUM | 6.1 MEDIUM |
IBM Financial Transaction Manager 3.0 could allow a remote attacker to hijack the clicking action of the victim. By persuading a victim to visit a malicious Web site, a remote attacker could exploit this vulnerability to hijack the victim's click actions and possibly launch further attacks against the victim. IBM X-Force ID: 172877. | |||||
CVE-2020-0051 | 1 Google | 1 Android | 2024-02-28 | 4.4 MEDIUM | 7.8 HIGH |
In onCreate of SettingsHomepageActivity, there is a possible tapjacking attack. This could lead to local escalation of privilege in Settings with no additional execution privileges needed. User interaction is needed for exploitation.Product: AndroidVersions: Android-10Android ID: A-138442483 | |||||
CVE-2019-17131 | 1 Vbulletin | 1 Vbulletin | 2024-02-28 | 4.3 MEDIUM | 4.3 MEDIUM |
vBulletin before 5.5.4 allows clickjacking. | |||||
CVE-2020-9517 | 1 Microfocus | 1 Service Manager | 2024-02-28 | 4.9 MEDIUM | 5.4 MEDIUM |
There is an improper restriction of rendered UI layers or frames vulnerability in Micro Focus Service Manager Release Control versions 9.50 and 9.60. The vulnerability may result in the ability of malicious users to perform UI redress attacks. | |||||
CVE-2015-5686 | 1 Puppet | 1 Puppet Enterprise | 2024-02-28 | 6.8 MEDIUM | 8.8 HIGH |
Parts of the Puppet Enterprise Console 3.x were found to be susceptible to clickjacking and CSRF (Cross-Site Request Forgery) attacks. This would allow an attacker to redirect user input to an untrusted site or hijack a user session. | |||||
CVE-2019-9147 | 1 Mailvelope | 1 Mailvelope | 2024-02-28 | 4.3 MEDIUM | 4.3 MEDIUM |
Mailvelope prior to 3.1.0 is vulnerable to a clickjacking attack against the settings page. As the settings page is intended to be accessible from web applications, the browser's extension isolation mechanisms are disabled (web_accessible_resources). Mailvelope implements additional measures to prevent web applications from directly embedding the settings page, but this mechanism can be bypassed. | |||||
CVE-2019-4086 | 1 Ibm | 1 Application Performance Management | 2024-02-28 | 4.3 MEDIUM | 6.1 MEDIUM |
IBM Cloud Application Performance Management 8.1.4 could allow a remote attacker to hijack the clicking action of the victim. By persuading a victim to visit a malicious Web site, a remote attacker could exploit this vulnerability to hijack the victim's click actions and possibly launch further attacks against the victim. IBM X-Force ID: 157509. | |||||
CVE-2019-3794 | 1 Pivotal Software | 1 Cloud Foundry Uaa | 2024-02-28 | 4.3 MEDIUM | 5.4 MEDIUM |
Cloud Foundry UAA, versions prior to v73.4.0, does not set an X-FRAME-OPTIONS header on various endpoints. A remote user can perform clickjacking attacks on UAA's frontend sites. | |||||
CVE-2018-1853 | 6 Apple, Hp, Ibm and 3 more | 7 Macos, Hp-ux, Aix and 4 more | 2024-02-28 | 4.3 MEDIUM | 6.1 MEDIUM |
IBM Tivoli Storage Manager (IBM Spectrum Protect 7.1 and 8.1) could allow a remote attacker to hijack the clicking action of the victim. By persuading a victim to visit a malicious Web site, a remote attacker could exploit this vulnerability to hijack the victim's click actions and possibly launch further attacks against the victim. IBM X-Force ID: 151014. | |||||
CVE-2019-5243 | 1 Huawei | 2 Hg255s, Hg255s Firmware | 2024-02-28 | 4.3 MEDIUM | 4.3 MEDIUM |
There is a Clickjacking vulnerability in Huawei HG255s product. An attacker may trick user to click a link and affect the integrity of a device by exploiting this vulnerability. |