CWE-115: Misinterpretation of Input
Misinterpretation of Input
Weakness ID: 115 (Weakness Base) Status: Incomplete
Description
Description Summary
The software misinterprets an input, whether from an attacker
or another product, in a security-relevant fashion.
Time of Introduction
Architecture and Design
Implementation
Operation
Observed Examples
Reference Description
CVE-2005-2225 Product sees dangerous file extension in free text
of a group discussion, disconnects all users.
CVE-2001-0003 Product does not correctly import and process
security settings from another product.
Relationships
Nature Type ID Name View(s) this relationship pertains to
ChildOf Weakness Base 436 Interpretation Conflict Development Concepts (primary) 699
Research Concepts (primary) 1000
Research Gaps
This concept needs further study. It is likely a factor in several
weaknesses, possibly resultant as well. Overlaps Multiple Interpretation
Errors (MIE).
Taxonomy Mappings
Mapped Taxonomy Name Node ID Fit Mapped Node Name
PLOVER Misinterpretation Error
Content History
Submissions Submission Date Submitter Organization Source PLOVER Externally Mined Modifications Modification Date Modifier Organization Source 2008-07-01 Eric Dalci Cigital External updated Time of Introduction 2008-09-08 CWE Content Team MITRE Internal updated Relationships,
Taxonomy Mappings 2009-10-29 CWE Content Team MITRE Internal updated Relationships