CWE
Home > CWE List > VIEW LIST: CWE-2000: Comprehensive CWE Dictionary (Draft 9)   View the CWE List

VIEW LIST: CWE-2000: Comprehensive CWE Dictionary (Draft 9)

Comprehensive CWE Dictionary
View ID
Status: Draft

2000 (View)

ObjectiveThis view (slice) covers all the elements in CWE.
View Data

Filter Used: true()

CWEs in this viewTotal CWEs
Total695out of695
Views14out of14
Categories64out of64
Weaknesses605out of605
Compound_Elements12out of12
Weakness BaseWeakness BaseWeakness Base Absolute Path Traversal - (36)
Weakness BaseWeakness BaseWeakness Base Acceptance of Extraneous Untrusted Data With Trusted Data - (349)
Weakness VariantWeakness VariantWeakness Variant Access Control Bypass Through User-Controlled Key - (639)
Weakness VariantWeakness VariantWeakness Variant Access Control Bypass Through User-Controlled SQL Primary Key - (566)
Weakness ClassWeakness ClassWeakness Class Access Control Issues - (284)
Weakness BaseWeakness BaseWeakness Base Addition of Data Structure Sentinel - (464)
Weakness BaseWeakness BaseWeakness Base Algorithmic Complexity - (407)
Weakness VariantWeakness VariantWeakness Variant Alternate XSS Syntax - (87)
Weakness ClassWeakness ClassWeakness Class Always-Incorrect Control Flow Implementation - (670)
Weakness VariantWeakness VariantWeakness Variant Apple '.DS_Store' - (71)
Weakness VariantWeakness VariantWeakness Variant Apple HFS+ Alternate Data Stream - (72)
Weakness BaseWeakness BaseWeakness Base Argument Injection or Modification - (88)
Weakness VariantWeakness VariantWeakness Variant Array Declared Public, Final, and Static - (582)
CategoryCategory ASP.NET Environment Issues - (10)
Weakness VariantWeakness VariantWeakness Variant ASP.NET Misconfiguration: Creating Debug Binary - (11)
Weakness VariantWeakness VariantWeakness Variant ASP.NET Misconfiguration: Missing Custom Error Handling - (12)
Weakness ClassWeakness ClassWeakness Class ASP.NET Misconfiguration: Not Using Input Validation Framework - (554)
Weakness VariantWeakness VariantWeakness Variant ASP.NET Misconfiguration: Password in Configuration File - (13)
Weakness VariantWeakness VariantWeakness Variant ASP.NET Misconfiguration: Use of Identity Impersonation - (556)
Weakness VariantWeakness VariantWeakness Variant Assigning instead of Comparing - (481)
Weakness BaseWeakness BaseWeakness Base Assignment of a Fixed Address to a Pointer - (587)
Weakness ClassWeakness ClassWeakness Class Asymmetric Resource Consumption (Amplification) - (405)
Weakness VariantWeakness VariantWeakness Variant Attempt to Access Child of a Non-structure Pointer - (588)
Weakness VariantWeakness VariantWeakness Variant Authentication Bypass by Alternate Name - (289)
Weakness VariantWeakness VariantWeakness Variant Authentication Bypass by Alternate Path/Channel - (288)
Weakness VariantWeakness VariantWeakness Variant Authentication Bypass by Assumed-Immutable Data - (302)
Weakness BaseWeakness BaseWeakness Base Authentication Bypass by Capture-replay - (294)
Weakness BaseWeakness BaseWeakness Base Authentication Bypass by Primary Weakness - (305)
Weakness BaseWeakness BaseWeakness Base Authentication Bypass by Spoofing - (290)
Weakness ClassWeakness ClassWeakness Class Authentication Bypass Issues - (592)
Weakness VariantWeakness VariantWeakness Variant Authentication Bypass: OpenSSL CTX Object Modified after SSL Objects are Created - (593)
Weakness BaseWeakness BaseWeakness Base Behavioral Change in New Version or Environment - (439)
Weakness BaseWeakness BaseWeakness Base Behavioral Discrepancy Information Leak - (205)
CategoryCategory Behavioral Problems - (438)
Weakness BaseWeakness BaseWeakness Base Boundary Beginning Violation ('Buffer Underwrite') - (124)
Weakness VariantWeakness VariantWeakness Variant Buffer Over-read - (126)
Weakness VariantWeakness VariantWeakness Variant Buffer Under-read - (127)
CategoryCategory Byte/Object Code - (503)
Weakness VariantWeakness VariantWeakness Variant Call to Non-ubiquitous API - (589)
Weakness VariantWeakness VariantWeakness Variant Call to Thread run() instead of start() - (572)
CategoryCategory Certificate Issues - (295)
ViewView Chain Elements - (679)
Weakness ClassWeakness ClassWeakness Class Channel Accessible by Non-Endpoint (aka 'Man-in-the-Middle') - (300)
CategoryCategory Channel and Path Errors - (417)
CategoryCategory Channel Errors - (418)
CategoryCategory Cleansing, Canonicalization, and Comparison Errors - (171)
Weakness VariantWeakness VariantWeakness Variant clone() Method Without super.clone() - (580)
CategoryCategory Code - (17)
Weakness ClassWeakness ClassWeakness Class Code Injection - (94)
Weakness BaseWeakness BaseWeakness Base Collapse of Data Into Unsafe Value - (182)
Weakness VariantWeakness VariantWeakness Variant Command Shell in Externally Accessible Directory - (553)
Weakness VariantWeakness VariantWeakness Variant Comparing instead of Assigning - (482)
Weakness VariantWeakness VariantWeakness Variant Comparison of Classes by Name - (486)
Weakness BaseWeakness BaseWeakness Base Compiler Removal of Code to Clear Buffers - (14)
ViewView Composites - (678)
ViewView Comprehensive CWE Dictionary - (2000)
CategoryCategory Concurrency Issues - (557)
CategoryCategory Configuration - (16)
Weakness ClassWeakness ClassWeakness Class Containment Errors (Container Errors) - (216)
Weakness BaseWeakness BaseWeakness Base Context Switching Race Condition - (368)
Weakness ClassWeakness ClassWeakness Class Covert Channel - (514)
Weakness BaseWeakness BaseWeakness Base Covert Storage Channel - (515)
Weakness BaseWeakness BaseWeakness Base Covert Timing Channel - (385)
Weakness BaseWeakness BaseWeakness Base Creation of Temporary File in Directory with Insecure Permissions - (379)
Weakness BaseWeakness BaseWeakness Base Creation of Temporary File With Insecure Permissions - (378)
CategoryCategory Credentials Management - (255)
Weakness VariantWeakness VariantWeakness Variant Critical Public Variable Without Final Modifier - (493)
Weakness BaseWeakness BaseWeakness Base Cross-boundary Cleansing Information Leak - (212)
Compound Element: CompositeCompound Element: Composite Cross-Site Request Forgery (CSRF) - (352)
CategoryCategory Cryptographic Issues - (310)
Weakness BaseWeakness BaseWeakness Base Custom Special Character Injection - (92)
Weakness BaseWeakness BaseWeakness Base Dangerous Handler not Disabled During Sensitive Operations - (432)
Weakness BaseWeakness BaseWeakness Base Dangling Database Cursor (aka 'Cursor Injection') - (619)
CategoryCategory Data Handling - (19)
Weakness VariantWeakness VariantWeakness Variant Data Leak Between Sessions - (488)
CategoryCategory Data Structure Issues - (461)
Weakness VariantWeakness VariantWeakness Variant Dead Code - (561)
Weakness BaseWeakness BaseWeakness Base Declaration of Catch for Generic Exception - (396)
Weakness BaseWeakness BaseWeakness Base Declaration of Throws for Generic Exception - (397)
Weakness BaseWeakness BaseWeakness Base Deletion of Data Structure Sentinel - (463)
Weakness BaseWeakness BaseWeakness Base Deployment of Wrong Handler - (430)
ViewView Deprecated - (604)
DeprecatedDeprecated DEPRECATED (Duplicate): Covert Timing Channel - (516)
DeprecatedDeprecated DEPRECATED (Duplicate): General Information Management Problems - (225)
DeprecatedDeprecated DEPRECATED (Duplicate): HTTP response splitting - (443)
DeprecatedDeprecated DEPRECATED: Incorrect Initialization - (458)
Weakness VariantWeakness VariantWeakness Variant Deserialization of Untrusted Data - (502)
Weakness BaseWeakness BaseWeakness Base Design Principle Violation: Client-Side Enforcement of Server-Side Security - (602)
Weakness BaseWeakness BaseWeakness Base Design Principle Violation: Failure to Satisfy Psychological Acceptability - (655)
Weakness ClassWeakness ClassWeakness Class Design Principle Violation: Failure to Use Least Privilege - (250)
Weakness BaseWeakness BaseWeakness Base Design Principle Violation: Insufficient Compartmentalization - (653)
Weakness ClassWeakness ClassWeakness Class Design Principle Violation: Lack of Administrator Control over Security - (671)
Weakness ClassWeakness ClassWeakness Class Design Principle Violation: Not Failing Securely - (636)
Weakness ClassWeakness ClassWeakness Class Design Principle Violation: Not Using Complete Mediation - (638)
Weakness ClassWeakness ClassWeakness Class Design Principle Violation: Not Using Economy of Mechanism - (637)
Weakness BaseWeakness BaseWeakness Base Design Principle Violation: Reliance on a Single Factor in a Security Decision - (654)
Weakness BaseWeakness BaseWeakness Base Design Principle Violation: Reliance on Security through Obscurity - (656)
Weakness ClassWeakness ClassWeakness Class Detection of Error Condition Without Action - (390)
Weakness BaseWeakness BaseWeakness Base Direct Request ('Forced Browsing') - (425)
Weakness BaseWeakness BaseWeakness Base Direct Use of Unsafe JNI - (111)
Weakness ClassWeakness ClassWeakness Class Discrepancy Information Leaks - (203)
Weakness BaseWeakness BaseWeakness Base Divide By Zero - (369)
Weakness VariantWeakness VariantWeakness Variant Double Decoding of the Same Data - (174)
Weakness VariantWeakness VariantWeakness Variant Double Free - (415)
Weakness BaseWeakness BaseWeakness Base Double-Checked Locking - (609)
Weakness VariantWeakness VariantWeakness Variant Doubled Character XSS Manipulations - (85)
Weakness VariantWeakness VariantWeakness Variant Download of Untrusted Mobile Code Without Integrity Check - (494)
Weakness BaseWeakness BaseWeakness Base Duplicate Key in Associative List (Alist) - (462)
Weakness ClassWeakness ClassWeakness Class Duplicate Operations on Resource - (675)
Weakness BaseWeakness BaseWeakness Base Dynamic Variable Evaluation - (627)
Weakness VariantWeakness VariantWeakness Variant EJB Bad Practices: Use of AWT Swing - (575)
Weakness VariantWeakness VariantWeakness Variant EJB Bad Practices: Use of Class Loader - (578)
Weakness VariantWeakness VariantWeakness Variant EJB Bad Practices: Use of Java I/O - (576)
Weakness VariantWeakness VariantWeakness Variant EJB Bad Practices: Use of Sockets - (577)
Weakness VariantWeakness VariantWeakness Variant EJB Bad Practices: Use of Synchronization Primitives - (574)
Weakness ClassWeakness ClassWeakness Class Element Problems - (237)
Weakness ClassWeakness ClassWeakness Class Embedded Malicious Code - (506)
Weakness VariantWeakness VariantWeakness Variant Empty Password in Configuration File - (258)
Weakness VariantWeakness VariantWeakness Variant Empty Synchronized Block - (585)
Weakness ClassWeakness ClassWeakness Class Encoding Error - (172)
CategoryCategory Environment - (2)
CategoryCategory Error Conditions, Return Values, Status Codes - (389)
CategoryCategory Error Handling - (388)
Weakness BaseWeakness BaseWeakness Base Error Message Information Leaks - (209)
Weakness BaseWeakness BaseWeakness Base Executable Regular Expression Error - (624)
Weakness BaseWeakness BaseWeakness Base Expected Behavior Violation - (440)
Weakness VariantWeakness VariantWeakness Variant Explicit Call to Finalize - (586)
Weakness VariantWeakness VariantWeakness Variant Exposed Unsafe ActiveX Method - (618)
Weakness ClassWeakness ClassWeakness Class Exposure of Resource to Wrong Sphere - (668)
Weakness VariantWeakness VariantWeakness Variant Expression is Always False - (570)
Weakness VariantWeakness VariantWeakness Variant Expression is Always True - (571)
CategoryCategory Expression Issues - (569)
Weakness VariantWeakness VariantWeakness Variant External Behavioral Inconsistency Information Leak - (207)
Weakness BaseWeakness BaseWeakness Base External Control of Assumed-Immutable Web Parameter - (472)
Weakness ClassWeakness ClassWeakness Class External Control of File Name or Path - (73)
Weakness BaseWeakness BaseWeakness Base External Control of System or Configuration Setting - (15)
Weakness BaseWeakness BaseWeakness Base External Control of User State Data - (642)
Weakness ClassWeakness ClassWeakness Class External Influence of Sphere Definition - (673)
Weakness BaseWeakness BaseWeakness Base External Initialization of Trusted Variables - (454)
Weakness ClassWeakness ClassWeakness Class Externally Controlled Reference to a Resource in Another Sphere - (610)
Weakness BaseWeakness BaseWeakness Base Failure to Add Integrity Check Value - (353)
Weakness BaseWeakness BaseWeakness Base Failure to Catch All Exceptions (Missing Catch Block) - (600)
Weakness VariantWeakness VariantWeakness Variant Failure to Change Working Directory in chroot Jail - (243)
Weakness BaseWeakness BaseWeakness Base Failure to Check for Certificate Revocation - (299)
Weakness BaseWeakness BaseWeakness Base Failure to Check Integrity Check Value - (354)
Weakness BaseWeakness BaseWeakness Base Failure to Check Whether Privileges Were Dropped Successfully - (273)
Weakness VariantWeakness VariantWeakness Variant Failure to Clear Heap Memory Before Release - (244)
Weakness ClassWeakness ClassWeakness Class Failure to Constrain Operations within the Bounds of an Allocated Memory Buffer - (119)
Weakness BaseWeakness BaseWeakness Base Failure to Encrypt Sensitive Data - (311)
Weakness BaseWeakness BaseWeakness Base Failure to Follow Chain of Trust in Certificate Validation - (296)
Weakness ClassWeakness ClassWeakness Class Failure to Follow Specification - (573)
Weakness ClassWeakness ClassWeakness Class Failure to Fulfill API Contract (aka 'API Abuse') - (227)
Weakness BaseWeakness BaseWeakness Base Failure to Handle Additional Special Element - (167)
Weakness VariantWeakness VariantWeakness Variant Failure to Handle Alternate Encoding - (173)
Weakness BaseWeakness BaseWeakness Base Failure to Handle Extra Parameter - (235)
Weakness BaseWeakness BaseWeakness Base Failure to Handle Extra Value - (231)
Weakness ClassWeakness ClassWeakness Class Failure to Handle File Names that Identify Virtual Resources - (66)
Weakness BaseWeakness BaseWeakness Base Failure to Handle Highly Compressed Data (Data Amplification) - (409)
Weakness BaseWeakness BaseWeakness Base Failure to Handle Incomplete Element - (239)
Weakness VariantWeakness VariantWeakness Variant Failure to Handle Insufficient Entropy in TRNG - (333)
Weakness BaseWeakness BaseWeakness Base Failure to Handle Insufficient Permissions or Privileges - (280)
Weakness BaseWeakness BaseWeakness Base Failure to Handle Insufficient Privileges - (274)
Weakness BaseWeakness BaseWeakness Base Failure to Handle Missing Element - (238)
Weakness BaseWeakness BaseWeakness Base Failure to Handle Missing Parameter - (234)
Weakness BaseWeakness BaseWeakness Base Failure to Handle Missing Special Element - (166)
Weakness BaseWeakness BaseWeakness Base Failure to Handle Missing Value - (230)
Weakness VariantWeakness VariantWeakness Variant Failure to Handle Mixed Encoding - (175)
Weakness BaseWeakness BaseWeakness Base Failure to Handle Undefined Parameter - (236)
Weakness BaseWeakness BaseWeakness Base Failure to Handle Undefined Value - (232)
Weakness VariantWeakness VariantWeakness Variant Failure to Handle Unicode Encoding - (176)
Weakness VariantWeakness VariantWeakness Variant Failure to Handle URL Encoding (Hex Encoding) - (177)
Weakness VariantWeakness VariantWeakness Variant Failure to Handle Windows ::DATA Alternate Data Stream - (69)
Weakness VariantWeakness VariantWeakness Variant Failure to Handle Windows Device Names - (67)
Weakness BaseWeakness BaseWeakness Base Failure to Handle Wrong Data Type - (241)
Weakness ClassWeakness ClassWeakness Class Failure to Protect Alternate Path - (424)
Weakness BaseWeakness BaseWeakness Base Failure to Protect Stored Data from Modification - (217)
Weakness BaseWeakness BaseWeakness Base Failure to Provide Confidentiality for Stored Data - (218)
Weakness BaseWeakness BaseWeakness Base Failure to Provide Specified Functionality - (684)
Weakness BaseWeakness BaseWeakness Base Failure to Release Memory Before Removing Last Reference (aka 'Memory Leak') - (401)
Weakness BaseWeakness BaseWeakness Base Failure to Report Error in Status Code - (392)
Weakness BaseWeakness BaseWeakness Base Failure to Resolve Case Sensitivity - (178)
Weakness VariantWeakness VariantWeakness Variant Failure to Resolve Encoded URI Schemes in a Web Page - (84)
Weakness BaseWeakness BaseWeakness Base Failure to Resolve Equivalent Special Elements into a Different Plane - (76)
Weakness BaseWeakness BaseWeakness Base Failure to Resolve Inconsistent Elements - (240)
Weakness BaseWeakness BaseWeakness Base Failure to Resolve Inconsistent Special Elements - (168)
Weakness BaseWeakness BaseWeakness Base Failure to Resolve Links Before File Access (aka 'Link Following') - (59)
Weakness ClassWeakness ClassWeakness Class Failure to Resolve Path Equivalence - (41)
Weakness BaseWeakness BaseWeakness Base Failure to Restrict Excessive Authentication Attempts - (307)
Weakness VariantWeakness VariantWeakness Variant Failure to Sanitize Comment Element - (151)
Weakness BaseWeakness BaseWeakness Base Failure to Sanitize CRLF Sequences (aka 'CRLF Injection') - (93)
Weakness BaseWeakness BaseWeakness Base Failure to Sanitize CRLF Sequences in HTTP Headers (aka 'HTTP Response Splitting') - (113)
Weakness ClassWeakness ClassWeakness Class Failure to Sanitize Data into a Control Plane (aka 'Command Injection') - (77)
Weakness ClassWeakness ClassWeakness Class Failure to Sanitize Data into a Different Plane (aka 'Injection') - (74)
Weakness BaseWeakness BaseWeakness Base Failure to Sanitize Data into an OS Command (aka 'OS Command Injection') - (78)
Weakness BaseWeakness BaseWeakness Base Failure to Sanitize Data into LDAP Queries (aka 'LDAP Injection') - (90)
Weakness BaseWeakness BaseWeakness Base Failure to Sanitize Data into SQL Queries (aka 'SQL Injection') - (89)
Weakness BaseWeakness BaseWeakness Base Failure to Sanitize Delimiters - (140)
Weakness BaseWeakness BaseWeakness Base Failure to Sanitize Directives in a Web Page (aka 'Cross-site scripting' (XSS)) - (79)
Weakness VariantWeakness VariantWeakness Variant Failure to Sanitize Directives in an Error Message Web Page - (81)
Weakness VariantWeakness VariantWeakness Variant Failure to Sanitize Escape, Meta, or Control Sequences - (150)
Weakness VariantWeakness VariantWeakness Variant Failure to Sanitize Expression/Command Delimiters - (146)
Weakness VariantWeakness VariantWeakness Variant Failure to Sanitize Input Leaders - (148)
Weakness VariantWeakness VariantWeakness Variant Failure to Sanitize Input Terminators - (147)
Weakness VariantWeakness VariantWeakness Variant Failure to Sanitize Internal Special Element - (164)
Weakness VariantWeakness VariantWeakness Variant Failure to Sanitize Leading Special Element - (160)
Weakness VariantWeakness VariantWeakness Variant Failure to Sanitize Line Delimiters - (144)
Weakness VariantWeakness VariantWeakness Variant Failure to Sanitize Macro Symbol - (152)
Weakness VariantWeakness VariantWeakness Variant Failure to Sanitize Multiple Internal Special Elements - (165)
Weakness VariantWeakness VariantWeakness Variant Failure to Sanitize Multiple Leading Special Elements - (161)
Weakness VariantWeakness VariantWeakness Variant Failure to Sanitize Multiple Trailing Special Elements - (163)
Weakness VariantWeakness VariantWeakness Variant Failure to Sanitize Null Byte or NUL Character - (158)
Weakness VariantWeakness VariantWeakness Variant Failure to Sanitize Paired Delimiters - (157)
Weakness VariantWeakness VariantWeakness Variant Failure to Sanitize Parameter/Argument Delimiters - (141)
Weakness VariantWeakness VariantWeakness Variant Failure to Sanitize Quoting Syntax - (149)
Weakness VariantWeakness VariantWeakness Variant Failure to Sanitize Record Delimiters - (143)
Weakness VariantWeakness VariantWeakness Variant Failure to Sanitize Script in Attributes in a Web Page - (83)
Weakness VariantWeakness VariantWeakness Variant Failure to Sanitize Script in Attributes of IMG Tags in a Web Page - (82)
Weakness VariantWeakness VariantWeakness Variant Failure to Sanitize Script-Related HTML Tags in a Web Page (Basic XSS) - (80)
Weakness VariantWeakness VariantWeakness Variant Failure to Sanitize Section Delimiters - (145)
Weakness BaseWeakness BaseWeakness Base Failure to Sanitize Server-Side Includes (SSI) Within a Web Page - (97)
Weakness ClassWeakness ClassWeakness Class Failure to Sanitize Special Element - (159)
Weakness ClassWeakness ClassWeakness Class Failure to Sanitize Special Elements - (138)
Weakness ClassWeakness ClassWeakness Class Failure to Sanitize Special Elements into a Different Plane (Special Element Injection) - (75)
Weakness VariantWeakness VariantWeakness Variant Failure to Sanitize Substitution Character - (153)
Weakness VariantWeakness VariantWeakness Variant Failure to Sanitize Trailing Special Element - (162)
Weakness VariantWeakness VariantWeakness Variant Failure to Sanitize Value Delimiters - (142)
Weakness VariantWeakness VariantWeakness Variant Failure to Sanitize Variable Name Delimiter - (154)
Weakness VariantWeakness VariantWeakness Variant Failure to Sanitize Whitespace - (156)
Weakness VariantWeakness VariantWeakness Variant Failure to Sanitize Wildcard or Matching Symbol - (155)
Weakness VariantWeakness VariantWeakness Variant Failure to Use Default Case in Switch - (478)
Weakness BaseWeakness BaseWeakness Base Failure to Validate Certificate Expiration - (298)
Weakness BaseWeakness BaseWeakness Base Failure to Validate Host-specific Certificate Data - (297)
Weakness ClassWeakness ClassWeakness Class File and Directory Information Leaks - (538)
Weakness BaseWeakness BaseWeakness Base Files or Directories Accessible to External Parties - (552)
Weakness VariantWeakness VariantWeakness Variant finalize() Method Declared Public - (583)
Weakness VariantWeakness VariantWeakness Variant finalize() Method Without super.finalize() - (568)
Weakness VariantWeakness VariantWeakness Variant Free of Invalid Pointer Not on the Heap - (590)
Weakness VariantWeakness VariantWeakness Variant Function Call With Incorrect Argument Type - (686)
Weakness VariantWeakness VariantWeakness Variant Function Call With Incorrect Number of Arguments - (685)
Weakness VariantWeakness VariantWeakness Variant Function Call With Incorrect Order of Arguments - (683)
Weakness VariantWeakness VariantWeakness Variant Function Call With Incorrect Variable or Reference as Argument - (688)
Weakness VariantWeakness VariantWeakness Variant Function Call With Incorrectly Specified Argument Value - (687)
Weakness BaseWeakness BaseWeakness Base Function Call with Incorrectly Specified Arguments - (628)
CategoryCategory General Special Element Problems - (139)
CategoryCategory Handler Errors - (429)
Weakness BaseWeakness BaseWeakness Base Hard-Coded Password - (259)
Weakness VariantWeakness VariantWeakness Variant Heap-based Buffer Overflow - (122)
Weakness VariantWeakness VariantWeakness Variant Improper Cleanup on Thrown Exception - (460)
Weakness ClassWeakness ClassWeakness Class Improper Handling of Values - (229)
Weakness BaseWeakness BaseWeakness Base Improper Implementation of Authentication Algorithm - (303)
Weakness BaseWeakness BaseWeakness Base Improper Null Termination - (170)
Weakness ClassWeakness ClassWeakness Class Improper Ownership Management - (282)
Weakness BaseWeakness BaseWeakness Base Improper Resource Shutdown or Release - (404)
Weakness BaseWeakness BaseWeakness Base Improper Use of Privileged APIs - (648)
Weakness BaseWeakness BaseWeakness Base Improperly Implemented Security Check for Standard - (358)
Weakness BaseWeakness BaseWeakness Base Improperly Trusted Reverse DNS - (350)
Weakness BaseWeakness BaseWeakness Base Improperly Verified Signature - (347)
CategoryCategory Inadvertently Introduced Weakness - (518)
Weakness BaseWeakness BaseWeakness Base Incomplete Blacklist - (184)
Compound Element: ChainCompound Element: Chain Incomplete Blacklist to Cross-Site Scripting - (692)
Weakness BaseWeakness BaseWeakness Base Incomplete Cleanup - (459)
Weakness VariantWeakness VariantWeakness Variant Incomplete Identification of Uploaded File Variables (PHP) - (616)
Weakness BaseWeakness BaseWeakness Base Incomplete Internal State Distinction - (372)
Weakness BaseWeakness BaseWeakness Base Incomplete Model of Endpoint Features - (437)
Weakness VariantWeakness VariantWeakness Variant Incorrect Behavior Order: Authorization Before Parsing and Canonicalization - (551)
Weakness BaseWeakness BaseWeakness Base Incorrect Behavior Order: Early Amplification - (408)
Weakness BaseWeakness BaseWeakness Base Incorrect Behavior Order: Early Validation - (179)
Weakness VariantWeakness VariantWeakness Variant Incorrect Behavior Order: Validate Before Canonicalize - (180)
Weakness VariantWeakness VariantWeakness Variant Incorrect Behavior Order: Validate Before Filter - (181)
Weakness VariantWeakness VariantWeakness Variant Incorrect Block Delimitation - (483)
Weakness BaseWeakness BaseWeakness Base Incorrect Calculation - (682)
Weakness ClassWeakness ClassWeakness Class Incorrect Calculation of Buffer Size - (131)
Weakness BaseWeakness BaseWeakness Base Incorrect Calculation of Multi-Byte String Length - (135)
Weakness BaseWeakness BaseWeakness Base Incorrect Conversion between Numeric Types - (681)
Weakness BaseWeakness BaseWeakness Base Incorrect or Incomplete Initialization - (665)
Weakness ClassWeakness ClassWeakness Class Incorrect Output Sanitization - (116)
Weakness BaseWeakness BaseWeakness Base Incorrect Output Sanitization for Logs - (117)
Weakness BaseWeakness BaseWeakness Base Incorrect Pointer Scaling - (468)
Weakness BaseWeakness BaseWeakness Base Incorrect Privilege Assignment - (266)
Weakness ClassWeakness ClassWeakness Class Incorrect Resource Transfer Between Spheres - (669)
Weakness BaseWeakness BaseWeakness Base Incorrect Semantic Object Comparison - (596)
Weakness BaseWeakness BaseWeakness Base Incorrect Sign Extension - (194)
Weakness BaseWeakness BaseWeakness Base Incorrect Syntactic Object Comparison - (595)
Weakness ClassWeakness ClassWeakness Class Indicator of Poor Code Quality - (398)
Weakness ClassWeakness ClassWeakness Class Information Leak (Information Disclosure) - (200)
Weakness BaseWeakness BaseWeakness Base Information Leak of System Data - (497)
Weakness VariantWeakness VariantWeakness Variant Information Leak Through Access Control List Files - (529)
Weakness VariantWeakness VariantWeakness Variant Information Leak Through Backup (.~bk) Files - (530)
Weakness VariantWeakness VariantWeakness Variant Information Leak Through Browser Caching - (525)
Weakness VariantWeakness VariantWeakness Variant Information Leak Through Caching - (524)
Weakness VariantWeakness VariantWeakness Variant Information Leak through Class Cloning - (498)
Weakness VariantWeakness VariantWeakness Variant Information Leak Through Cleanup Log Files - (542)
Weakness VariantWeakness VariantWeakness Variant Information Leak Through Comments - (615)
Weakness VariantWeakness VariantWeakness Variant Information Leak Through Core Dump Files - (528)
Weakness VariantWeakness VariantWeakness Variant Information Leak Through CVS Repository - (527)
Weakness VariantWeakness VariantWeakness Variant Information Leak Through Debug Information - (215)
Weakness VariantWeakness VariantWeakness Variant Information Leak Through Debug Log Files - (534)
Weakness VariantWeakness VariantWeakness Variant Information Leak Through Directory Listing - (548)
Weakness VariantWeakness VariantWeakness Variant Information Leak Through Environmental Variables - (526)
Weakness VariantWeakness VariantWeakness Variant Information Leak Through Include Source Code - (541)
Weakness VariantWeakness VariantWeakness Variant Information Leak Through Indexing of Private Data - (612)
Weakness VariantWeakness VariantWeakness Variant Information Leak Through Java Runtime Error Message - (537)
Weakness VariantWeakness VariantWeakness Variant Information Leak Through Log Files - (532)
Weakness VariantWeakness VariantWeakness Variant Information Leak Through Persistent Cookies - (539)
Weakness VariantWeakness VariantWeakness Variant Information Leak Through Query Strings in GET Request - (598)
Weakness VariantWeakness VariantWeakness Variant Information Leak Through Sent Data - (201)
Weakness VariantWeakness VariantWeakness Variant Information Leak Through Server Error Message - (550)
Weakness VariantWeakness VariantWeakness Variant Information Leak Through Server Log Files - (533)
Weakness VariantWeakness VariantWeakness Variant Information Leak Through Servlet Runtime Error Message - (536)
Weakness VariantWeakness VariantWeakness Variant Information Leak Through Shell Error Message - (535)
Weakness VariantWeakness VariantWeakness Variant Information Leak Through Source Code - (540)
Weakness VariantWeakness VariantWeakness Variant Information Leak Through Test Code - (531)
Weakness VariantWeakness VariantWeakness Variant Information Leak through WSDL File - (651)
Weakness VariantWeakness VariantWeakness Variant Information Leak Through XML External Entity File Disclosure - (611)
Weakness ClassWeakness ClassWeakness Class Information Loss or Omission - (221)
CategoryCategory Information Management Errors - (199)
CategoryCategory Initialization and Cleanup Errors - (452)
Weakness VariantWeakness VariantWeakness Variant Insecure Default Permissions - (276)
Weakness BaseWeakness BaseWeakness Base Insecure Default Variable Initialization - (453)
Weakness VariantWeakness VariantWeakness Variant Insecure Execution-assigned Permissions - (279)
Weakness VariantWeakness VariantWeakness Variant Insecure Inherited Permissions - (277)
Weakness VariantWeakness VariantWeakness Variant Insecure Preserved Inherited Permissions - (278)
Weakness BaseWeakness BaseWeakness Base Insecure Temporary File - (377)
Weakness ClassWeakness ClassWeakness Class Insufficient Authentication - (287)
Weakness ClassWeakness ClassWeakness Class Insufficient Control Flow Management - (691)
Weakness BaseWeakness BaseWeakness Base Insufficient Control of a Resource Through its Lifetime - (664)
Weakness BaseWeakness BaseWeakness Base Insufficient Control of Directives in Dynamically Evaluated Code (aka 'Eval Injection') - (95)
Weakness BaseWeakness BaseWeakness Base Insufficient Control of Directives in Statically Saved Code (Static Code Injection) - (96)
Compound Element: CompositeCompound Element: Composite Insufficient Control of Filename for Include/Require Statement in PHP Program (aka 'PHP File Inclusion') - (98)
Weakness BaseWeakness BaseWeakness Base Insufficient Control of Resource Identifiers (aka 'Resource Injection') - (99)
Weakness ClassWeakness ClassWeakness Class Insufficient Encapsulation - (485)
Weakness BaseWeakness BaseWeakness Base Insufficient Entropy - (331)
Weakness VariantWeakness VariantWeakness Variant Insufficient Entropy in PRNG - (332)
Weakness VariantWeakness VariantWeakness Variant Insufficient Filtering of File and Other Resource Names for Executable Content - (641)
Weakness VariantWeakness VariantWeakness Variant Insufficient Filtering of HTTP Headers for Scripting Syntax - (644)
Weakness ClassWeakness ClassWeakness Class Insufficient Input Validation - (20)
Weakness BaseWeakness BaseWeakness Base Insufficient Locking - (667)
Weakness BaseWeakness BaseWeakness Base Insufficient Resource Locking - (413)
Weakness BaseWeakness BaseWeakness Base Insufficient Resource Pool - (410)