CWE
Home > CWE List > VIEW LIST: CWE-679: Chain Elements (Draft 9)   View the CWE List

VIEW LIST: CWE-679: Chain Elements (Draft 9)

Chain Elements
View ID
Status: Draft

679 (View)

ObjectiveThis view (slice) displays only weakness elements that are part of a chain.
View Data

Filter Used: (.//Relationship_Nature='CanPrecede') or (@*[contains(name(),'ID')] = //Relationship_Target_ID[../Relationship_Nature='CanPrecede'])

CWEs in this viewTotal CWEs
Total43out of695
Views0out of14
Categories1out of64
Weaknesses36out of605
Compound_Elements6out of12
Weakness VariantWeakness Variant Authentication Bypass by Alternate Name - (289)
Category Cleansing, Canonicalization, and Comparison Errors - (171)
Weakness BaseWeakness Base Design Principle Violation: Client-Side Enforcement of Server-Side Security - (602)
Weakness BaseWeakness Base Design Principle Violation: Reliance on Security through Obscurity - (656)
Weakness ClassWeakness Class Detection of Error Condition Without Action - (390)
Weakness VariantWeakness Variant Download of Untrusted Mobile Code Without Integrity Check - (494)
Weakness BaseWeakness Base Error Message Information Leaks - (209)
Weakness BaseWeakness Base External Control of Assumed-Immutable Web Parameter - (472)
Weakness BaseWeakness Base Failure to Catch All Exceptions (Missing Catch Block) - (600)
Weakness VariantWeakness Variant Failure to Handle Alternate Encoding - (173)
Weakness VariantWeakness Variant Failure to Release Memory Before Removing Last Reference (aka 'Memory Leak') - (401)
Weakness BaseWeakness Base Failure to Resolve Case Sensitivity - (178)
Weakness BaseWeakness Base Failure to Sanitize CRLF Sequences (aka 'CRLF Injection') - (93)
Weakness BaseWeakness Base Failure to Sanitize CRLF Sequences in HTTP Headers (aka 'HTTP Response Splitting') - (113)
Weakness BaseWeakness Base Failure to Sanitize Data into an OS Command (aka 'OS Command Injection') - (78)
Weakness BaseWeakness Base Failure to Sanitize Data into SQL Queries (aka 'SQL Injection') - (89)
Weakness BaseWeakness Base Failure to Sanitize Directives in a Web Page (aka 'Cross-site scripting' (XSS)) - (79)
Weakness BaseWeakness Base Hard-Coded Password - (259)
Weakness VariantWeakness Variant Heap-based Buffer Overflow - (122)
Weakness BaseWeakness Base Improper Null Termination - (170)
Weakness BaseWeakness Base Incomplete Blacklist - (184)
Compound Element: Chain Incomplete Blacklist to Cross-Site Scripting - (692)
Weakness BaseWeakness Base Incorrect Output Sanitization for Logs - (117)
Compound Element: Composite Insufficient Control of Filename for Include/Require Statement in PHP Program (aka 'PHP File Inclusion') - (98)
Weakness BaseWeakness Base Integer Overflow (Wrap or Wraparound) - (190)
Compound Element: Chain Integer Overflow to Buffer Overflow - (680)
Weakness BaseWeakness Base Missing Initialization - (456)
Weakness BaseWeakness Base Modification of Assumed-Immutable Data (MAID) - (471)
Weakness BaseWeakness Base NULL Pointer Dereference - (476)
Weakness BaseWeakness Base Off-by-one Error - (193)
Weakness VariantWeakness Variant Path Equivalence: '/multiple/trailing/slash//' - (52)
Weakness VariantWeakness Variant Path Equivalence: 'filename ' (Trailing Space) - (46)
Weakness VariantWeakness Variant PHP External Variable Modification - (473)
Weakness VariantWeakness Variant Reachable Assertion - (617)
Weakness VariantWeakness Variant Signed to Unsigned Conversion Error - (195)
Compound Element: Composite Unbounded Transfer ('Classic Buffer Overflow') - (120)
Weakness BaseWeakness Base Unchecked Return Value - (252)
Compound Element: Chain Unchecked Return Value to NULL Pointer Dereference - (690)
Weakness VariantWeakness Variant Unparsed Raw Web Content Delivery - (433)
Compound Element: Composite Unrestricted File Upload - (434)
Weakness BaseWeakness Base Use After Free - (416)
Weakness BaseWeakness Base Use of Hard-coded Cryptographic Key - (321)
Weakness BaseWeakness Base Write-what-where Condition - (123)
Page Last Updated: April 11, 2008