CWE VIEW: Named Chains

View ID: 709
Structure: Graph
Status: Incomplete
View Objective

This view (graph) displays Named Chains and their components.

709 - Named Chains
+Compound Element: ChainCompound Element: ChainInteger Overflow to Buffer Overflow - (680)
680 (Integer Overflow to Buffer Overflow)
The product performs a calculation to determine how much memory to allocate, but an integer overflow can occur that causes less memory to be allocated than expected, leading to a buffer overflow.
+Compound Element: ChainCompound Element: ChainUnchecked Return Value to NULL Pointer Dereference - (690)
690 (Unchecked Return Value to NULL Pointer Dereference)
The product does not check for an error after calling a function that can return with a NULL pointer if the function fails, which leads to a resultant NULL pointer dereference.
+Compound Element: ChainCompound Element: ChainIncomplete Blacklist to Cross-Site Scripting - (692)
692 (Incomplete Blacklist to Cross-Site Scripting)
The product uses a blacklist-based protection mechanism to defend against XSS attacks, but the blacklist is incomplete, allowing XSS variants to succeed.
