| CWE |
Name |
|
Actions |
| CWE-615 |
Inclusion of Sensitive Information in Source Code Comments |
|
|
| CWE-614 |
Sensitive Cookie in HTTPS Session Without 'Secure' Attribute |
|
|
| CWE-613 |
Insufficient Session Expiration |
|
|
| CWE-612 |
Improper Authorization of Index Containing Sensitive Information |
|
|
| CWE-611 |
Improper Restriction of XML External Entity Reference |
|
|
| CWE-610 |
Externally Controlled Reference to a Resource in Another Sphere |
|
|
| CWE-61 |
UNIX Symbolic Link (Symlink) Following |
|
|
| CWE-609 |
Double-Checked Locking |
|
|
| CWE-608 |
Struts: Non-private Field in ActionForm Class |
|
|
| CWE-607 |
Public Static Final Field References Mutable Object |
|
|
| CWE-606 |
Unchecked Input for Loop Condition |
|
|
| CWE-605 |
Multiple Binds to the Same Port |
|
|
| CWE-603 |
Use of Client-Side Authentication |
|
|
| CWE-602 |
Client-Side Enforcement of Server-Side Security |
|
|
| CWE-601 |
URL Redirection to Untrusted Site ('Open Redirect') |
|
|
| CWE-600 |
Uncaught Exception in Servlet |
|
|
| CWE-60 |
DEPRECATED: UNIX Path Link Problems |
|
|
| CWE-6 |
J2EE Misconfiguration: Insufficient Session-ID Length |
|
|
| CWE-599 |
Missing Validation of OpenSSL Certificate |
|
|
| CWE-598 |
Use of GET Request Method With Sensitive Query Strings |
|
|
| CWE-597 |
Use of Wrong Operator in String Comparison |
|
|
| CWE-596 |
DEPRECATED: Incorrect Semantic Object Comparison |
|
|
| CWE-595 |
Comparison of Object References Instead of Object Contents |
|
|
| CWE-594 |
J2EE Framework: Saving Unserializable Objects to Disk |
|
|
| CWE-593 |
Authentication Bypass: OpenSSL CTX Object Modified after SSL Objects are Created |
|
|
| CWE-592 |
DEPRECATED: Authentication Bypass Issues |
|
|
| CWE-591 |
Sensitive Data Storage in Improperly Locked Memory |
|
|
| CWE-590 |
Free of Memory not on the Heap |
|
|
| CWE-59 |
Improper Link Resolution Before File Access ('Link Following') |
|
|
| CWE-589 |
Call to Non-ubiquitous API |
|
|
| CWE-588 |
Attempt to Access Child of a Non-structure Pointer |
|
|
| CWE-587 |
Assignment of a Fixed Address to a Pointer |
|
|
| CWE-586 |
Explicit Call to Finalize() |
|
|
| CWE-585 |
Empty Synchronized Block |
|
|
| CWE-584 |
Return Inside Finally Block |
|
|
| CWE-583 |
finalize() Method Declared Public |
|
|
| CWE-582 |
Array Declared Public, Final, and Static |
|
|
| CWE-581 |
Object Model Violation: Just One of Equals and Hashcode Defined |
|
|
| CWE-580 |
clone() Method Without super.clone() |
|
|
| CWE-58 |
Path Equivalence: Windows 8.3 Filename |
|
|