| CWE |
Name |
|
Actions |
| CWE-963 |
SFP Secondary Cluster: Exposed Data |
|
|
| CWE-962 |
SFP Secondary Cluster: Unchecked Status Condition |
|
|
| CWE-961 |
SFP Secondary Cluster: Incorrect Exception Behavior |
|
|
| CWE-960 |
SFP Secondary Cluster: Ambiguous Exception Type |
|
|
| CWE-96 |
Improper Neutralization of Directives in Statically Saved Code ('Static Code Injection') |
|
|
| CWE-959 |
SFP Secondary Cluster: Weak Cryptography |
|
|
| CWE-958 |
SFP Secondary Cluster: Broken Cryptography |
|
|
| CWE-957 |
SFP Secondary Cluster: Protocol Error |
|
|
| CWE-956 |
SFP Secondary Cluster: Channel Attack |
|
|
| CWE-955 |
SFP Secondary Cluster: Unrestricted Authentication |
|
|
| CWE-954 |
SFP Secondary Cluster: Multiple Binds to the Same Port |
|
|
| CWE-953 |
SFP Secondary Cluster: Missing Endpoint Authentication |
|
|
| CWE-952 |
SFP Secondary Cluster: Missing Authentication |
|
|
| CWE-951 |
SFP Secondary Cluster: Insecure Authentication Policy |
|
|
| CWE-950 |
SFP Secondary Cluster: Hardcoded Sensitive Data |
|
|
| CWE-95 |
Improper Neutralization of Directives in Dynamically Evaluated Code ('Eval Injection') |
|
|
| CWE-949 |
SFP Secondary Cluster: Faulty Endpoint Authentication |
|
|
| CWE-948 |
SFP Secondary Cluster: Digital Certificate |
|
|
| CWE-947 |
SFP Secondary Cluster: Authentication Bypass |
|
|
| CWE-946 |
SFP Secondary Cluster: Insecure Resource Permissions |
|
|
| CWE-945 |
SFP Secondary Cluster: Insecure Resource Access |
|
|
| CWE-944 |
SFP Secondary Cluster: Access Management |
|
|
| CWE-943 |
Improper Neutralization of Special Elements in Data Query Logic |
|
|
| CWE-942 |
Permissive Cross-domain Policy with Untrusted Domains |
|
|
| CWE-941 |
Incorrectly Specified Destination in a Communication Channel |
|
|
| CWE-940 |
Improper Verification of Source of a Communication Channel |
|
|
| CWE-94 |
Improper Control of Generation of Code ('Code Injection') |
|
|
| CWE-939 |
Improper Authorization in Handler for Custom URL Scheme |
|
|
| CWE-938 |
OWASP Top Ten 2013 Category A10 - Unvalidated Redirects and Forwards |
|
|
| CWE-937 |
OWASP Top Ten 2013 Category A9 - Using Components with Known Vulnerabilities |
|
|
| CWE-936 |
OWASP Top Ten 2013 Category A8 - Cross-Site Request Forgery (CSRF) |
|
|
| CWE-935 |
OWASP Top Ten 2013 Category A7 - Missing Function Level Access Control |
|
|
| CWE-934 |
OWASP Top Ten 2013 Category A6 - Sensitive Data Exposure |
|
|
| CWE-933 |
OWASP Top Ten 2013 Category A5 - Security Misconfiguration |
|
|
| CWE-932 |
OWASP Top Ten 2013 Category A4 - Insecure Direct Object References |
|
|
| CWE-931 |
OWASP Top Ten 2013 Category A3 - Cross-Site Scripting (XSS) |
|
|
| CWE-930 |
OWASP Top Ten 2013 Category A2 - Broken Authentication and Session Management |
|
|
| CWE-93 |
Improper Neutralization of CRLF Sequences ('CRLF Injection') |
|
|
| CWE-929 |
OWASP Top Ten 2013 Category A1 - Injection |
|
|
| CWE-927 |
Use of Implicit Intent for Sensitive Communication |
|
|