| CWE |
Name |
|
Actions |
| CWE-85 |
Doubled Character XSS Manipulations |
|
|
| CWE-849 |
The CERT Oracle Secure Coding Standard for Java (2011) Chapter 6 - Object Orientation (OBJ) |
|
|
| CWE-848 |
The CERT Oracle Secure Coding Standard for Java (2011) Chapter 5 - Numeric Types and Operations (NUM) |
|
|
| CWE-847 |
The CERT Oracle Secure Coding Standard for Java (2011) Chapter 4 - Expressions (EXP) |
|
|
| CWE-846 |
The CERT Oracle Secure Coding Standard for Java (2011) Chapter 3 - Declarations and Initialization (DCL) |
|
|
| CWE-845 |
The CERT Oracle Secure Coding Standard for Java (2011) Chapter 2 - Input Validation and Data Sanitization (IDS) |
|
|
| CWE-843 |
Access of Resource Using Incompatible Type ('Type Confusion') |
|
|
| CWE-842 |
Placement of User into Incorrect Group |
|
|
| CWE-841 |
Improper Enforcement of Behavioral Workflow |
|
|
| CWE-840 |
Business Logic Errors |
|
|
| CWE-84 |
Improper Neutralization of Encoded URI Schemes in a Web Page |
|
|
| CWE-839 |
Numeric Range Comparison Without Minimum Check |
|
|
| CWE-838 |
Inappropriate Encoding for Output Context |
|
|
| CWE-837 |
Improper Enforcement of a Single, Unique Action |
|
|
| CWE-836 |
Use of Password Hash Instead of Password for Authentication |
|
|
| CWE-835 |
Loop with Unreachable Exit Condition ('Infinite Loop') |
|
|
| CWE-834 |
Excessive Iteration |
|
|
| CWE-833 |
Deadlock |
|
|
| CWE-832 |
Unlock of a Resource that is not Locked |
|
|
| CWE-831 |
Signal Handler Function Associated with Multiple Signals |
|
|
| CWE-830 |
Inclusion of Web Functionality from an Untrusted Source |
|
|
| CWE-83 |
Improper Neutralization of Script in Attributes in a Web Page |
|
|
| CWE-829 |
Inclusion of Functionality from Untrusted Control Sphere |
|
|
| CWE-828 |
Signal Handler with Functionality that is not Asynchronous-Safe |
|
|
| CWE-827 |
Improper Control of Document Type Definition |
|
|
| CWE-826 |
Premature Release of Resource During Expected Lifetime |
|
|
| CWE-825 |
Expired Pointer Dereference |
|
|
| CWE-824 |
Access of Uninitialized Pointer |
|
|
| CWE-823 |
Use of Out-of-range Pointer Offset |
|
|
| CWE-822 |
Untrusted Pointer Dereference |
|
|
| CWE-821 |
Incorrect Synchronization |
|
|
| CWE-820 |
Missing Synchronization |
|
|
| CWE-82 |
Improper Neutralization of Script in Attributes of IMG Tags in a Web Page |
|
|
| CWE-819 |
OWASP Top Ten 2010 Category A10 - Unvalidated Redirects and Forwards |
|
|
| CWE-818 |
OWASP Top Ten 2010 Category A9 - Insufficient Transport Layer Protection |
|
|
| CWE-817 |
OWASP Top Ten 2010 Category A8 - Failure to Restrict URL Access |
|
|
| CWE-816 |
OWASP Top Ten 2010 Category A7 - Insecure Cryptographic Storage |
|
|
| CWE-815 |
OWASP Top Ten 2010 Category A6 - Security Misconfiguration |
|
|
| CWE-814 |
OWASP Top Ten 2010 Category A5 - Cross-Site Request Forgery(CSRF) |
|
|
| CWE-813 |
OWASP Top Ten 2010 Category A4 - Insecure Direct Object References |
|
|