| CWE |
Name |
|
Actions |
| CWE-812 |
OWASP Top Ten 2010 Category A3 - Broken Authentication and Session Management |
|
|
| CWE-811 |
OWASP Top Ten 2010 Category A2 - Cross-Site Scripting (XSS) |
|
|
| CWE-810 |
OWASP Top Ten 2010 Category A1 - Injection |
|
|
| CWE-81 |
Improper Neutralization of Script in an Error Message Web Page |
|
|
| CWE-808 |
2010 Top 25 - Weaknesses On the Cusp |
|
|
| CWE-807 |
Reliance on Untrusted Inputs in a Security Decision |
|
|
| CWE-806 |
Buffer Access Using Size of Source Buffer |
|
|
| CWE-805 |
Buffer Access with Incorrect Length Value |
|
|
| CWE-804 |
Guessable CAPTCHA |
|
|
| CWE-803 |
2010 Top 25 - Porous Defenses |
|
|
| CWE-802 |
2010 Top 25 - Risky Resource Management |
|
|
| CWE-801 |
2010 Top 25 - Insecure Interaction Between Components |
|
|
| CWE-80 |
Improper Neutralization of Script-Related HTML Tags in a Web Page (Basic XSS) |
|
|
| CWE-8 |
J2EE Misconfiguration: Entity Bean Declared Remote |
|
|
| CWE-799 |
Improper Control of Interaction Frequency |
|
|
| CWE-798 |
Use of Hard-coded Credentials |
|
|
| CWE-797 |
Only Filtering Special Elements at an Absolute Position |
|
|
| CWE-796 |
Only Filtering Special Elements Relative to a Marker |
|
|
| CWE-795 |
Only Filtering Special Elements at a Specified Location |
|
|
| CWE-794 |
Incomplete Filtering of Multiple Instances of Special Elements |
|
|
| CWE-793 |
Only Filtering One Instance of a Special Element |
|
|
| CWE-792 |
Incomplete Filtering of One or More Instances of Special Elements |
|
|
| CWE-791 |
Incomplete Filtering of Special Elements |
|
|
| CWE-790 |
Improper Filtering of Special Elements |
|
|
| CWE-79 |
Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') |
|
|
| CWE-789 |
Memory Allocation with Excessive Size Value |
|
|
| CWE-788 |
Access of Memory Location After End of Buffer |
|
|
| CWE-787 |
Out-of-bounds Write |
|
|
| CWE-786 |
Access of Memory Location Before Start of Buffer |
|
|
| CWE-785 |
Use of Path Manipulation Function without Maximum-sized Buffer |
|
|
| CWE-784 |
Reliance on Cookies without Validation and Integrity Checking in a Security Decision |
|
|
| CWE-783 |
Operator Precedence Logic Error |
|
|
| CWE-782 |
Exposed IOCTL with Insufficient Access Control |
|
|
| CWE-781 |
Improper Address Validation in IOCTL with METHOD_NEITHER I/O Control Code |
|
|
| CWE-780 |
Use of RSA Algorithm without OAEP |
|
|
| CWE-78 |
Improper Neutralization of Special Elements used in an OS Command ('OS Command Injection') |
|
|
| CWE-779 |
Logging of Excessive Data |
|
|
| CWE-778 |
Insufficient Logging |
|
|
| CWE-777 |
Regular Expression without Anchors |
|
|
| CWE-776 |
Improper Restriction of Recursive Entity References in DTDs ('XML Entity Expansion') |
|
|