CWE 弱点
CWE 基础字段与弱点分类查询。
| CWE ID | 名称 | 抽象级别 | 结构 | 状态 | 操作 |
|---|---|---|---|---|---|
| CWE-1287 | Improper Validation of Specified Type of Input | Base | Simple | Incomplete | |
| CWE-1288 | Improper Validation of Consistency within Input | Base | Simple | Incomplete | |
| CWE-1289 | Improper Validation of Unsafe Equivalence in Input | Base | Simple | Incomplete | |
| CWE-129 | Improper Validation of Array Index | Variant | Simple | Draft | |
| CWE-1290 | Incorrect Decoding of Security Identifiers | Base | Simple | Incomplete | |
| CWE-1291 | Public Key Re-Use for Signing both Debug and Production Code | Base | Simple | Draft | |
| CWE-1292 | Incorrect Conversion of Security Identifiers | Base | Simple | Draft | |
| CWE-1293 | Missing Source Correlation of Multiple Independent Data | Base | Simple | Draft | |
| CWE-1294 | Insecure Security Identifier Mechanism | Class | Simple | Incomplete | |
| CWE-1295 | Debug Messages Revealing Unnecessary Information | Base | Simple | Incomplete | |
| CWE-1296 | Incorrect Chaining or Granularity of Debug Components | Base | Simple | Incomplete | |
| CWE-1297 | Unprotected Confidential Information on Device is Accessible by OSAT Vendors | Base | Simple | Incomplete | |
| CWE-1298 | Hardware Logic Contains Race Conditions | Base | Simple | Draft | |
| CWE-1299 | Missing Protection Mechanism for Alternate Hardware Interface | Base | Simple | Draft | |
| CWE-13 | ASP.NET Misconfiguration: Password in Configuration File | Variant | Simple | Draft | |
| CWE-130 | Improper Handling of Length Parameter Inconsistency | Base | Simple | Incomplete | |
| CWE-1300 | Improper Protection of Physical Side Channels | Base | Simple | Stable | |
| CWE-1301 | Insufficient or Incomplete Data Removal within Hardware Component | Base | Simple | Incomplete | |
| CWE-1302 | Missing Source Identifier in Entity Transactions on a System-On-Chip (SOC) | Base | Simple | Incomplete | |
| CWE-1303 | Non-Transparent Sharing of Microarchitectural Resources | Base | Simple | Draft |