CWE 弱点
CWE 基础字段与弱点分类查询。
| CWE ID | 名称 | 抽象级别 | 结构 | 状态 | 操作 |
|---|---|---|---|---|---|
| CWE-24 | Path Traversal: '../filedir' | Variant | Simple | Incomplete | |
| CWE-240 | Improper Handling of Inconsistent Structural Elements | Base | Simple | Draft | |
| CWE-241 | Improper Handling of Unexpected Data Type | Base | Simple | Draft | |
| CWE-242 | Use of Inherently Dangerous Function | Base | Simple | Draft | |
| CWE-243 | Creation of chroot Jail Without Changing Working Directory | Variant | Simple | Draft | |
| CWE-244 | Improper Clearing of Heap Memory Before Release ('Heap Inspection') | Variant | Simple | Draft | |
| CWE-245 | J2EE Bad Practices: Direct Management of Connections | Variant | Simple | Draft | |
| CWE-246 | J2EE Bad Practices: Direct Use of Sockets | Variant | Simple | Draft | |
| CWE-247 | DEPRECATED: Reliance on DNS Lookups in a Security Decision | Base | Simple | Deprecated | |
| CWE-248 | Uncaught Exception | Base | Simple | Draft | |
| CWE-249 | DEPRECATED: Often Misused: Path Manipulation | Variant | Simple | Deprecated | |
| CWE-25 | Path Traversal: '/../filedir' | Variant | Simple | Incomplete | |
| CWE-250 | Execution with Unnecessary Privileges | Base | Simple | Draft | |
| CWE-252 | Unchecked Return Value | Base | Simple | Draft | |
| CWE-253 | Incorrect Check of Function Return Value | Base | Simple | Incomplete | |
| CWE-256 | Plaintext Storage of a Password | Base | Simple | Incomplete | |
| CWE-257 | Storing Passwords in a Recoverable Format | Base | Simple | Incomplete | |
| CWE-258 | Empty Password in Configuration File | Variant | Simple | Incomplete | |
| CWE-259 | Use of Hard-coded Password | Variant | Simple | Draft | |
| CWE-26 | Path Traversal: '/dir/../filename' | Variant | Simple | Draft |