CWE 弱点
CWE 基础字段与弱点分类查询。
| CWE ID | 名称 | 抽象级别 | 结构 | 状态 | 操作 |
|---|---|---|---|---|---|
| CWE-603 | Use of Client-Side Authentication | Base | Simple | Draft | |
| CWE-605 | Multiple Binds to the Same Port | Variant | Simple | Draft | |
| CWE-606 | Unchecked Input for Loop Condition | Base | Simple | Draft | |
| CWE-607 | Public Static Final Field References Mutable Object | Variant | Simple | Draft | |
| CWE-608 | Struts: Non-private Field in ActionForm Class | Variant | Simple | Draft | |
| CWE-609 | Double-Checked Locking | Base | Simple | Draft | |
| CWE-61 | UNIX Symbolic Link (Symlink) Following | Compound | Composite | Incomplete | |
| CWE-610 | Externally Controlled Reference to a Resource in Another Sphere | Class | Simple | Draft | |
| CWE-611 | Improper Restriction of XML External Entity Reference | Base | Simple | Draft | |
| CWE-612 | Improper Authorization of Index Containing Sensitive Information | Base | Simple | Draft | |
| CWE-613 | Insufficient Session Expiration | Base | Simple | Incomplete | |
| CWE-614 | Sensitive Cookie in HTTPS Session Without 'Secure' Attribute | Variant | Simple | Draft | |
| CWE-615 | Inclusion of Sensitive Information in Source Code Comments | Variant | Simple | Incomplete | |
| CWE-616 | Incomplete Identification of Uploaded File Variables (PHP) | Variant | Simple | Incomplete | |
| CWE-617 | Reachable Assertion | Base | Simple | Draft | |
| CWE-618 | Exposed Unsafe ActiveX Method | Variant | Simple | Incomplete | |
| CWE-619 | Dangling Database Cursor ('Cursor Injection') | Base | Simple | Incomplete | |
| CWE-62 | UNIX Hard Link | Variant | Simple | Incomplete | |
| CWE-620 | Unverified Password Change | Base | Simple | Draft | |
| CWE-621 | Variable Extraction Error | Variant | Simple | Incomplete |