CWE 弱点
CWE 基础字段与弱点分类查询。
| CWE ID | 名称 | 抽象级别 | 结构 | 状态 | 操作 |
|---|---|---|---|---|---|
| CWE-787 | Out-of-bounds Write | Base | Simple | Draft | |
| CWE-788 | Access of Memory Location After End of Buffer | Base | Simple | Incomplete | |
| CWE-789 | Memory Allocation with Excessive Size Value | Variant | Simple | Draft | |
| CWE-79 | Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') | Base | Simple | Stable | |
| CWE-790 | Improper Filtering of Special Elements | Class | Simple | Incomplete | |
| CWE-791 | Incomplete Filtering of Special Elements | Base | Simple | Incomplete | |
| CWE-792 | Incomplete Filtering of One or More Instances of Special Elements | Variant | Simple | Incomplete | |
| CWE-793 | Only Filtering One Instance of a Special Element | Variant | Simple | Incomplete | |
| CWE-794 | Incomplete Filtering of Multiple Instances of Special Elements | Variant | Simple | Incomplete | |
| CWE-795 | Only Filtering Special Elements at a Specified Location | Base | Simple | Incomplete | |
| CWE-796 | Only Filtering Special Elements Relative to a Marker | Variant | Simple | Incomplete | |
| CWE-797 | Only Filtering Special Elements at an Absolute Position | Variant | Simple | Incomplete | |
| CWE-798 | Use of Hard-coded Credentials | Base | Simple | Draft | |
| CWE-799 | Improper Control of Interaction Frequency | Class | Simple | Incomplete | |
| CWE-8 | J2EE Misconfiguration: Entity Bean Declared Remote | Variant | Simple | Incomplete | |
| CWE-80 | Improper Neutralization of Script-Related HTML Tags in a Web Page (Basic XSS) | Variant | Simple | Incomplete | |
| CWE-804 | Guessable CAPTCHA | Base | Simple | Incomplete | |
| CWE-805 | Buffer Access with Incorrect Length Value | Base | Simple | Incomplete | |
| CWE-806 | Buffer Access Using Size of Source Buffer | Variant | Simple | Incomplete | |
| CWE-807 | Reliance on Untrusted Inputs in a Security Decision | Base | Simple | Incomplete |