VULHUB
™
首页
漏洞
ATT&CK
CWE
视图
自定义
留言
关于
登录
首页
漏洞
ATT&CK
CWE
视图
自定义
留言
关于
研究者视图
Research Concepts
该视图旨在促进对弱点的研究,包括它们之间的相互依赖性,并可用来系统地找出CWE内部的理论差距。它对弱点进行了分类,在很大程度上忽略了如何检测它们,它们出现在代码中的什么地方,以及它们何时被引入软件开发生命周期。相反,它主要是根据软件行为的抽象来组织的。
Development Concepts
该视图围绕软件开发中经常使用或遇到的概念组织弱点。因此,该视图可以与开发人员、教育工作者和评估供应商的观点紧密一致。它提供了多种类别,旨在简化导航、浏览和映射。
Architectural Concepts
该视图根据常见的架构安全策略组织弱点。它旨在帮助架构师识别设计软件时可能出现的潜在错误。
CWE-429: 处理程序错误
CWE-445: 已弃用:用户界面错误
CWE-559: 常见误用:形参和实参
CWE-63: DEPRECATED: Windows Path Link Problems
CWE-632: DEPRECATED: Weaknesses that Affect Files or Directories
CWE-633: DEPRECATED: Weaknesses that Affect Memory
CWE-634: DEPRECATED: Weaknesses that Affect System Processes
CWE-68: DEPRECATED: Windows Virtual File Problems
CWE-70: DEPRECATED: Mac Virtual File Problems
CWE-712: OWASP Top Ten 2007 Category A1 - Cross Site Scripting (XSS)
CWE-713: OWASP Top Ten 2007 Category A2 - Injection Flaws
CWE-714: OWASP Top Ten 2007 Category A3 - Malicious File Execution
CWE-715: OWASP Top Ten 2007 Category A4 - Insecure Direct Object Reference
CWE-716: OWASP Top Ten 2007 Category A5 - Cross Site Request Forgery (CSRF)
CWE-717: OWASP Top Ten 2007 Category A6 - Information Leakage and Improper Error Handling
CWE-718: OWASP Top Ten 2007 Category A7 - Broken Authentication and Session Management
CWE-721: OWASP Top Ten 2007 Category A10 - Failure to Restrict URL Access
CWE-724: OWASP Top Ten 2004 Category A3 - Broken Authentication and Session Management
CWE-739: CERT C Secure Coding Standard (2008) Chapter 6 - Floating Point (FLP)
CWE-742: CERT C Secure Coding Standard (2008) Chapter 9 - Memory Management (MEM)
CWE-801: 2010 Top 25 - Insecure Interaction Between Components
CWE-808: 2010 Top 25 - Weaknesses On the Cusp
CWE-812: OWASP Top Ten 2010 Category A3 - Broken Authentication and Session Management
CWE-845: The CERT Oracle Secure Coding Standard for Java (2011) Chapter 2 - Input Validation and Data Sanitization (IDS)
CWE-848: The CERT Oracle Secure Coding Standard for Java (2011) Chapter 5 - Numeric Types and Operations (NUM)
CWE-853: The CERT Oracle Secure Coding Standard for Java (2011) Chapter 10 - Locking (LCK)
CWE-858: The CERT Oracle Secure Coding Standard for Java (2011) Chapter 15 - Serialization (SER)
CWE-861: The CERT Oracle Secure Coding Standard for Java (2011) Chapter 18 - Miscellaneous (MSC)
CWE-866: 2011 Top 25 - Porous Defenses
CWE-871: CERT C++ Secure Coding Section 03 - Expressions (EXP)
1
2
…
28
29
30
31
32
33
34
35
…
39
40
[共 1189 条]