研究者视图

Research Concepts

该视图旨在促进对弱点的研究,包括它们之间的相互依赖性,并可用来系统地找出CWE内部的理论差距。它对弱点进行了分类,在很大程度上忽略了如何检测它们,它们出现在代码中的什么地方,以及它们何时被引入软件开发生命周期。相反,它主要是根据软件行为的抽象来组织的。

Development Concepts

该视图围绕软件开发中经常使用或遇到的概念组织弱点。因此,该视图可以与开发人员、教育工作者和评估供应商的观点紧密一致。它提供了多种类别,旨在简化导航、浏览和映射。

Architectural Concepts

该视图根据常见的架构安全策略组织弱点。它旨在帮助架构师识别设计软件时可能出现的潜在错误。
CWE-429: 处理程序错误 CWE-445: 已弃用:用户界面错误 CWE-559: 常见误用:形参和实参 CWE-63: DEPRECATED: Windows Path Link Problems CWE-632: DEPRECATED: Weaknesses that Affect Files or Directories CWE-633: DEPRECATED: Weaknesses that Affect Memory CWE-634: DEPRECATED: Weaknesses that Affect System Processes CWE-68: DEPRECATED: Windows Virtual File Problems CWE-70: DEPRECATED: Mac Virtual File Problems CWE-712: OWASP Top Ten 2007 Category A1 - Cross Site Scripting (XSS) CWE-713: OWASP Top Ten 2007 Category A2 - Injection Flaws CWE-714: OWASP Top Ten 2007 Category A3 - Malicious File Execution CWE-715: OWASP Top Ten 2007 Category A4 - Insecure Direct Object Reference CWE-716: OWASP Top Ten 2007 Category A5 - Cross Site Request Forgery (CSRF) CWE-717: OWASP Top Ten 2007 Category A6 - Information Leakage and Improper Error Handling CWE-718: OWASP Top Ten 2007 Category A7 - Broken Authentication and Session Management CWE-721: OWASP Top Ten 2007 Category A10 - Failure to Restrict URL Access CWE-724: OWASP Top Ten 2004 Category A3 - Broken Authentication and Session Management CWE-739: CERT C Secure Coding Standard (2008) Chapter 6 - Floating Point (FLP) CWE-742: CERT C Secure Coding Standard (2008) Chapter 9 - Memory Management (MEM) CWE-801: 2010 Top 25 - Insecure Interaction Between Components CWE-808: 2010 Top 25 - Weaknesses On the Cusp CWE-812: OWASP Top Ten 2010 Category A3 - Broken Authentication and Session Management CWE-845: The CERT Oracle Secure Coding Standard for Java (2011) Chapter 2 - Input Validation and Data Sanitization (IDS) CWE-848: The CERT Oracle Secure Coding Standard for Java (2011) Chapter 5 - Numeric Types and Operations (NUM) CWE-853: The CERT Oracle Secure Coding Standard for Java (2011) Chapter 10 - Locking (LCK) CWE-858: The CERT Oracle Secure Coding Standard for Java (2011) Chapter 15 - Serialization (SER) CWE-861: The CERT Oracle Secure Coding Standard for Java (2011) Chapter 18 - Miscellaneous (MSC) CWE-866: 2011 Top 25 - Porous Defenses CWE-871: CERT C++ Secure Coding Section 03 - Expressions (EXP)
[共 1189 条]