Güvenlik zafiyetleri bilgi tabanı

CWE Zafiyet Sözlüğü

Bir güvenlik açığının arkasındaki yazılım veya donanım hatasını anlayın; neden oluştuğunu, etkisini, nasıl tespit edildiğini ve nasıl önleneceğini inceleyin.

19

Öne çıkan CWE

9

Zafiyet kategorisi

CAPEC saldırı
kalıplarını aç
19 CWE kaydı gösteriliyorBaşlığa, kimliğe ve açıklamaya göre arama
CWE-79Web Security

Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')

The software does not neutralize or incorrectly neutralizes user-controllable input before it is placed in output that is used as a web page that is served to other users.

Base · Simpleİncele
CWE-89Database & Injection

Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection')

The software constructs an SQL command using externally-influenced input, but fails to neutralize or incorrectly neutralizes special elements that could modify the intended SQL command.

Base · Simpleİncele
CWE-20Input Validation

Improper Input Validation

The product receives input or data, but does not validate or incorrectly validates that the input has the properties that are required to process the data safely and correctly.

Class · Simpleİncele
CWE-119Memory Safety

Improper Restriction of Operations within the Bounds of a Memory Buffer

The software performs operations on a memory buffer, but reads or writes outside the intended boundary of the buffer.

Class · Simpleİncele
CWE-125Memory Safety

Out-of-bounds Read

The software reads data past the end, or before the beginning, of the intended buffer, potentially exposing sensitive information.

Base · Simpleİncele
CWE-787Memory Safety

Out-of-bounds Write

The software writes data past the end, or before the beginning, of the intended buffer, leading to memory corruption or arbitrary code execution.

Base · Simpleİncele
CWE-416Memory Safety

Use After Free

Referencing memory after it has been freed can cause a program to crash, use unexpected values, or execute code.

Base · Simpleİncele
CWE-200Information Leak

Exposure of Sensitive Information to an Unauthorized Actor

The product exposes sensitive information to an actor that is not explicitly authorized to have access to that information.

Class · Simpleİncele
CWE-22Access Control

Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal')

The software uses external input to construct a pathname without properly neutralizing special elements such as "..", allowing access to arbitrary files.

Base · Simpleİncele
CWE-352Web Security

Cross-Site Request Forgery (CSRF)

The web application does not verify whether a request originated from the user intentionally, allowing attackers to execute unauthorized state-changing actions.

Base · Simpleİncele
CWE-78Database & Injection

Improper Neutralization of Special Elements used in an OS Command ('OS Command Injection')

The software constructs an OS command using externally-influenced input without neutralizing special characters that alter the command execution.

Base · Simpleİncele
CWE-476Memory Safety

NULL Pointer Dereference

A NULL pointer dereference occurs when the application attempts to read or write to memory through a pointer that evaluates to NULL.

Base · Simpleİncele
CWE-190Memory Safety

Integer Overflow or Wraparound

The software performs an integer calculation that results in a value that is larger than the maximum integer representation, wrapping around to a small or negative value.

Base · Simpleİncele
CWE-287Authentication

Improper Authentication

The software does not properly authenticate users when they attempt to access protected resources.

Class · Simpleİncele
CWE-770Resource Management

Allocation of Resources Without Limits or Throttling

The software allocates resources without setting restrictions on quantity or rate, exposing the system to Denial of Service (DoS).

Base · Simpleİncele
CWE-502Serialization

Deserialization of Untrusted Data

The application deserializes untrusted data without sufficient verification, leading to remote code execution.

Base · Simpleİncele
CWE-94Database & Injection

Improper Control of Generation of Code ('Code Injection')

The software constructs code using externally-influenced input without properly neutralizing special elements, allowing arbitrary code execution.

Class · Simpleİncele
CWE-918Web Security

Server-Side Request Forgery (SSRF)

The web application fetches a remote resource without validating the user-supplied URL, allowing requests to internal or restricted resources.

Base · Simpleİncele
CWE-1321Web Security

Improper Modification of Object Prototype Attributes ('Prototype Pollution')

The application modifies attributes of an object prototype using untrusted input, altering the behavior of all objects inheriting from that prototype.

Variant · Simpleİncele
CWE Zafiyet Sözlüğü · DayBreach · DayBreach