Güvenlik zafiyetleri bilgi tabanı
CWE Zafiyet Sözlüğü
Bir güvenlik açığının arkasındaki yazılım veya donanım hatasını anlayın; neden oluştuğunu, etkisini, nasıl tespit edildiğini ve nasıl önleneceğini inceleyin.
Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')
The software does not neutralize or incorrectly neutralizes user-controllable input before it is placed in output that is used as a web page that is served to other users.
Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection')
The software constructs an SQL command using externally-influenced input, but fails to neutralize or incorrectly neutralizes special elements that could modify the intended SQL command.
Improper Input Validation
The product receives input or data, but does not validate or incorrectly validates that the input has the properties that are required to process the data safely and correctly.
Improper Restriction of Operations within the Bounds of a Memory Buffer
The software performs operations on a memory buffer, but reads or writes outside the intended boundary of the buffer.
Out-of-bounds Read
The software reads data past the end, or before the beginning, of the intended buffer, potentially exposing sensitive information.
Out-of-bounds Write
The software writes data past the end, or before the beginning, of the intended buffer, leading to memory corruption or arbitrary code execution.
Use After Free
Referencing memory after it has been freed can cause a program to crash, use unexpected values, or execute code.
Exposure of Sensitive Information to an Unauthorized Actor
The product exposes sensitive information to an actor that is not explicitly authorized to have access to that information.
Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal')
The software uses external input to construct a pathname without properly neutralizing special elements such as "..", allowing access to arbitrary files.
Cross-Site Request Forgery (CSRF)
The web application does not verify whether a request originated from the user intentionally, allowing attackers to execute unauthorized state-changing actions.
Improper Neutralization of Special Elements used in an OS Command ('OS Command Injection')
The software constructs an OS command using externally-influenced input without neutralizing special characters that alter the command execution.
NULL Pointer Dereference
A NULL pointer dereference occurs when the application attempts to read or write to memory through a pointer that evaluates to NULL.
Integer Overflow or Wraparound
The software performs an integer calculation that results in a value that is larger than the maximum integer representation, wrapping around to a small or negative value.
Improper Authentication
The software does not properly authenticate users when they attempt to access protected resources.
Allocation of Resources Without Limits or Throttling
The software allocates resources without setting restrictions on quantity or rate, exposing the system to Denial of Service (DoS).
Deserialization of Untrusted Data
The application deserializes untrusted data without sufficient verification, leading to remote code execution.
Improper Control of Generation of Code ('Code Injection')
The software constructs code using externally-influenced input without properly neutralizing special elements, allowing arbitrary code execution.
Server-Side Request Forgery (SSRF)
The web application fetches a remote resource without validating the user-supplied URL, allowing requests to internal or restricted resources.
Improper Modification of Object Prototype Attributes ('Prototype Pollution')
The application modifies attributes of an object prototype using untrusted input, altering the behavior of all objects inheriting from that prototype.