1.
CWE - CWE-426: Untrusted Search Path (1.3)
Compound Element ID: 426 (Compound Element Base: Composite). Description. Summary. The application searches for critical resources using an ...
2.
CWE - CWE-343: Predictable Value Range from Previous Values (1.3)
Oct 14, 2008 ... The software's random number generator produces a series of values which, when observed, can be used to infer a relatively small range of ...
3.
CWE - CWE-154: Improper Sanitization of Variable Name Delimiters (1.3)
Common Weakness Enumeration (CWE) is a list of software weaknesses.
4.
CWE - CWE-91: XML Injection (aka Blind XPath Injection) (1.3)
XML Injection (aka Blind XPath Injection). Status: Draft ... does not properly filter or quote special characters or reserved words that are used in XML, ...
5.
CWE - CWE-20: Improper Input Validation (1.3)
However, input validation is not always sufficient, especially when less stringent data types must be supported, such as free-form text. ...
6.
Naval Research Laboratory A Taxonomy of Computer Program Security ...
File Format: PDF/Adobe Acrobat - View as HTML This paper provides a taxonomy for computer program security flaws together ...... Although this taxonomy principally addresses software flaws, programs can ...
7.
Root Genesis How does a security flaw find its way into a program ...
File Format: PDF/Adobe Acrobat - View as HTML Root. Genesis. How does a security flaw find its way into a program? ... unusual in a large software system. If such a flaw af ects security and its cor ...
8.
CWE - CWE-301: Reflection Attack in an Authentication Protocol (1.3)
Simple authentication protocols are subject to reflection attacks if a malicious user ... In a reflection attack, the attacker claims to be a valid user and ...
9.
CWE - CWE-301: Reflection Attack in an Authentication Protocol (1.3)
Simple authentication protocols are subject to reflection attacks if a ... The primary result of reflection attacks is successful authentication with a ...
10.
CWE - VIEW GRAPH: CWE-692: Incomplete Blacklist to Cross-Site ...
Common Weakness Enumeration (CWE) is a list of software weaknesses.