| CRLF Injection | |
| Inclusion of Functionality from Untrusted Control Sphere | |
| Exposure of Sensitive Information Through Metadata | |
| Buffer Over-read | |
| Improper Neutralization of Quoting Syntax | |
| Use of Less Trusted Source | |
| Improper Preservation of Consistency Between Independent Representations of Shared State | |
| Incorrect Privilege Assignment | |
| Arbitrary Code Execution | |
| Time-of-check Time-of-use (TOCTOU) Race Condition | |
| Improper Access Control | |
| Privilege Management Errors | |
| Buffer Overflow | |
| Improper Privilege Management | |
| Information Exposure | |
| Denial of Service (DoS) | |
| SQL Injection | [,11.21)[12.10,12.16)[13.6,13.12)[14.2,14.9)[15.3,15.4) |
| Access Control Bypass | |
| Arbitrary Code Execution | [,11.21)[12.10,12.16)[13.6,13.12)[14.2,14.8) |
| Improper Privilege Management | [,11.21)[12.10,12.16)[13.6,13.12)[14.2,14.8) |
| Information Exposure | [,11.21)[12.10,12.16)[13.6,13.12)[14.2,14.7) |
| Arbitrary Code Execution | [,10.23)[11.15,11.21)[12.10,12.16)[13.6,13.12)[14.2,14.5) |
| Incorrect Authorization | [,10.23)[12.10,12.16)[13.6,13.12)[14.2,14.7) |
| Symlink Attack | |
| Access Restriction Bypass | |
| CVE-2005-1409 | |
| Access Restriction Bypass | |
| CVE-2002-1657 | |
| Out-of-Bounds | |
| Arbitrary Code Execution | |
| CVE-2007-3279 | |
| Access Restriction Bypass | |
| Information Exposure | |
| Denial of Service (DoS) | |
| Access Restriction Bypass | |
| Improper Input Validation | |
| Denial of Service (DoS) | |
| Remote Code Execution (RCE) | |
| Information Exposure | |
| Denial of Service (DoS) | |
| Information Exposure | |
| Improper Input Validation | |
| Denial of Service (DoS) | |
| Denial of Service (DoS) | |
| Denial of Service (DoS) | |
| Information Exposure | |
| CVE-2004-0977 | |
| Remote Code Execution (RCE) | |