| Resource Exhaustion |  | 
| Resource Exhaustion |  | 
| HTTP Request Smuggling |  | 
| Inefficient Regular Expression Complexity |  | 
| Allocation of Resources Without Limits or Throttling |  | 
| Improper Validation of Specified Type of Input |  | 
| Covert Timing Channel |  | 
| Inefficient Regular Expression Complexity |  | 
| Resource Exhaustion |  | 
| Buffer Over-read |  | 
| Out-of-bounds Read |  | 
| Arbitrary Code Injection |  | 
| Improper Input Validation |  | 
| Improper Input Validation |  | 
| HTTP Response Splitting |  | 
| Out-of-bounds Write |  | 
| Out-of-bounds Read |  | 
| Reliance on Cookies without Validation and Integrity Checking |  | 
| Resource Exhaustion |  | 
| Null Byte Interaction Error (Poison Null Byte) |  | 
| Out-of-Bounds |  | 
| Heap-based Buffer Overflow |  | 
| Improper Input Validation |  | 
| Information Exposure |  | 
| Improper Restriction of Recursive Entity References in DTDs ('XML Entity Expansion') |  | 
| Off-by-one Error |  | 
| Improper Restriction of Recursive Entity References in DTDs ('XML Entity Expansion') |  | 
| XML External Entity (XXE) Injection |  | 
| HTTP Request Smuggling |  | 
| Improper Input Validation |  | 
| Directory Traversal |  | 
| Null Byte Interaction Error (Poison Null Byte) |  | 
| Resource Exhaustion |  | 
| Out-of-bounds Read |  | 
| Directory Traversal |  | 
| Arbitrary Code Injection |  | 
| HTTP Response Splitting |  | 
| Resource Exhaustion |  | 
| Null Byte Interaction Error (Poison Null Byte) |  | 
| Improper Certificate Validation |  | 
| Improper Input Validation |  | 
| Improper Verification of Cryptographic Signature |  | 
| Directory Traversal |  | 
| Cross-site Scripting (XSS) |  | 
| Deserialization of Untrusted Data |  | 
| Loop with Unreachable Exit Condition ('Infinite Loop') |  | 
| Improper Input Validation |  | 
| Directory Traversal |  | 
| Improper Input Validation |  | 
| Out-of-bounds Write |  | 
| Heap-based Buffer Overflow |  | 
| Out-of-bounds Read |  | 
| Out-of-bounds Write |  | 
| Out-of-bounds Read |  | 
| HTTP Response Splitting |  | 
| Arbitrary Command Injection |  | 
| Improper Input Validation |  | 
| Arbitrary Argument Injection |  | 
| Arbitrary Argument Injection |  | 
| Arbitrary Argument Injection |  | 
| Arbitrary Argument Injection |  | 
| Improper Neutralization of Special Elements |  | 
| Improper Neutralization of Special Elements |  | 
| Improper Neutralization of Special Elements |  | 
| Improper Output Neutralization for Logs |  | 
| Improper Neutralization of Special Elements |  | 
| Cleartext Transmission of Sensitive Information |  | 
| Information Exposure |  | 
| Arbitrary Command Injection |  | 
| Inadequate Encryption Strength |  | 
| Heap-based Buffer Overflow |  | 
| Access of Resource Using Incompatible Type ('Type Confusion') |  | 
| Off-by-one Error |  | 
| Arbitrary Argument Injection |  | 
| Privilege Defined With Unsafe Actions |  | 
| Out-of-bounds Read |  | 
| NULL Pointer Dereference |  | 
| Improper Input Validation |  | 
| Improper Validation of Certificate with Host Mismatch |  | 
| Privilege Defined With Unsafe Actions |  |