Information Exposure Through Log Files | |
Cross-site Scripting (XSS) | |
Cross-site Scripting (XSS) | |
Cross-site Scripting (XSS) | |
Information Exposure | |
SQL Injection | |
Information Exposure | |
Deserialization of Untrusted Data | |
Cross-site Scripting (XSS) | |
Cross-site Scripting (XSS) | |
XML External Entity (XXE) Injection | |
Information Exposure | |
Reachable Assertion | |
Incorrect Use of Privileged APIs | |
Improper Input Validation | |
Improper Certificate Validation | |
Improper Input Validation | |
Uncaught Exception | |
Exposed Dangerous Method or Function | |
Use of a Broken or Risky Cryptographic Algorithm | |
Return of Wrong Status Code | |
Improper Access Control | |
Numeric Range Comparison Without Minimum Check | |
Improper Input Validation | |
Improper Input Validation | |
Null Byte Interaction Error (Poison Null Byte) | |
Improper Input Validation | |
Improper Input Validation | |
Return of Wrong Status Code | |
Loop with Unreachable Exit Condition ('Infinite Loop') | |
Insufficient Session Expiration | |
Integer Overflow or Wraparound | |
Use After Free | |
Loop with Unreachable Exit Condition ('Infinite Loop') | |
Improper Input Validation | |
Improper Input Validation | |
Improper Input Validation | |
Missing Required Cryptographic Step | |
Missing Required Cryptographic Step | |
Information Exposure | |
Incorrect Authorization | |
Incorrect Permission Assignment for Critical Resource | |
Incorrect Permission Assignment for Critical Resource | |
Resource Exhaustion | |
Resource Exhaustion | |
Covert Timing Channel | |
Incorrect Calculation | |
Missing Required Cryptographic Step | |
Missing Required Cryptographic Step | |
Missing Required Cryptographic Step | |
Directory Traversal | |
Use of Cryptographically Weak Pseudo-Random Number Generator (PRNG) | |
Improper Certificate Validation | |
CVE-2013-6668 | |
Information Exposure | |
Improper Input Validation | |
Information Exposure | |
Improper Input Validation | |
Improper Input Validation | |
Cross-site Scripting (XSS) | |
Use of Externally-Controlled Input to Select Classes or Code ('Unsafe Reflection') | |
Omission of Security-relevant Information | |
Information Exposure | |
Incomplete Blacklist | |
Resource Exhaustion | |
Out-of-Bounds | |
CVE-2016-6346 | |
Access Restriction Bypass | |
Improper Data Handling | |
Improper Data Handling | |
Algorithmic Complexity | |