| Least Privilege Violation | |
| Insufficient Verification of Data Authenticity | |
| Placement of User into Incorrect Group | |
| Arbitrary File Read/Write | [,16.2.10)[17.1.0,17.2.2) |
| NULL Pointer Dereference | |
| Insufficiently Protected Credentials | [,14.2.16)[15.0.0,15.2.8)[16.0.0,16.2.0) |
| Improper Input Validation | |
| Improper Input Validation | |
| Insufficiently Protected Credentials | |
| CRLF Injection | |
| Improper Authentication | [,10.2.11)[12.2.0,12.2.6)[13.2.0,13.2.1) |
| Improper Authentication | |
| Improper Input Validation | |
| Replay Attack | [,14.2.14)[15.0.0,15.2.6) |
| Improper Authorization | |
| Information Exposure | |
| Improper Authentication | [,10.2.11)[12.2.0,12.2.6)[13.2.0,13.2.1) |
| Cross-site Scripting (XSS) | |
| Denial of Service (DoS) | |
| Incorrect Authorization | |
| Insecure Randomness | |
| Insufficiently Protected Credentials | [,14.2.17)[15.2.0,15.2.9) |
| NULL Pointer Dereference | |
| HTTP Response Splitting | |
| Security Features | |
| Improper Input Validation | |
| Improper Authentication | |