C/C++

Pages44

Operating System Command Injection

Operating system command injection in C/C++

Externally Controlled Format Strings in C/C++

Risks of using untrusted input as a printf-style format string

Path Traversal

Filesystem path traversal in C/C++

Archive path traversal

Archive path traversal

SQL injection

SQL injection in C/C++

Manipulation of process or dynamic-library targets

Manipulation of process or dynamic-library targets in C/C++

XML external entities (XXE)

XML external entities (XXE)

Disabled certificate validation

Disabled certificate validation

Disabled hostname verification

Disabled hostname verification

Weak TLS protocols

Weak TLS protocols

Weak cryptographic algorithms

Weak cryptographic algorithms

Insufficient cryptographic key size

Insufficient cryptographic key size

Insecure random-number generation

Insecure random-number generation

Sensitive data stored in plaintext

Sensitive data stored in plaintext

Sensitive data sent in plaintext

Sensitive data sent in plaintext

Clearing sensitive data with memset

Clearing sensitive data with memset

Insecure file permissions

Insecure file permissions

Insecure temporary file creation

Insecure temporary file creation

Security-sensitive files in publicly writable directories

Security-sensitive files in publicly writable directories

Arbitrary memory write

Arbitrary memory write

Constant array index outside the declared bounds

Constant array index outside the declared bounds

Division by zero

Division by zero

Double fetch

Double fetch across a validation boundary

Double free

Double free

Overflow when copying into a heap buffer

Overflow when copying into a dynamically allocated heap buffer

Fixed-size buffer overflow

Fixed-size buffer overflow

Integer overflow in allocation sizes

Integer overflow in allocation sizes

Integer underflow in allocation sizes

Integer underflow in allocation sizes

Invalid free

Freeing memory that was not dynamically allocated

Mismatched allocation and deallocation

Memory released with a mismatched allocator family

NULL pointer dereference

NULL pointer dereference

Returning a stack address

Returning an address into stack storage

Stack use after scope

Stack storage used after its scope ends

User-Controlled Allocation Size

User-controlled allocation size

User-Controlled Array Index

User-controlled array index

User-Controlled Buffer Length

User-controlled buffer length

Uninitialized Memory Disclosure

Uninitialized memory copied into user-visible output

Use-After-Free

Use-after-free

Unsafe use of gets

Unsafe use of gets

Unsafe use of sprintf

Unsafe use of sprintf

Unsafe use of strcat

Unsafe use of strcat

Unsafe use of strcpy

Unsafe use of strcpy

Unsafe use of tmpnam

Unsafe use of tmpnam

scanf string input without a field width

scanf string input without a field width