Security
GistPad.com – Security & Privacy
Last Updated: November 14, 2025
At GistPad.com, we take the security and privacy of your gists and account data very seriously. Our platform is designed with modern security practices to ensure that your data remains safe while using our services.
1. Data Protection
GistPad.com protects your information through several technical and organizational measures:
- All data in transit is secured using HTTPS encryption, preventing unauthorized interception.
- Passwords are hashed securely using industry-standard algorithms; no password is stored in plain text.
- Regular backups are performed to ensure that your gists are not lost due to technical failures.
- Our system monitors for unusual activity and potential security threats to prevent unauthorized access.
- We follow strict internal protocols for access to sensitive data by our staff, limiting exposure.
2. Privacy & Account Options
Users have flexible control over their gists and account information:
- Gists can be public, unlisted, or private, allowing users to control who can access them.
- Private gists can be password-protected for additional security.
- Social login options, including X login, are available for convenience and to reduce the need for creating new credentials.
- We do not sell, trade, or share your personal information with third parties. Your privacy is a core principle of our platform.
3. VPN and Secure Access
We recommend using a VPN (Virtual Private Network) to further protect your account and gists while accessing GistPad.com. Using a VPN can:
- Encrypt your internet connection to prevent interception of sensitive data.
- Mask your IP address and location to maintain privacy.
- Provide an additional layer of security when using public or untrusted networks.
While using a VPN is optional, it is strongly encouraged for users handling sensitive information or working on public networks.
4. Vulnerability Disclosure Program (VDP)
GistPad.com values responsible security research. Our VDP allows ethical hackers and security researchers to report potential vulnerabilities responsibly.
- Security reports can be submitted directly to our VDP on Hackerone form you can find it below or to hello@gistpad.com.
- We do not provide monetary rewards for reported vulnerabilities.
- All contributors are recognized in our Hall of Fame, publicly acknowledging their efforts.
- Responsible disclosure helps improve platform security for all users and ensures the safety of their data.
5. Responsible Use
To maintain a secure environment for all users, the following rules apply:
- Do not attempt to exploit, hack, or abuse the GistPad.com platform.
- Report any potential security issues only through the official VDP process.
- Do not share API keys, credentials, or personal information of other users.
6. Additional Measures
GistPad.com continuously works to improve security by:
- Regularly updating software and frameworks to fix known vulnerabilities.
- Performing internal security audits to identify and mitigate risks.
- Ensuring that all third-party integrations, including social logins, follow strict security standards.
- Monitoring traffic and platform behavior to detect potential abuse or attacks.
7. Disclaimer
While GistPad.com implements modern security practices, no system can be completely secure. Users are responsible for maintaining the security of their own accounts and are encouraged to use additional tools, such as VPNs, for sensitive activity. Using the platform constitutes acceptance of these terms.
HackerOne
Submit Vulnerability Report
Program highlights
Open ScopeAccepts reports for all owned assets based on impact, even if not listed in scope.Learn more about Open Scope (opens in a new tab)
Gold Standard Safe HarborAdheres to Gold Standard Safe Harbor.Learn more about Gold Standard Safe Harbor (opens in a new tab)
MenuMenu
You're about to submit a report to GistPad VDP. Provide as much information as possible about the potential issue you have discovered. The more information you provide, the quicker GistPad VDP will be able to validate the issue.
Response targets for this program:
- Time to first response: 3 days
- Time to triage: 3 days
- Time to resolution: 30 days
1
Weakness
Select the type of the potential issue you have discovered. Can't pick just one? Select the best match or submit a separate report for each distinct weakness.
Select Weakness Type...
- Absolute Path Traversal(CWE-36)
Absolute Path Traversal(CAPEC-597)
Acceptance of Extraneous Untrusted Data With Trusted Data(CWE-349)
Access Control Check Implemented After Asset is Accessed(CWE-1280)
Accessing Functionality Not Properly Constrained by ACLs(CAPEC-1)
Accessing/Intercepting/Modifying HTTP Cookies(CAPEC-31)
Access of Memory Location After End of Buffer(CWE-788)
Access of Memory Location Before Start of Buffer(CWE-786)
Access of Uninitialized Pointer(CWE-824)
Access to Critical Private Variable via Public Method(CWE-767)
Account Footprinting(CAPEC-575)
Action Spoofing(CAPEC-173)
Active OS Fingerprinting(CAPEC-312)
Adding a Space to a File Extension(CAPEC-649)
Addition of Data Structure Sentinel(CWE-464) Add Malicious File to Shared Webroot(CAPEC-563) Adversary in the Browser (AiTB)(CAPEC-662) Adversary in the Middle (AiTM)(CAPEC-94) AJAX Footprinting(CAPEC-85) Allocation of File Descriptors or Handles Without Limits or Throttling(CWE-774) Allocation of Resources Without Limits or Throttling(CWE-770) Alteration of a Software Update(CAPEC-669) Altered Component Firmware(CAPEC-638) Altered Installed BIOS(CAPEC-532) Alternative Execution Due to Deceptive Filenames(CAPEC-635) Always-Incorrect Control Flow Implementation(CWE-670) Amplification(CAPEC-490) Analysis of Packet Timing and Sizes(CAPEC-621) Android Activity Hijack(CAPEC-501) Android Intent Intercept(CAPEC-499) Application API Button Hijacking(CAPEC-388) Application API Message Manipulation via Man-in-the-Middle(CAPEC-384) Application API Navigation Remapping(CAPEC-386) Application Fingerprinting(CAPEC-541) Application-Level Admin Tool with Inconsistent View of Underlying Operating System(CWE-1249) Architecture with Number of Horizontal Layers Outside of Expected Range(CWE-1044) Argument Injection(CAPEC-6) Array Declared Public, Final, and Static(CWE-582) Array Index Underflow(CWE-129) Artificially Inflate File Sizes(CAPEC-572) ASIC With Malicious Functionality(CAPEC-539) ASP.NET Misconfiguration: Creating Debug Binary(CWE-11) ASP.NET Misconfiguration: Improper Model Validation(CWE-1174) ASP.NET Misconfiguration: Missing Custom Error Page(CWE-12) ASP.NET Misconfiguration: Not Using Input Validation Framework(CWE-554) ASP.NET Misconfiguration: Password in Configuration File(CWE-13) ASP.NET Misconfiguration: Use of Identity Impersonation(CWE-556) Assigning instead of Comparing(CWE-481) Assignment of a Fixed Address to a Pointer(CWE-587) Assignment to Variable without Use(CWE-563) Assumed-Immutable Data is Stored in Writable Memory(CWE-1282) Asymmetric Resource Consumption (Amplification)(CWE-405) Attempt to Access Child of a Non-structure Pointer(CWE-588) Audit Log Manipulation(CAPEC-268) Authentication Abuse(CAPEC-114) Authentication Bypass(CAPEC-115) Authentication Bypass by Alternate Name(CWE-289) Authentication Bypass by Assumed-Immutable Data(CWE-302) Authentication Bypass by Capture-replay(CWE-294) Authentication Bypass by Primary Weakness(CWE-305) Authentication Bypass by Spoofing(CWE-290) Authentication Bypass: OpenSSL CTX Object Modified after SSL Objects are Created(CWE-593) Authentication Bypass Using an Alternate Path or Channel(CWE-288) Authorization Bypass Through User-Controlled SQL Primary Key(CWE-566) Automated Recognition Mechanism with Inadequate Detection or Handling of Adversarial Input Perturbations(CWE-1039) Avoid Security Tool Identification by Adding Data(CAPEC-655) Behavioral Change in New Version or Environment(CWE-439) BGP Route Disabling(CAPEC-584) Binding to an Unrestricted IP Address(CWE-1327) BitSquatting(CAPEC-611) Black Box Reverse Engineering(CAPEC-189) Blind SQL Injection(CAPEC-7) Block Access to Libraries(CAPEC-96) Blockage(CAPEC-603) Block Logging to Central Repository(CAPEC-571) Blue Boxing(CAPEC-5) BlueSmacking(CAPEC-666) Bluetooth Impersonation AttackS (BIAS)(CAPEC-667) Browser Fingerprinting(CAPEC-472) Browser in the Middle (BiTM)(CAPEC-701) Brute Force(CAPEC-112) Buffer Access Using Size of Source Buffer(CWE-806) Buffer Access with Incorrect Length Value(CWE-805) Buffer Manipulation(CAPEC-123) Buffer Overflow in an API Call(CAPEC-8) Buffer Overflow in Local Command-Line Utilities(CAPEC-9) Buffer Overflow via Environment Variables(CAPEC-10) Buffer Overflow via Parameter Expansion(CAPEC-47) Buffer Overflow via Symbolic Links(CAPEC-45) Buffer Over-read(CWE-126) Buffer Underflow(CWE-124) Buffer Under-read(CWE-127) Business Logic Errors(CWE-840) Bypassing ATA Password Security(CAPEC-402) Bypassing Electronic Locks and Access Controls(CAPEC-395) Bypassing of Intermediate Forms in Multiple-Form Sets(CAPEC-140) Bypassing Physical Locks(CAPEC-391) Bypassing Physical Security(CAPEC-390) Cache Poisoning(CAPEC-141) Callable with Insufficient Behavioral Summary(CWE-1117) Calling Micro-Services Directly(CAPEC-179) Call to Non-ubiquitous API(CWE-589) Call to Thread run() instead of start()(CWE-572) Capture Credentials via Keylogger(CAPEC-568) Carry-Off GPS Attack(CAPEC-628) Cause Web Server Misclassification(CAPEC-11) Cellular Broadcast Message Request(CAPEC-618) Cellular Data Injection(CAPEC-610) Cellular Jamming(CAPEC-605) Cellular Rogue Base Station(CAPEC-617) Cellular Traffic Intercept(CAPEC-609) Checksum Spoofing(CAPEC-145) Choosing Message Identifier(CAPEC-12) Classic Buffer Overflow(CWE-120) Class Instance Self Destruction Control Element(CWE-1082) Class with Excessively Deep Inheritance(CWE-1074) Class with Excessive Number of Child Classes(CWE-1086) Class with Virtual Method without a Virtual Destructor(CWE-1087) Cleartext Storage in a File or on Disk(CWE-313) Cleartext Storage in the Registry(CWE-314) Cleartext Storage of Sensitive Information(CWE-312) Cleartext Storage of Sensitive Information in a Cookie(CWE-315) Cleartext Storage of Sensitive Information in Executable(CWE-318) Cleartext Storage of Sensitive Information in GUI(CWE-317) Cleartext Storage of Sensitive Information in Memory(CWE-316) Cleartext Transmission of Sensitive Information(CWE-319) Client-Server Protocol Manipulation(CAPEC-220) Client-Side Enforcement of Server-Side Security(CWE-602) Client-side Injection-induced Buffer Overflow(CAPEC-14) Cloneable Class Containing Sensitive Information(CWE-498) clone() Method Without super.clone()(CWE-580) Cloning Magnetic Strip Cards(CAPEC-397) Cloning RFID Cards or Chips(CAPEC-399) Code Inclusion(CAPEC-175) Code Injection(CAPEC-242) Code Injection(CWE-94) Collapse of Data into Unsafe Value(CWE-182) Collect Data as Provided by Users(CAPEC-569) Collect Data from Clipboard(CAPEC-637) Collect Data from Common Resource Locations(CAPEC-150) Collect Data from Registries(CAPEC-647) Collect Data from Screen Capture(CAPEC-648) Command Delimiters(CAPEC-15) Command Injection(CAPEC-248) Command Injection - Generic(CWE-77) Command Line Execution through SQL Injection(CAPEC-108) Command Shell in Externally Accessible Directory(CWE-553) Communication Channel Manipulation(CAPEC-216) Comparing instead of Assigning(CWE-482) Comparison Logic is Vulnerable to Power Side-Channel Attacks(CWE-1255) Comparison of Classes by Name(CWE-486) Comparison of Incompatible Types(CWE-1024) Comparison of Object References Instead of Object Contents(CWE-595) Comparison Using Wrong Factors(CWE-1025) Compilation with Insufficient Warnings or Errors(CWE-1127) Compiler Optimization Removal or Modification of Security-critical Code(CWE-733) Compiler Removal of Code to Clear Buffers(CWE-14) Compromising Emanations Attack(CAPEC-623) Concurrent Execution using Shared Resource with Improper Synchronization ('Race Condition')(CWE-362) Configuration/Environment Manipulation(CAPEC-176) Connection Reset(CAPEC-595) Contaminate Resource(CAPEC-548) Content Spoofing(CAPEC-148) Content Spoofing Via Application API Manipulation(CAPEC-389) Context Switching Race Condition(CWE-368) Contradictory Destinations in Traffic Routing Schemes(CAPEC-481) Counterfeit GPS Signals(CAPEC-627) Counterfeit Hardware Component Inserted During Product Assembly(CAPEC-520) Counterfeit Organizations(CAPEC-544) Counterfeit Websites(CAPEC-543) Covert Channel(CWE-514) Covert Storage Channel(CWE-515) Covert Timing Channel(CWE-385) CPU Hardware Not Configured to Support Exclusivity of Write and Execute Operations(CWE-1252) Create files with the same name as files protected with a higher classification(CAPEC-177) Create Malicious Client(CAPEC-202) Creating a Rogue Certification Authority Certificate(CAPEC-459) Creation of chroot Jail Without Changing Working Directory(CWE-243) Creation of Class Instance within a Static Code Block(CWE-1063) Creation of Emergent Resource(CWE-1229) Creation of Immutable Text Using String Concatenation(CWE-1046) Creation of Temporary File in Directory with Insecure Permissions(CWE-379) Creation of Temporary File With Insecure Permissions(CWE-378) Credential Prompt Impersonation(CAPEC-654) Credential Stuffing(CAPEC-600) Critical Data Element Declared Public(CWE-766) Critical Public Variable Without Final Modifier(CWE-493) CRLF Injection(CWE-93) Cross-Domain Search Timing(CAPEC-462) Cross Frame Scripting (XFS)(CAPEC-587) Cross-Site Flashing(CAPEC-178) Cross Site Identification(CAPEC-467) Cross Site Request Forgery(CAPEC-62) Cross-Site Request Forgery (CSRF)(CWE-352) Cross-Site Scripting (XSS)(CAPEC-63) Cross-site Scripting (XSS) - DOM(CWE-79) Cross-site Scripting (XSS) - Generic(CWE-79) Cross-site Scripting (XSS) - Reflected(CWE-79) Cross-site Scripting (XSS) - Stored(CWE-79) Cross Site Tracing(CAPEC-107) Cross Zone Scripting(CAPEC-104) Cryptanalysis(CAPEC-97) Cryptanalysis of Cellular Encryption(CAPEC-608) Cryptographic Issues - Generic(CWE-310) Cryptographic Operations are run Before Supporting Units are Ready(CWE-1279) Dangerous Signal Handler not Disabled During Sensitive Operations(CWE-432) Dangling Database Cursor ('Cursor Injection')(CWE-619) Data Access from Outside Expected Data Manager Component(CWE-1083) Data Access Operations Outside of Expected Data Manager Component(CWE-1057) Data Element Aggregating an Excessively Large Number of Non-Primitive Elements(CWE-1043) Data Element containing Pointer Item without Proper Copy Control Element(CWE-1098) Data Injected During Configuration(CAPEC-536) Data Interchange Protocol Manipulation(CAPEC-277) Data Resource Access without Use of Connection Pooling(CWE-1072) Data Serialization External Entities Blowup(CAPEC-221) Dead Code(CWE-561) Deadlock(CWE-833) Debug Messages Revealing Unnecessary Information(CWE-1295) Declaration of Catch for Generic Exception(CWE-396) Declaration of Throws for Generic Exception(CWE-397) Declaration of Variable with Unnecessarily Wide Scope(CWE-1126) Deletion of Data Structure Sentinel(CWE-463) Dependency on Vulnerable Third-Party Component(CWE-1395) Deployment of Wrong Handler(CWE-430) DEPRECATED: Abuse of Transaction Data Structure(CAPEC-257) DEPRECATED: Apple '.DS_Store'(CWE-71) DEPRECATED: Authentication Bypass Issues(CWE-592) DEPRECATED: Bypassing Card or Badge-Based Systems(CAPEC-396) DEPRECATED: Catching exception throw/signal from privileged block(CAPEC-236) DEPRECATED: Code Injection(CAPEC-241) DEPRECATED: Containment Errors (Container Errors)(CWE-216) DEPRECATED: Covert Timing Channel(CWE-516) DEPRECATED: Degradation(CAPEC-602) DEPRECATED: Directory Traversal(CAPEC-213) DEPRECATED: DTD Injection in a SOAP Message(CAPEC-254) DEPRECATED: Dump Password Hashes(CAPEC-566) DEPRECATED: Environment Variable Manipulation(CAPEC-264) DEPRECATED: Failure to Protect Stored Data from Modification(CWE-217) DEPRECATED: Failure to provide confidentiality for stored data(CWE-218) DEPRECATED: Fuzzing for garnering J2EE/.NET-based stack traces, for application mapping(CAPEC-214) DEPRECATED: General Information Management Problems(CWE-225) DEPRECATED: Global variable manipulation(CAPEC-265) DEPRECATED: HTTP response splitting(CWE-443) DEPRECATED: ICMP Echo Request Ping(CAPEC-288) DEPRECATED: ICMP Fingerprinting Probes(CAPEC-316) DEPRECATED: Implementing a callback to system routine (old AWT Queue)(CAPEC-235) DEPRECATED: Improper Sanitization of Custom Special Characters(CWE-92) DEPRECATED: Incorrect Initialization(CWE-458) DEPRECATED: Incorrect Semantic Object Comparison(CWE-596) DEPRECATED: Information Exposure Through Cleanup Log Files(CWE-542) DEPRECATED: Information Exposure Through Debug Log Files(CWE-534) DEPRECATED: Information Exposure Through Server Log Files(CWE-533) DEPRECATED: Information Gathering from Non-Traditional Sources(CAPEC-409) DEPRECATED: Information Gathering from Traditional Sources(CAPEC-408) DEPRECATED: Infrastructure-based footprinting(CAPEC-289) DEPRECATED: IP Fingerprinting Probes(CAPEC-314) DEPRECATED: Leveraging web tools (e.g. Mozilla's GreaseMonkey, Firebug) to change application behavior(CAPEC-211) DEPRECATED: Lifting credential(s)/key material embedded in client distributions (thick or thin)(CAPEC-205) DEPRECATED: Linux Terminal Injection(CAPEC-249) DEPRECATED: Malicious Logic Insertion via Counterfeit Hardware(CAPEC-453) DEPRECATED: Malicious Logic Insertion via Inclusion of Counterfeit Hardware Components(CAPEC-455) DEPRECATED: Malware Propagation via Infected Peripheral Device(CAPEC-451) DEPRECATED: Malware Propagation via USB Stick(CAPEC-449) DEPRECATED: Malware Propagation via USB U3 Autorun(CAPEC-450) DEPRECATED: Manipulate Canonicalization(CAPEC-266) DEPRECATED: Miscalculated Null Termination(CWE-132) DEPRECATED: Modification of Existing Components with Counterfeit Hardware(CAPEC-454) DEPRECATED: Obtain Data via Utilities(CAPEC-567) DEPRECATED: Often Misused: Path Manipulation(CWE-249) DEPRECATED: OS Fingerprinting(CAPEC-311) DEPRECATED: Passively Sniffing and Capturing Application Code Bound for an Authorized Client During Dynamic Update(CAPEC-258) DEPRECATED: Passively Sniffing and Capturing Application Code Bound for an Authorized Client During Initial Distribution(CAPEC-260) DEPRECATED: Passively Sniffing and Capturing Application Code Bound for an Authorized Client During Patching(CAPEC-259) DEPRECATED: Pretexting(CAPEC-411) DEPRECATED: Proxied Trusted Channel(CWE-423) DEPRECATED: Race Condition in Switch(CWE-365) DEPRECATED: Registry Manipulation(CAPEC-269) DEPRECATED: Reliance on DNS Lookups in a Security Decision(CWE-247) DEPRECATED: Removing/short-circuiting 'guard logic'(CAPEC-56) DEPRECATED: Schedule Software To Run(CAPEC-557) DEPRECATED: Signature-Based Avoidance(CAPEC-570) DEPRECATED: SOAP Parameter Tampering(CAPEC-280) DEPRECATED: Social Information Gathering Attacks(CAPEC-404) DEPRECATED: Social Information Gathering via Research(CAPEC-405) DEPRECATED: State Synchronization Error(CWE-373) DEPRECATED: Subversion of Authorization Checks: Cache Filtering, Programmatic Security, etc.(CAPEC-239) DEPRECATED: Target Influence via Micro-Expressions(CAPEC-430) DEPRECATED: Target Influence via Neuro-Linguistic Programming (NLP)(CAPEC-431) DEPRECATED: Target Influence via Perception of Concession(CAPEC-419) DEPRECATED: Target Influence via Voice in NLP(CAPEC-432) DEPRECATED: TCP/IP Fingerprinting Probes(CAPEC-315) DEPRECATED: Trusting Self-reported DNS Name(CWE-292) DEPRECATED: Uncontrolled File Descriptor Consumption(CWE-769) DEPRECATED: Use of Dynamic Class Loading(CWE-545) DEPRECATED: Use of Uninitialized Resource(CWE-1187) DEPRECATED: Using URL/codebase / G.A.C. (code source) to convince sandbox of privilege(CAPEC-238) DEPRECATED: Variable Manipulation(CAPEC-171) DEPRECATED: Violating Implicit Assumptions Regarding XML Content (aka XML Denial of Service (XDoS))(CAPEC-82) DEPRECATED: XML Client-Side Attack(CAPEC-484) DEPRECATED: XML Parser Attack(CAPEC-99) DEPRECATED: XSS in IMG Tags(CAPEC-91) DEPRECATED: XSS through Log Files(CAPEC-106) DEPRECATED: XSS Using Flash(CAPEC-246) Deserialization of Untrusted Data(CWE-502) Design Alteration(CAPEC-447) Design for FPGA Maliciously Altered(CAPEC-674) Detection of Error Condition Without Action(CWE-390) Detect Unpublicized Web Pages(CAPEC-143) Detect Unpublicized Web Services(CAPEC-144) Developer Signing Maliciously Altered Software(CAPEC-673) Development Alteration(CAPEC-444) Device Unlock Credential Sharing(CWE-1273) DHCP Spoofing(CAPEC-697) Dictionary-based Password Attack(CAPEC-16) Directory Indexing(CAPEC-127) Direct Use of Unsafe JNI(CWE-111) Disable Security Software(CAPEC-578) Disabling Network Hardware(CAPEC-583) Divide By Zero(CWE-369) DLL Side-Loading(CAPEC-641) DMA Device Enabled Too Early in Boot Phase(CWE-1190) DNS Blocking(CAPEC-589) DNS Cache Poisoning(CAPEC-142) DNS Domain Seizure(CAPEC-585) DNS Rebinding(CAPEC-275) DNS Spoofing(CAPEC-598) DNS Zone Transfers(CAPEC-291) Documentation Alteration to Cause Errors in System Design(CAPEC-519) Documentation Alteration to Circumvent Dial-down(CAPEC-517) Documentation Alteration to Produce Under-performing Systems(CAPEC-518) DOM-Based XSS(CAPEC-588) Double-Checked Locking(CWE-609) Doubled Character XSS Manipulations(CWE-85) Double Decoding of the Same Data(CWE-174) Double Encoding(CAPEC-120) Double Free(CWE-415) Download of Code Without Integrity Check(CWE-494) Driving Intermediate Cryptographic State/Results to Hardware Module Outputs(CWE-1431) Drop Encryption Level(CAPEC-620) DTD Injection(CAPEC-228) Dumpster Diving(CAPEC-406) Duplicate Key in Associative List (Alist)(CWE-462) Dynamic Variable Evaluation(CWE-627) Eavesdropping(CAPEC-651) Eavesdropping on a Monitor(CAPEC-699) EJB Bad Practices: Use of AWT Swing(CWE-575) EJB Bad Practices: Use of Class Loader(CWE-578) EJB Bad Practices: Use of Java I/O(CWE-576) EJB Bad Practices: Use of Sockets(CWE-577) EJB Bad Practices: Use of Synchronization Primitives(CWE-574) Electromagnetic Side-Channel Attack(CAPEC-622) Email Injection(CAPEC-134) Embedded Malicious Code(CWE-506) Embedding NULL Bytes(CAPEC-52) Embedding Scripts within Scripts(CAPEC-19) Embed Virus into DLL(CAPEC-448) Empty Code Block(CWE-1071) Empty Exception Block(CWE-1069) Empty Password in Configuration File(CWE-258) Empty Synchronized Block(CWE-585) Encoding Error(CWE-172) Encryption Brute Forcing(CAPEC-20) Enumerate Mail Exchange (MX) Records(CAPEC-290) Escaping a Sandbox by Calling Code in Another Language(CAPEC-237) Escaping Virtualization(CAPEC-480) Establish Rogue Location(CAPEC-616) Evercookie(CAPEC-464) Evil Twin Wi-Fi Attack(CAPEC-615) Excavation(CAPEC-116) Excessive Allocation(CAPEC-130) Excessive Attack Surface(CWE-1125) Excessive Code Complexity(CWE-1120) Excessive Data Query Operations in a Large Data Table(CWE-1049) Excessive Execution of Sequential Searches of Data Resource(CWE-1067) Excessive Halstead Complexity(CWE-1122) Excessive Index Range Scan for a Data Resource(CWE-1094) Excessive Iteration(CWE-834) Excessively Complex Data Representation(CWE-1093) Excessively Deep Nesting(CWE-1124) Excessive McCabe Cyclomatic Complexity(CWE-1121) Excessive Number of Inefficient Server-Side Data Accesses(CWE-1060) Excessive Platform Resource Consumption within a Loop(CWE-1050) Excessive Reliance on Global Variables(CWE-1108) Excessive Use of Hard-Coded Literals in Initialization(CWE-1052) Excessive Use of Self-Modifying Code(CWE-1123) Excessive Use of Unconditional Branching(CWE-1119) Executable Regular Expression Error(CWE-624) Execution After Redirect (EAR)(CWE-698) Execution with Unnecessary Privileges(CWE-250) Expanding Control over the Operating System from the Database(CAPEC-470) Expected Behavior Violation(CWE-440) Expired Pointer Dereference(CWE-825) Explicit Call to Finalize()(CWE-586) Exploitation of Firmware or ROM Code with Unpatchable Vulnerabilities(CAPEC-682) Exploitation of Improperly Configured or Implemented Memory Protections(CAPEC-679) Exploitation of Improperly Controlled Hardware Security Identifiers(CAPEC-681) Exploitation of Improperly Controlled Registers(CAPEC-680) Exploitation of Thunderbolt Protection Flaws(CAPEC-665) Exploitation of Transient Instruction Execution(CAPEC-663) Exploitation of Trusted Identifiers(CAPEC-21) Exploiting Incorrect Chaining or Granularity of Hardware Debug Components(CAPEC-702) Exploiting Incorrectly Configured Access Control Security Levels(CAPEC-180) Exploiting Incorrectly Configured SSL/TLS(CAPEC-217) Exploiting Multiple Input Interpretation Layers(CAPEC-43) Exploiting Trust in Client(CAPEC-22) Exploit Non-Production Interfaces(CAPEC-121) Exploit Script-Based APIs(CAPEC-160) Explore for Predictable Temporary File Names(CAPEC-149) Exponential Data Expansion(CAPEC-197) Exposed Dangerous Method or Function(CWE-749) Exposed IOCTL with Insufficient Access Control(CWE-782) Exposed Unsafe ActiveX Method(CWE-618) Exposure of Access Control List Files to an Unauthorized Control Sphere(CWE-529) Exposure of Backup File to an Unauthorized Control Sphere(CWE-530) Exposure of Core Dump File to an Unauthorized Control Sphere(CWE-528) Exposure of Data Element to Wrong Session(CWE-488) Exposure of File Descriptor to Unintended Control Sphere ('File Descriptor Leak')(CWE-403) Exposure of Information Through Shell Error Message(CWE-535) Exposure of Resource to Wrong Sphere(CWE-668) Exposure of Sensitive Information caused by Incorrect Data Forwarding during Transient Execution(CWE-1422) Exposure of Sensitive Information caused by Shared Microarchitectural Predictor State that Influences Transient Execution(CWE-1423) Exposure of Sensitive Information Due to Incompatible Policies(CWE-213) Exposure of Sensitive Information during Transient Execution(CWE-1420) Exposure of Sensitive Information in Shared Microarchitectural Structures during Transient Execution(CWE-1421) Exposure of Sensitive Information Through Data Queries(CWE-202) Exposure of Sensitive Information Through Environmental Variables(CWE-526) Exposure of Sensitive Information Through Metadata(CWE-1230) Exposure of Sensitive System Information Due to Uncleared Debug Information(CWE-1258) Exposure of Sensitive System Information to an Unauthorized Control Sphere(CWE-497) Exposure of Version-Control Repository to an Unauthorized Control Sphere(CWE-527) Exposure of WSDL File Containing Sensitive Information(CWE-651) Expression is Always False(CWE-570) Expression is Always True(CWE-571) External Control of Assumed-Immutable Web Parameter(CWE-472) External Control of Critical State Data(CWE-642) External Control of File Name or Path(CWE-73) External Control of System or Configuration Setting(CWE-15) External Influence of Sphere Definition(CWE-673) External Initialization of Trusted Variables or Data Stores(CWE-454) Externally Controlled Reference to a Resource in Another Sphere(CWE-610) Externally-Generated Error Message Containing Sensitive Information(CWE-211) Fabric-Address Map Allows Programming of Unwarranted Overlaps of Protected and Unprotected Ranges(CWE-1316) Failure to Disable Reserved Bits(CWE-1209) Failure to Handle Incomplete Element(CWE-239) Failure to Handle Missing Parameter(CWE-234) Failure to Sanitize Paired Delimiters(CWE-157) Failure to Sanitize Special Elements into a Different Plane (Special Element Injection)(CWE-75) Fake the Source of Data(CAPEC-194) File and Directory Information Exposure(CWE-538) File Content Injection(CAPEC-23) File Discovery(CAPEC-497) File Manipulation(CAPEC-165) Files or Directories Accessible to External Parties(CWE-552) Filter Failure through Buffer Overflow(CAPEC-24) finalize() Method Declared Public(CWE-583) finalize() Method Without super.finalize()(CWE-568) Fingerprinting(CAPEC-224) Firmware Not Updateable(CWE-1277) Flash File Overlay(CAPEC-181) Flash Injection(CAPEC-182) Flash Memory Attacks(CAPEC-458) Flash Parameter Injection(CAPEC-174) Floating Point Comparison with Incorrect Operator(CWE-1077) Flooding(CAPEC-125) Footprinting(CAPEC-169) Forced Browsing(CWE-425) Forced Deadlock(CAPEC-25) Forced Integer Overflow(CAPEC-92) Forceful Browsing(CAPEC-87) Force the System to Reset Values(CAPEC-166) Force Use of Corrupted Files(CAPEC-263) Format String Injection(CAPEC-135) Free of Memory not on the Heap(CWE-590) Free of Pointer not at Start of Buffer(CWE-761) Functionality Bypass(CAPEC-554) Functionality Misuse(CAPEC-212) Function Call With Incorrect Argument Type(CWE-686) Function Call with Incorrectly Specified Arguments(CWE-628) Function Call With Incorrectly Specified Argument Value(CWE-687) Function Call With Incorrect Number of Arguments(CWE-685) Function Call With Incorrect Order of Arguments(CWE-683) Function Call With Incorrect Variable or Reference as Argument(CWE-688) Fuzzing(CAPEC-28) Fuzzing for application mapping(CAPEC-215) Fuzzing for garnering other adjacent user/sensitive data(CAPEC-261) Generation of Incorrect Security Tokens(CWE-1270) Generation of Predictable IV with CBC Mode(CWE-329) Generation of Predictable Numbers or Identifiers(CWE-340) Generation of Weak Initialization Vector (IV)(CWE-1204) Generic Cross-Browser Cross-Domain Theft(CAPEC-468) Group Permission Footprinting(CAPEC-576) Guessable CAPTCHA(CWE-804) Hardware Allows Activation of Test or Debug Logic at Runtime(CWE-1313) Hardware Child Block Incorrectly Connected to Parent System(CWE-1276) Hardware Component Substitution(CAPEC-531) Hardware Component Substitution During Baselining(CAPEC-516) Hardware Design Specifications Are Altered(CAPEC-521) Hardware Fault Injection(CAPEC-624) Hardware Integrity Attack(CAPEC-440) Hardware Internal or Debug Modes Allow Override of Locks(CWE-1234) Hardware Logic Contains Race Conditions(CWE-1298) Hardware Logic with Insecure De-Synchronization between Control and Data Channels(CWE-1264) Harvesting Information via API Event Monitoring(CAPEC-383) Heap Overflow(CWE-122) Hidden Functionality(CWE-912) Hiding Malicious Data or Code within Files(CAPEC-636) Hijacking a privileged process(CAPEC-234) Hijacking a Privileged Thread of Execution(CAPEC-30) Homograph Attack via Homoglyphs(CAPEC-632) Host Discovery(CAPEC-292) HTTP DoS(CAPEC-469) HTTP Flood(CAPEC-488) HTTP Parameter Pollution (HPP)(CAPEC-460) HTTP Request Smuggling(CWE-444) HTTP Request Smuggling(CAPEC-33) HTTP Request Splitting(CAPEC-105) HTTP Response Smuggling(CAPEC-273) HTTP Response Splitting(CWE-113) HTTP Response Splitting(CAPEC-34) HTTP Verb Tampering(CAPEC-274) ICMP Address Mask Request(CAPEC-294) ICMP Echo Request Ping(CAPEC-285) ICMP Error Message Echoing Integrity Probe(CAPEC-330) ICMP Error Message Quoting Probe(CAPEC-329) ICMP Flood(CAPEC-487) ICMP Fragmentation(CAPEC-496) ICMP Information Request(CAPEC-296) ICMP IP 'ID' Field Error Message Probe(CAPEC-332) ICMP IP Total Length Field Probe(CAPEC-331) Identify Shared Files/Directories on System(CAPEC-643) Identity Spoofing(CAPEC-151) iFrame Overlay(CAPEC-222) IMAP/SMTP Command Injection(CAPEC-183) Improper Access Control Applied to Mirrored or Aliased Memory Regions(CWE-1257) Improper Access Control for Register Interface(CWE-1262) Improper Access Control for Volatile Memory Containing Boot Code(CWE-1274) Improper Access Control - Generic(CWE-284) Improper Address Validation in IOCTL with METHOD_NEITHER I/O Control Code(CWE-781) Improper Adherence to Coding Standards(CWE-710) Improper Authentication - Generic(CWE-287) Improper Authorization(CWE-285) Improper Authorization in Handler for Custom URL Scheme(CWE-939) Improper Authorization of Index Containing Sensitive Information(CWE-612) Improper Certificate Validation(CWE-295) Improper Check for Certificate Revocation(CWE-299) Improper Check for Dropped Privileges(CWE-273) Improper Check for Unusual or Exceptional Conditions(CWE-754) Improper Check or Handling of Exceptional Conditions(CWE-703) Improper Cleanup on Thrown Exception(CWE-460) Improper Clearing of Heap Memory Before Release ('Heap Inspection')(CWE-244) Improper Control of a Resource Through its Lifetime(CWE-664) Improper Control of Document Type Definition(CWE-827) Improper Control of Dynamically-Identified Variables(CWE-914) Improper Control of Dynamically-Managed Code Resources(CWE-913) Improper Control of Interaction Frequency(CWE-799) Improper Encoding or Escaping of Output(CWE-116) Improper Enforcement of a Single, Unique Action(CWE-837) Improper Enforcement of Behavioral Workflow(CWE-841) Improper Enforcement of Message Integrity During Transmission in a Communication Channel(CWE-924) Improper Export of Android Application Components(CWE-926) Improper Filtering of Special Elements(CWE-790) Improper Finite State Machines (FSMs) in Hardware Logic(CWE-1245) Improper Following of a Certificate's Chain of Trust(CWE-296) Improper Following of Specification by Caller(CWE-573) Improper Handling of Additional Special Element(CWE-167) Improper Handling of Alternate Encoding(CWE-173) Improper Handling of Apple HFS+ Alternate Data Stream Path(CWE-72) Improper Handling of Case Sensitivity(CWE-178) Improper Handling of Exceptional Conditions(CWE-755) Improper Handling of Extra Parameters(CWE-235) Improper Handling of Extra Values(CWE-231) Improper Handling of Faults that Lead to Instruction Skips(CWE-1332) Improper Handling of File Names that Identify Virtual Resources(CWE-66) Improper Handling of Hardware Behavior in Exceptionally Cold Environments(CWE-1351) Improper Handling of Highly Compressed Data (Data Amplification)(CWE-409) Improper Handling of Incomplete Structural Elements(CWE-238) Improper Handling of Inconsistent Special Elements(CWE-168) Improper Handling of Inconsistent Structural Elements(CWE-240) Improper Handling of Insufficient Entropy in TRNG(CWE-333) Improper Handling of Insufficient Permissions or Privileges(CWE-280) Improper Handling of Insufficient Privileges(CWE-274) Improper Handling of Invalid Use of Special Elements(CWE-159) Improper Handling of Length Parameter Inconsistency(CWE-130) Improper Handling of Missing Special Element(CWE-166) Improper Handling of Missing Values(CWE-230) Improper Handling of Mixed Encoding(CWE-175) Improper Handling of Overlap Between Protected Memory Ranges(CWE-1260) Improper Handling of Parameters(CWE-233) Improper Handling of Physical or Environmental Conditions(CWE-1384) Improper Handling of Single Event Upsets(CWE-1261) Improper Handling of Structural Elements(CWE-237) Improper Handling of Syntactically Invalid Structure(CWE-228) Improper Handling of Undefined Parameters(CWE-236) Improper Handling of Undefined Values(CWE-232) Improper Handling of Unexpected Data Type(CWE-241) Improper Handling of Unicode Encoding(CWE-176) Improper Handling of URL Encoding (Hex Encoding)(CWE-177) Improper Handling of Values(CWE-229) Improper Handling of Windows ::DATA Alternate Data Stream(CWE-69) Improper Handling of Windows Device Names(CWE-67) Improper Initialization(CWE-665) Improper Input Validation(CWE-20) Improper Interaction Between Multiple Correctly-Behaving Entities(CWE-435) Improper Isolation of Shared Resources in Network On Chip (NoC)(CWE-1331) Improper Isolation of Shared Resources on System-on-a-Chip (SoC)(CWE-1189) Improper Isolation or Compartmentalization(CWE-653) Improper Link Resolution Before File Access ('Link Following')(CWE-59) Improper Lock Behavior After Power State Transition(CWE-1232) Improper Locking(CWE-667) Improperly Controlled Modification of Dynamically-Determined Object Attributes(CWE-915) Improperly Controlled Modification of Object Prototype Attributes ('Prototype Pollution')(CWE-1321) Improperly Controlled Sequential Memory Allocation(CWE-1325) Improperly Implemented Security Check for Standard(CWE-358) Improperly Preserved Integrity of Hardware Configuration State During a Power Save/Restore Operation(CWE-1304) Improper Management of Sensitive Trace Data(CWE-1323) Improper Neutralization(CWE-707) Improper Neutralization of Alternate XSS Syntax(CWE-87) Improper Neutralization of Argument Delimiters in a Command ('Argument Injection')(CWE-88) Improper Neutralization of Comment Delimiters(CWE-151) Improper Neutralization of Data within XPath Expressions ('XPath Injection')(CWE-643) Improper Neutralization of Data within XQuery Expressions ('XQuery Injection')(CWE-652) Improper Neutralization of Delimiters(CWE-140) Improper Neutralization of Directives in Dynamically Evaluated Code ('Eval Injection')(CWE-95) Improper Neutralization of Directives in Statically Saved Code ('Static Code Injection')(CWE-96) Improper Neutralization of Encoded URI Schemes in a Web Page(CWE-84) Improper Neutralization of Equivalent Special Elements(CWE-76) Improper Neutralization of Escape, Meta, or Control Sequences(CWE-150) Improper Neutralization of Expression/Command Delimiters(CWE-146) Improper Neutralization of Formula Elements in a CSV File(CWE-1236) Improper Neutralization of HTTP Headers for Scripting Syntax(CWE-644) Improper Neutralization of Input Leaders(CWE-148) Improper Neutralization of Input Terminators(CWE-147) Improper Neutralization of Input Used for LLM Prompting(CWE-1427) Improper Neutralization of Internal Special Elements(CWE-164) Improper Neutralization of Invalid Characters in Identifiers in Web Pages(CWE-86) Improper Neutralization of Leading Special Elements(CWE-160) Improper Neutralization of Line Delimiters(CWE-144) Improper Neutralization of Macro Symbols(CWE-152) Improper Neutralization of Multiple Internal Special Elements(CWE-165) Improper Neutralization of Multiple Leading Special Elements(CWE-161) Improper Neutralization of Multiple Trailing Special Elements(CWE-163) Improper Neutralization of Null Byte or NUL Character(CWE-158) Improper Neutralization of Parameter/Argument Delimiters(CWE-141) Improper Neutralization of Quoting Syntax(CWE-149) Improper Neutralization of Record Delimiters(CWE-143) Improper Neutralization of Script in an Error Message Web Page(CWE-81) Improper Neutralization of Script in Attributes in a Web Page(CWE-83) Improper Neutralization of Script in Attributes of IMG Tags in a Web Page(CWE-82) Improper Neutralization of Script-Related HTML Tags in a Web Page (Basic XSS)(CWE-80) Improper Neutralization of Section Delimiters(CWE-145) Improper Neutralization of Server-Side Includes (SSI) Within a Web Page(CWE-97) Improper Neutralization of Special Elements(CWE-138) Improper Neutralization of Special Elements in Data Query Logic(CWE-943) Improper Neutralization of Special Elements in Output Used by a Downstream Component ('Injection')(CWE-74) Improper Neutralization of Special Elements used in an Expression Language Statement ('Expression Language Injection')(CWE-917) Improper Neutralization of Special Elements Used in a Template Engine(CWE-1336) Improper Neutralization of Substitution Characters(CWE-153) Improper Neutralization of Trailing Special Elements(CWE-162) Improper Neutralization of Value Delimiters(CWE-142) Improper Neutralization of Variable Name Delimiters(CWE-154) Improper Neutralization of Whitespace(CWE-156) Improper Neutralization of Wildcards or Matching Symbols(CWE-155) Improper Null Termination(CWE-170) Improper Output Neutralization for Logs(CWE-117) Improper Ownership Management(CWE-282) Improper Physical Access Control(CWE-1263) Improper Preservation of Consistency Between Independent Representations of Shared State(CWE-1250) Improper Preservation of Permissions(CWE-281) Improper Prevention of Lock Bit Modification(CWE-1231) Improper Privilege Management(CWE-269) Improper Protection against Electromagnetic Fault Injection (EM-FI)(CWE-1319) Improper Protection Against Voltage and Clock Glitches(CWE-1247) Improper Protection for Out of Bounds Signal Level Alerts(CWE-1320) Improper Protection of Alternate Path(CWE-424) Improper Protection of Physical Side Channels(CWE-1300) Improper Protections Against Hardware Overheating(CWE-1338) Improper Removal of Sensitive Information Before Storage or Transfer(CWE-212) Improper Resolution of Path Equivalence(CWE-41) Improper Resource Locking(CWE-413) Improper Resource Shutdown or Release(CWE-404) Improper Restriction of Authentication Attempts(CWE-307) Improper Restriction of Communication Channel to Intended Endpoints(CWE-923) Improper Restriction of Names for Files and Other Resources(CWE-641) Improper Restriction of Power Consumption(CWE-920) Improper Restriction of Rendered UI Layers or Frames(CWE-1021) Improper Restriction of Security Token Assignment(CWE-1259) Improper Restriction of Software Interfaces to Hardware Features(CWE-1256) Improper Restriction of Write-Once Bit Fields(CWE-1224) Improper Scrubbing of Sensitive Data from Decommissioned Device(CWE-1266) Improper Setting of Bus Controlling Capability in Fabric End-point(CWE-1315) Improper Synchronization(CWE-662) Improper Translation of Security Attributes by Fabric Bridge(CWE-1311) Improper Update of Reference Count(CWE-911) Improper Use of Validation Framework(CWE-1173) Improper Validation of Certificate Expiration(CWE-298) Improper Validation of Certificate with Host Mismatch(CWE-297) Improper Validation of Consistency within Input(CWE-1288) Improper Validation of Function Hook Arguments(CWE-622) Improper Validation of Generative AI Output(CWE-1426) Improper Validation of Integrity Check Value(CWE-354) Improper Validation of Specified Index, Position, or Offset in Input(CWE-1285) Improper Validation of Specified Quantity in Input(CWE-1284) Improper Validation of Specified Type of Input(CWE-1287) Improper Validation of Syntactic Correctness of Input(CWE-1286) Improper Validation of Unsafe Equivalence in Input(CWE-1289) Improper Verification of Cryptographic Signature(CWE-347) Improper Verification of Intent by Broadcast Receiver(CWE-925) Improper Verification of Source of a Communication Channel(CWE-940) Improper Write Handling in Limited-write Non-Volatile Memories(CWE-1246) Improper Zeroization of Hardware Register(CWE-1239) Inaccurate Comments(CWE-1116) Inadequate Encryption Strength(CWE-326) Inappropriate Comment Style(CWE-1113) Inappropriate Encoding for Output Context(CWE-838) Inappropriate Source Code Style or Formatting(CWE-1078) Inappropriate Whitespace Style(CWE-1114) Inclusion of Code in Existing Process(CAPEC-640) Inclusion of Functionality from Untrusted Control Sphere(CWE-829) Inclusion of Sensitive Information in an Include File(CWE-541) Inclusion of Sensitive Information in Source Code(CWE-540) Inclusion of Sensitive Information in Source Code Comments(CWE-615) Inclusion of Sensitive Information in Test Code(CWE-531) Inclusion of Undocumented Features or Chicken Bits(CWE-1242) Inclusion of Web Functionality from an Untrusted Source(CWE-830) Incomplete Blacklist(CWE-184) Incomplete Cleanup(CWE-459) Incomplete Comparison with Missing Factors(CWE-1023) Incomplete Data Deletion in a Multi-Tenant Environment(CAPEC-546) Incomplete Denylist to Cross-Site Scripting(CWE-692) Incomplete Design Documentation(CWE-1110) Incomplete Documentation of Program Execution(CWE-1112) Incomplete Filtering of Multiple Instances of Special Elements(CWE-794) Incomplete Filtering of One or More Instances of Special Elements(CWE-792) Incomplete Filtering of Special Elements(CWE-791) Incomplete Identification of Uploaded File Variables (PHP)(CWE-616) Incomplete Internal State Distinction(CWE-372) Incomplete I/O Documentation(CWE-1111) Incomplete Model of Endpoint Features(CWE-437) Inconsistency Between Implementation and Documented Design(CWE-1068) Inconsistent Naming Conventions for Identifiers(CWE-1099) Incorrect Access of Indexable Resource ('Range Error')(CWE-118) Incorrect Authorization(CWE-863) Incorrect Behavior Order(CWE-696) Incorrect Behavior Order: Authorization Before Parsing and Canonicalization(CWE-551) Incorrect Behavior Order: Early Amplification(CWE-408) Incorrect Behavior Order: Early Validation(CWE-179) Incorrect Behavior Order: Validate Before Canonicalize(CWE-180) Incorrect Behavior Order: Validate Before Filter(CWE-181) Incorrect Bitwise Shift of Integer(CWE-1335) Incorrect Block Delimitation(CWE-483) Incorrect Calculation(CWE-682) Incorrect Calculation of Buffer Size(CWE-131) Incorrect Calculation of Multi-Byte String Length(CWE-135) Incorrect Chaining or Granularity of Debug Components(CWE-1296) Incorrect Check of Function Return Value(CWE-253) Incorrect Comparison(CWE-697) Incorrect Comparison Logic Granularity(CWE-1254) Incorrect Control Flow Scoping(CWE-705) Incorrect Conversion between Numeric Types(CWE-681) Incorrect Conversion of Security Identifiers(CWE-1292) Incorrect Decoding of Security Identifiers (CWE-1290) Incorrect Default Permissions(CWE-276) Incorrect Execution-Assigned Permissions(CWE-279) Incorrect Implementation of Authentication Algorithm(CWE-303) Incorrect Initialization of Resource(CWE-1419) Incorrectly Specified Destination in a Communication Channel(CWE-941) Incorrect Ownership Assignment(CWE-708) Incorrect Parsing of Numbers with Different Radices(CWE-1389) Incorrect Permission Assignment for Critical Resource(CWE-732) Incorrect Pointer Scaling(CWE-468) Incorrect Privilege Assignment(CWE-266) Incorrect Provision of Specified Functionality(CWE-684) Incorrect Register Defaults or Module Parameters(CWE-1221) Incorrect Regular Expression(CWE-185) Incorrect Resource Transfer Between Spheres(CWE-669) Incorrect Selection of Fuse Values(CWE-1253) Incorrect Short Circuit Evaluation(CWE-768) Incorrect Synchronization(CWE-821) Incorrect Type Conversion or Cast(CWE-704) Incorrect Usage of Seeds in Pseudo-Random Number Generator (PRNG)(CWE-335) Incorrect Use of Autoboxing and Unboxing for Performance Critical Operations(CWE-1235) Incorrect Use of Privileged APIs(CWE-648) Incorrect User Management(CWE-286) Inducing Account Lockout(CAPEC-2) Inefficient Algorithmic Complexity(CWE-407) Inefficient CPU Computation(CWE-1176) Inefficient Regular Expression Complexity(CWE-1333) Infected Hardware(CAPEC-452) Infected Memory(CAPEC-456) Infected Software(CAPEC-442) Infiltration of Hardware Development Environment(CAPEC-537) Infiltration of Software Development Environment(CAPEC-511) Influence Perception(CAPEC-417) Influence Perception of Authority(CAPEC-421) Influence Perception of Commitment and Consistency(CAPEC-422) Influence Perception of Consensus or Social Proof(CAPEC-424) Influence Perception of Liking(CAPEC-423) Influence Perception of Reciprocation(CAPEC-418) Influence Perception of Scarcity(CAPEC-420) Influence via Incentives(CAPEC-426) Influence via Modes of Thinking(CAPEC-428) Influence via Psychological Principles(CAPEC-427) Information Disclosure(CWE-200) Information Elicitation(CAPEC-410) Information Exposure Through an Error Message(CWE-209) Information Exposure Through Debug Information(CWE-215) Information Exposure Through Directory Listing(CWE-548) Information Exposure Through Discrepancy(CWE-203) Information Exposure through Microarchitectural State after Transient Execution(CWE-1342) Information Exposure Through Sent Data(CWE-201) Information Exposure Through Timing Discrepancy(CWE-208) Information Loss or Omission(CWE-221) Infrastructure Manipulation(CAPEC-161) Initialization with Hard-Coded Network Resource Configuration Data(CWE-1051) Input Data Manipulation(CAPEC-153) Insecure Automated Optimizations(CWE-1038) Insecure Default Initialization of Resource(CWE-1188) Insecure Default Variable Initialization(CWE-453) Insecure Direct Object Reference (IDOR)(CWE-639) Insecure Inherited Permissions(CWE-277) Insecure Operation on Windows Junction / Mount Point(CWE-1386) Insecure Preserved Inherited Permissions(CWE-278) Insecure Security Identifier Mechanism(CWE-1294) Insecure Setting of Generative AI/ML Model Inference Parameters(CWE-1434) Insecure Storage of Sensitive Information(CWE-922) Insecure Temporary File(CWE-377) Insertion of Sensitive Information into Log File(CWE-532) Install Malicious Extension(CAPEC-698) Install New Service(CAPEC-550) Install Rootkit (CAPEC-552) Insufficient Adherence to Expected Conventions(CWE-1076) Insufficient Control Flow Management(CWE-691) Insufficient Control of Network Message Volume (Network Amplification)(CWE-406) Insufficient Documentation of Error Handling Techniques(CWE-1118) Insufficient Encapsulation(CWE-1061) Insufficient Encapsulation of Machine-Dependent Functionality(CWE-1105) Insufficient Entropy(CWE-331) Insufficient Entropy in PRNG(CWE-332) Insufficient Granularity of Access Control(CWE-1220) Insufficient Granularity of Address Regions Protected by Register Locks(CWE-1222) Insufficient Isolation of Symbolic Constant Definitions(CWE-1107) Insufficient Isolation of System-Dependent Functions(CWE-1100) Insufficient Logging(CWE-778) Insufficiently Protected Credentials(CWE-522) Insufficient or Incomplete Data Removal within Hardware Component(CWE-1301) Insufficient Precision or Accuracy of a Real Number(CWE-1339) Insufficient Psychological Acceptability(CWE-655) Insufficient Resource Pool(CWE-410) Insufficient Session Expiration(CWE-613) Insufficient Technical Documentation(CWE-1059) Insufficient Type Distinction(CWE-351) Insufficient UI Warning of Dangerous Operations(CWE-357) Insufficient Use of Symbolic Constants(CWE-1106) Insufficient Verification of Data Authenticity(CWE-345) Insufficient Visual Distinction of Homoglyphs Presented to User(CWE-1007) Integer Attacks(CAPEC-128) Integer Coercion Error(CWE-192) Integer Overflow(CWE-190) Integer Overflow to Buffer Overflow(CWE-680) Integer Underflow(CWE-191) Intent Spoof(CAPEC-502) Interception(CAPEC-117) Inter-component Protocol Manipulation(CAPEC-276) Interface Manipulation(CAPEC-113) Internal Asset Exposed to Unsafe Debug Access Level or State(CWE-1244) Interpretation Conflict(CWE-436) Invocation of a Control Element at an Unnecessarily Deep Horizontal Layer(CWE-1054) Invocation of Process Using Visible Sensitive Information(CWE-214) Invokable Control Element in Multi-Thread Context with non-Final Static Storable or Member Element(CWE-1058) Invokable Control Element with Excessive File or Data Access Operations(CWE-1084) Invokable Control Element with Excessive Volume of Commented-out Code(CWE-1085) Invokable Control Element with Large Number of Outward Calls(CWE-1048) Invokable Control Element with Signature Containing an Excessive Number of Parameters(CWE-1064) Invokable Control Element with Variadic Parameters(CWE-1056) IP Address Blocking(CAPEC-590) IP (DF) 'Don't Fragment Bit' Echoing Probe(CAPEC-319) IP 'ID' Echoed Byte-Order Probe(CAPEC-318) IP ID Sequencing Probe(CAPEC-317) Irrelevant Code(CWE-1164) J2EE Bad Practices: Direct Management of Connections(CWE-245) J2EE Bad Practices: Direct Use of Sockets(CWE-246) J2EE Bad Practices: Direct Use of Threads(CWE-383) J2EE Bad Practices: Non-serializable Object Stored in Session(CWE-579) J2EE Bad Practices: Use of System.exit()(CWE-382) J2EE Framework: Saving Unserializable Objects to Disk(CWE-594) J2EE Misconfiguration: Data Transmission Without Encryption(CWE-5) J2EE Misconfiguration: Entity Bean Declared Remote(CWE-8) J2EE Misconfiguration: Insufficient Session-ID Length(CWE-6) J2EE Misconfiguration: Missing Custom Error Page(CWE-7) J2EE Misconfiguration: Plaintext Password in Configuration File(CWE-555) J2EE Misconfiguration: Weak Access Permissions for EJB Methods(CWE-9) Jamming(CAPEC-601) Java Runtime Error Message Containing Sensitive Information(CWE-537) JSON Hijacking (aka JavaScript Hijacking)(CAPEC-111) Kerberoasting(CAPEC-509) Key Exchange without Entity Authentication(CWE-322) Key Negotiation of Bluetooth Attack (KNOB)(CAPEC-668) Lack of Administrator Control over Security(CWE-671) Lack of Binary Hardening Large Data Table with Excessive Number of Indices(CWE-1089) LDAP Injection(CAPEC-136) LDAP Injection(CWE-90) Least Privilege Violation(CWE-272) Leftover Debug Code (Backdoor)(CWE-489) Leverage Alternate Encoding(CAPEC-267) Leverage Executable Code in Non-Executable Files(CAPEC-35) Leveraging Active Adversary in the Middle Attacks to Bypass Same Origin Policy(CAPEC-466) Leveraging/Manipulating Configuration File Search Paths(CAPEC-38) Leveraging Race Conditions(CAPEC-26) Leveraging Race Conditions via Symbolic Links(CAPEC-27) Leveraging Time-of-Check and Time-of-Use (TOCTOU) Race Conditions(CAPEC-29) Lifting Sensitive Data Embedded in Cache(CAPEC-204) Load Value Injection(CAPEC-696) Local Code Inclusion(CAPEC-251) Lock Bumping(CAPEC-392) Lock Picking(CAPEC-393) Logging of Excessive Data(CWE-779) Logic/Time Bomb(CWE-511) Log Injection-Tampering-Forging(CAPEC-93) Loop Condition Value Update within the Loop(CWE-1095) Loop with Unreachable Exit Condition ('Infinite Loop')(CWE-835) Magnetic Strip Card Brute Force Attacks(CAPEC-398) Malicious Automated Software Update via Redirection(CAPEC-187) Malicious Automated Software Update via Spoofing(CAPEC-657) Malicious Code Implanted During Chip Programming(CAPEC-672) Malicious Gray Market Hardware(CAPEC-535) Malicious Hardware Component Replacement(CAPEC-522) Malicious Hardware Update(CAPEC-534) Malicious Logic Inserted Into Product Software by Authorized Developer(CAPEC-443) Malicious Logic Insertion(CAPEC-441) Malicious Logic Insertion into Product Software via Configuration Management Manipulation(CAPEC-445) Malicious Logic Insertion into Product Software via Inclusion of 3rd Party Component Dependency(CAPEC-446) Malicious Manual Software Update(CAPEC-533) Malicious Root Certificate(CAPEC-479) Malicious Software Download(CAPEC-185) Malicious Software Implanted(CAPEC-523) Malicious Software Update(CAPEC-186) Malware(CAPEC-549) Malware-Directed Internal Reconnaissance(CAPEC-529) Man-in-the-Middle(CWE-300) Manipulate Human Behavior(CAPEC-416) Manipulate Registry Information(CAPEC-203) Manipulating Hidden Fields(CAPEC-162) Manipulating Opaque Client-based Data Tokens(CAPEC-39) Manipulating State(CAPEC-74) Manipulating User-Controlled Variables(CAPEC-77) Manipulating Web Input to File System Calls(CAPEC-76) Manipulating Writeable Configuration Files(CAPEC-75) Manipulating Writeable Terminal Devices(CAPEC-40) Manipulation During Distribution(CAPEC-439) Memory Allocation with Excessive Size Value(CWE-789) Memory Corruption - Generic(CWE-119) Metadata Spoofing(CAPEC-690) Method Containing Access of a Member Element from Another Class(CWE-1090) MIME Conversion(CAPEC-42) Mirrored Regions with Different Values(CWE-1251) Misconfiguration(CWE-16) Misinterpretation of Input(CWE-115) Mismatched Memory Management Routines(CWE-762) Missing Ability to Patch ROM Code(CWE-1310) Missing Authentication for Critical Function(CWE-306) Missing Authorization(CWE-862) Missing Check for Certificate Revocation after Initial Check(CWE-370) Missing Critical Step in Authentication(CWE-304) Missing Custom Error Page(CWE-756) Missing Default Case in Switch Statement(CWE-478) Missing Documentation for Design(CWE-1053) Missing Encryption of Sensitive Data(CWE-311) Missing Handler(CWE-431) Missing Immutable Root of Trust in Hardware(CWE-1326) Missing Initialization of a Variable(CWE-456) Missing Initialization of Resource(CWE-909) Missing Lock Check(CWE-414) Missing Origin Validation in WebSockets(CWE-1385) Missing Password Field Masking(CWE-549) Missing Protection Against Hardware Reverse Engineering Using Integrated Circuit (IC) Imaging Techniques(CWE-1278) Missing Protection for Mirrored Regions in On-Chip Fabric Firewall(CWE-1312) Missing Protection Mechanism for Alternate Hardware Interface(CWE-1299) Missing Reference to Active Allocated Resource(CWE-771) Missing Reference to Active File Descriptor or Handle(CWE-773) Missing Release of File Descriptor or Handle after Effective Lifetime(CWE-775) Missing Release of Memory after Effective Lifetime(CWE-401) Missing Release of Resource after Effective Lifetime(CWE-772) Missing Report of Error Condition(CWE-392) Missing Required Cryptographic Step(CWE-325) Missing Security Checks in Fabric Bridge(CWE-1317) Missing Security Identifier(CWE-1302) Missing Security-Relevant Feedback for Unexecuted Operations in Hardware Interface(CWE-1429) Missing Serialization Control Element(CWE-1066) Missing Source Correlation of Multiple Independent Data(CWE-1293) Missing Standardized Error Handling Mechanism(CWE-544) Missing Support for Integrity Check(CWE-353) Missing Support for Security Features in On-chip Fabrics or Buses(CWE-1318) Missing Synchronization(CWE-820) Missing Validation of OpenSSL Certificate(CWE-599) Missing Write Protection for Parametric Data Values(CWE-1314) Missing XML Validation(CWE-112) Mobile Device Fault Injection(CAPEC-625) Mobile Phishing(CAPEC-164) Modification During Manufacture(CAPEC-438) Modification of Assumed-Immutable Data (MAID)(CWE-471) Modification of Registry Run Keys(CAPEC-270) Modification of Windows Service Configuration(CAPEC-478) Modify Existing Service(CAPEC-551) Modify Shared File(CAPEC-562) Modules with Circular Dependencies(CWE-1047) Multiple Binds to the Same Port(CWE-605) Multiple Inheritance from Concrete Classes(CWE-1055) Multiple Interpretations of UI Input(CWE-450) Multiple Locks of a Critical Resource(CWE-764) Multiple Operations on Resource in Single-Operation Context(CWE-675) Multiple Releases of Same Resource or Handle(CWE-1341) Multiple Unlocks of a Critical Resource(CWE-765) Mutable Attestation or Measurement Reporting Data(CWE-1283) Navigation Remapping To Propagate Malicious Content(CAPEC-387) .NET Misconfiguration: Use of Impersonation(CWE-520) Network Boundary Bridging(CAPEC-700) Network Topology Mapping(CAPEC-309) Non-exit on Failed Initialization(CWE-455) Non-Replicating Malicious Code(CWE-508) Non-SQL Invokable Control Element with Excessive Number of Data Resource Accesses(CWE-1073) Non-Transparent Sharing of Microarchitectural Resources(CWE-1303) NoSQL Injection(CAPEC-676) Not Failing Securely ('Failing Open')(CWE-636) Not Using Complete Mediation(CWE-638) Not Using Password Aging(CWE-262) Null Byte Interaction Error (Poison Null Byte)(CWE-626) NULL Pointer Dereference(CWE-476) Numeric Range Comparison Without Minimum Check(CWE-839) Numeric Truncation Error(CWE-197) Object Injection(CAPEC-586) Object Model Violation: Just One of Equals and Hashcode Defined(CWE-581) Object Relational Mapping Injection(CAPEC-109) Obscured Security-relevant Information by Alternate Name(CWE-224) Observable Behavioral Discrepancy(CWE-205) Observable Behavioral Discrepancy With Equivalent Products(CWE-207) Observable Internal Behavioral Discrepancy(CWE-206) Observable Response Discrepancy(CWE-204) Obsolete Feature in UI(CWE-448) Obstruction(CAPEC-607) Off-by-one Error(CWE-193) Omission of Security-relevant Information(CWE-223) Omitted Break Statement in Switch(CWE-484) On-Chip Debug and Test Interface With Improper Access Control(CWE-1191) Only Filtering One Instance of a Special Element(CWE-793) Only Filtering Special Elements at an Absolute Position(CWE-797) Only Filtering Special Elements at a Specified Location(CWE-795) Only Filtering Special Elements Relative to a Marker(CWE-796) Open Redirect(CWE-601) Open-Source Library Manipulation(CAPEC-538) Operation on a Resource after Expiration or Release(CWE-672) Operation on Resource in Wrong Phase of Lifetime(CWE-666) Operator Precedence Logic Error(CWE-783) Orbital Jamming(CAPEC-559) Origin Validation Error(CWE-346) OS Command Injection(CAPEC-88) OS Command Injection(CWE-78) Out-of-bounds Read(CWE-125) Out-of-bounds Write(CWE-787) Overflow Binary Resource File(CAPEC-44) Overflow Buffers(CAPEC-100) Overflow Variables and Tags(CAPEC-46) Overly Restrictive Account Lockout Mechanism(CWE-645) Overly Restrictive Regular Expression(CWE-186) Overread Buffers(CAPEC-540) Oversized Serialized Data Payloads(CAPEC-231) Owner Footprinting(CAPEC-577) Padding Oracle Crypto Attack(CAPEC-463) Parameter Injection(CAPEC-137) Parent Class with a Virtual Destructor and a Child Class without a Virtual Destructor(CWE-1045) Parent Class without Virtual Destructor Method(CWE-1079) Parent Class with References to Child Class(CWE-1062) Partial String Comparison(CWE-187) Passing Local Filenames to Functions That Expect a URL(CAPEC-48) Passing Mutable Objects to an Untrusted Method(CWE-374) Passive OS Fingerprinting(CAPEC-313) Password Aging with Long Expiration(CWE-263) Password Brute Forcing(CAPEC-49) Password in Configuration File(CWE-260) Password Recovery Exploitation(CAPEC-50) Password Spraying(CAPEC-565) Path Equivalence: 'fakedir/../realdir/filename'(CWE-57) Path Equivalence: 'filedir\' (Trailing Backslash)(CWE-54) Path Equivalence: 'filedir*' (Wildcard)(CWE-56) Path Equivalence: 'file.name' (Internal Dot)(CWE-44) Path Equivalence: 'file name' (Internal Whitespace)(CWE-48) Path Equivalence: ' filename' (Leading Space)(CWE-47) Path Equivalence: 'file...name' (Multiple Internal Dot)(CWE-45) Path Equivalence: 'filename....' (Multiple Trailing Dot)(CWE-43) Path Equivalence: 'filename.' (Trailing Dot)(CWE-42) Path Equivalence: 'filename/' (Trailing Slash)(CWE-49) Path Equivalence: 'filename ' (Trailing Space)(CWE-46) Path Equivalence: '\multiple\\internal\backslash'(CWE-53) Path Equivalence: '/multiple//internal/slash'(CWE-51) Path Equivalence: '//multiple/leading/slash'(CWE-50) Path Equivalence: '/multiple/trailing/slash//'(CWE-52) Path Equivalence: '/./' (Single Dot Directory)(CWE-55) Path Equivalence: Windows 8.3 Filename(CWE-58) Path Traversal(CAPEC-126) Path Traversal(CWE-22) Path Traversal: '.../...//'(CWE-35) Path Traversal: '....//'(CWE-34) Path Traversal: '/absolute/pathname/here'(CWE-37) Path Traversal: '\absolute\pathname\here'(CWE-38) Path Traversal: 'C:dirname'(CWE-39) Path Traversal: '/dir/../filename'(CWE-26) Path Traversal: '\dir\..\filename'(CWE-30) Path Traversal: 'dir/../../filename'(CWE-27) Path Traversal: 'dir\..\..\filename'(CWE-31) Path Traversal: '/../filedir'(CWE-25) Path Traversal: '../filedir'(CWE-24) Path Traversal: '..\filedir'(CWE-28) Path Traversal: '\..\filename'(CWE-29) Path Traversal: '....' (Multiple Dot)(CWE-33) Path Traversal: '...' (Triple Dot)(CWE-32) Path Traversal: '\\UNC\share\name\' (Windows UNC Share)(CWE-40) Peripheral Footprinting(CAPEC-646) Permission Race Condition During Resource Copy(CWE-689) Permissive Cross-domain Policy with Untrusted Domains(CWE-942) Permissive List of Allowed Inputs(CWE-183) Permissive Regular Expression(CWE-625) Persistent Storable Data Element without Associated Comparison Control Element(CWE-1097) Pharming(CAPEC-89) Phishing(CAPEC-98) PHP External Variable Modification(CWE-473) PHP Local File Inclusion(CAPEC-252) PHP Remote File Inclusion(CAPEC-193) Physical Destruction of Device or Component(CAPEC-547) Physically Hacking Hardware(CAPEC-401) Physical Theft(CAPEC-507) Placement of User into Incorrect Group(CWE-842) Plaintext Storage of a Password(CWE-256) Pointer Manipulation(CAPEC-129) Poison Web Service Registry(CAPEC-51) Policy Privileges are not Assigned Consistently Between Control and Data Agents(CWE-1268) Policy Uses Obsolete Encoding(CWE-1267) Port Scanning(CAPEC-300) Postfix, Null Terminate, and Backslash(CAPEC-53) Power-On of Untrusted Execution Core Before Enabling Fabric Access Control(CWE-1193) Predictable Exact Value from Previous Values(CWE-342) Predictable from Observable State(CWE-341) Predictable Seed in Pseudo-Random Number Generator (PRNG)(CWE-337) Predictable Value Range from Previous Values(CWE-343) Premature Release of Resource During Expected Lifetime(CWE-826) Pretexting(CAPEC-407) Pretexting via Customer Service(CAPEC-412) Pretexting via Delivery Person(CAPEC-414) Pretexting via Phone(CAPEC-415) Pretexting via Tech Support(CAPEC-413) Principal Spoof(CAPEC-195) Privacy Violation(CWE-359) Private Data Structure Returned From A Public Method(CWE-495) Privilege Abuse(CAPEC-122) Privilege Chaining(CWE-268) Privilege Context Switching Error(CWE-270) Privilege Defined With Unsafe Actions(CWE-267) Privilege Dropping / Lowering Errors(CWE-271) Privilege Escalation(CAPEC-233) Probe Audio and Video Peripherals(CAPEC-634) Probe iOS Screenshots(CAPEC-498) Probe System Files(CAPEC-639) Process Control(CWE-114) Process Footprinting(CAPEC-573) Processor Optimization Removal or Modification of Security-critical Code(CWE-1037) Product Released in Non-Release Configuration(CWE-1269) Product UI does not Warn User of Unsafe Actions(CWE-356) Protection Mechanism Failure(CWE-693) Protocol Analysis(CAPEC-192) Protocol Manipulation(CAPEC-272) Provide Counterfeit Component(CAPEC-530) Public cloneable() Method Without Final ('Object Hijack')(CWE-491) Public Data Assigned to Private Array-Typed Field(CWE-496) Public Key Re-Use for Signing both Debug and Production Code(CWE-1291) Public Static Field Not Marked Final(CWE-500) Public Static Final Field References Mutable Object(CWE-607) Pull Data from System Resources(CAPEC-545) Quadratic Data Expansion(CAPEC-491) Query System for Information(CAPEC-54) Race Condition During Access to Alternate Channel(CWE-421) Race Condition Enabling Link Following(CWE-363) Race Condition for Write-Once Attributes(CWE-1223) Race Condition within a Thread(CWE-366) Rainbow Table Password Cracking(CAPEC-55) Reachable Assertion(CWE-617) Read Sensitive Constants Within an Executable(CAPEC-191) Redirect Access to Libraries(CAPEC-159) Reflected XSS(CAPEC-591) Reflection Attack in an Authentication Protocol(CWE-301) Reflection Attack in Authentication Protocol(CAPEC-90) Reflection Injection(CAPEC-138) Regular Expression Exponential Blowup(CAPEC-492) Regular Expression without Anchors(CWE-777) Relative Path Traversal(CAPEC-139) Relative Path Traversal(CWE-23) Release of Invalid Pointer or Reference(CWE-763) Reliance on a Single Factor in a Security Decision(CWE-654) Reliance on Component That is Not Updateable(CWE-1329) Reliance on Cookies without Validation and Integrity Checking(CWE-565) Reliance on Cookies without Validation and Integrity Checking in a Security Decision(CWE-784) Reliance on Data/Memory Layout(CWE-188) Reliance on File Name or Extension of Externally-Supplied File(CWE-646) Reliance on HTTP instead of HTTPS(CWE-1428) Reliance on IP Address for Authentication(CWE-291) Reliance on Machine-Dependent Data Representation(CWE-1102) Reliance on Obfuscation or Encryption of Security-Relevant Inputs without Integrity Checking(CWE-649) Reliance on Package-level Scope(CWE-487) Reliance on Reverse DNS Resolution for a Security-Critical Action(CWE-350) Reliance on Runtime Component in Generated Code(CWE-1101) Reliance on Uncontrolled Component(CWE-1357) Reliance on Undefined, Unspecified, or Implementation-Defined Behavior(CWE-758) Reliance on Untrusted Inputs in a Security Decision(CWE-807) Remanent Data Readable after Memory Erase(CWE-1330) Remote Code Inclusion(CAPEC-253) Remote File Inclusion(CWE-98) Remote Services with Stolen Credentials(CAPEC-555) Removal of filters: Input filters, output filters, data masking(CAPEC-200) Removing Important Client Functionality(CAPEC-207) Removing/short-circuiting 'Purse' logic: removing/mutating 'cash' decrements(CAPEC-208) Replace Binaries(CAPEC-642) Replace File Extension Handlers(CAPEC-556) Replace Trusted Executable(CAPEC-558) Replace Winlogon Helper DLL(CAPEC-579) Replicating Malicious Code (Virus or Worm)(CWE-509) Repo Jacking(CAPEC-695) Requirements for ASIC Functionality Maliciously Altered(CAPEC-671) Resource Injection(CWE-99) Resource Injection(CAPEC-240) Resource Leak Exposure(CAPEC-131) Resource Location Spoofing(CAPEC-154) Restful Privilege Elevation(CAPEC-58) Retrieve Data from Decommissioned Devices(CAPEC-675) Retrieve Embedded Sensitive Data(CAPEC-37) Returning a Mutable Object to an Untrusted Caller(CWE-375) Return Inside Finally Block(CWE-584) Return of Pointer Value Outside of Expected Range(CWE-466) Return of Stack Variable Address(CWE-562) Return of Wrong Status Code(CWE-393) Reusing a Nonce, Key Pair in Encryption(CWE-323) Reusing Session IDs (aka Session Replay)(CAPEC-60) Reverse Engineer an Executable to Expose Assumed Hidden Functionality(CAPEC-190) Reverse Engineering(CAPEC-188) Reversible One-Way Hash(CWE-328) RFID Chip Deactivation or Destruction(CAPEC-400) Rogue Integration Procedures(CAPEC-524) Rooting SIM Cards(CAPEC-614) Root/Jailbreak Detection Evasion via Debugging(CAPEC-661) Root/Jailbreak Detection Evasion via Hooking(CAPEC-660) Route Disabling(CAPEC-582) Run Software at Logon(CAPEC-564) Runtime Resource Management Control Element in a Component Built to Run on Application Servers(CWE-1065) SaaS User Request Forgery(CAPEC-510) Same Seed in Pseudo-Random Number Generator (PRNG)(CWE-336) Scanning for Vulnerable Software(CAPEC-310) Schema Poisoning(CAPEC-271) Scheme Squatting(CAPEC-505) Screen Temporary Files for Sensitive Information(CAPEC-155) Search Order Hijacking(CAPEC-471) Security-Sensitive Hardware Controls with Missing Lock Bit Protection(CWE-1233) Security Software Footprinting(CAPEC-581) Security Through Obscurity(CWE-656) Security Version Number Mutable to Older Versions(CWE-1328) Selection of Less-Secure Algorithm During Negotiation ('Algorithm Downgrade')(CWE-757) Self-generated Error Message Containing Sensitive Information(CWE-210) Semiconductor Defects in Hardware Logic with Security-Sensitive Implications(CWE-1248) Sensitive Cookie in HTTPS Session Without 'Secure' Attribute(CWE-614) Sensitive Cookie with Improper SameSite Attribute(CWE-1275) Sensitive Cookie Without 'HttpOnly' Flag(CWE-1004) Sensitive Data Storage in Improperly Locked Memory(CWE-591) Sensitive Information Accessible by Physical Probing of JTAG Interface(CWE-1324) Sensitive Information in Resource Not Removed Before Reuse(CWE-226) Sensitive Information Uncleared Before Debug/Power State Transition(CWE-1272) Sensitive Non-Volatile Information Not Protected During Debug(CWE-1243) Sequence of Processor Instructions Leads to Unexpected Behavior(CWE-1281) Serializable Class Containing Sensitive Data(CWE-499) Serializable Data Element Containing non-Serializable Item Elements(CWE-1070) Serialized Data External Linking(CAPEC-201) Serialized Data Parameter Blowup(CAPEC-229) Serialized Data with Nested Payloads(CAPEC-230) Server Functionality Compromise(CAPEC-677) Server-generated Error Message Containing Sensitive Information(CWE-550) Server Side Include (SSI) Injection(CAPEC-101) Server Side Request Forgery(CAPEC-664) Server-Side Request Forgery (SSRF)(CWE-918) Services Footprinting(CAPEC-574) Servlet Runtime Error Message Containing Sensitive Information(CWE-536) Session Credential Falsification through Forging(CAPEC-196) Session Credential Falsification through Manipulation(CAPEC-226) Session Credential Falsification through Prediction(CAPEC-59) Session Fixation(CAPEC-61) Session Fixation(CWE-384) Session Hijacking(CAPEC-593) Session Sidejacking(CAPEC-102) Shared Resource Manipulation(CAPEC-124) Shoulder Surfing(CAPEC-508) Signal Handler Function Associated with Multiple Signals(CWE-831) Signal Handler Race Condition(CWE-364) Signal Handler Use of a Non-reentrant Function(CWE-479) Signal Handler with Functionality that is not Asynchronous-Safe(CWE-828) Signal Strength Tracking(CAPEC-619) Signature Spoof(CAPEC-473) Signature Spoofing by Improper Validation(CAPEC-475) Signature Spoofing by Key Recreation(CAPEC-485) Signature Spoofing by Key Theft(CAPEC-474) Signature Spoofing by Misrepresentation(CAPEC-476) Signature Spoofing by Mixing Signed and Unsigned Content(CAPEC-477) Signed to Unsigned Conversion Error(CWE-195) Signing Malicious Code(CAPEC-206) Singleton Class Instance Creation without Proper Locking or Synchronization(CWE-1096) Small Seed Space in PRNG(CWE-339) Small Space of Random Values(CWE-334) Smudge Attack(CAPEC-626) Sniff Application Code(CAPEC-65) Sniffing Attacks(CAPEC-157) Sniffing Network Traffic(CAPEC-158) SOAP Array Blowup(CAPEC-493) SOAP Array Overflow(CAPEC-256) SOAP Manipulation(CAPEC-279) Software Development Tools Maliciously Altered(CAPEC-670) Software Integrity Attack(CAPEC-184) SoundSquatting(CAPEC-631) Source Code Element without Standard Prologue(CWE-1115) Source Code File with Excessive Number of Lines of Code(CWE-1080) Spear Phishing(CAPEC-163) Spoofing of UDDI/ebXML Messages(CAPEC-218) Spoof Open-Source Software Metadata(CAPEC-691) Spoof Version Control System Commit Metadata(CAPEC-692) Spyware(CWE-512) SQL Injection(CWE-89) SQL Injection(CAPEC-66) SQL Injection: Hibernate(CWE-564) SQL Injection through SOAP Parameter Tampering(CAPEC-110) SSL Flood(CAPEC-489) Stack Overflow(CWE-121) StarJacking(CAPEC-693) Static Member Data Element outside of a Singleton Class Element(CWE-1042) Storage of File With Sensitive Data Under FTP Root(CWE-220) Storage of File with Sensitive Data Under Web Root(CWE-219) Storage of Sensitive Data in a Mechanism without Access Control(CWE-921) Stored XSS(CAPEC-592) Storing Passwords in a Recoverable Format(CWE-257) String Format Overflow in syslog()(CAPEC-67) Struts: Duplicate Validation Forms(CWE-102) Struts: Form Bean Does Not Extend Validation Class(CWE-104) Struts: Form Field Without Validator(CWE-105) Struts: Incomplete validate() Method Definition(CWE-103) Struts: Non-private Field in ActionForm Class(CWE-608) Struts: Plug-in Framework not in Use(CWE-106) Struts: Unused Validation Form(CWE-107) Struts: Unvalidated Action Form(CWE-108) Struts: Validator Turned Off(CWE-109) Struts: Validator Without Form Field(CWE-110) Subvert Code-signing Facilities(CAPEC-68) Subverting Environment Variable Values(CAPEC-13) Suspicious Comment(CWE-546) Sustained Client Engagement(CAPEC-227) Symbolic Name not Mapping to Correct Object(CWE-386) Symlink Attack(CAPEC-132) Synchronous Access of Remote Resource without Timeout(CWE-1088) System Build Data Maliciously Altered(CAPEC-678) System Footprinting(CAPEC-580) System Location Discovery(CAPEC-694) System-on-Chip (SoC) Using Components without Unique, Immutable Identifiers(CWE-1192) Tapjacking(CAPEC-506) Targeted Malware(CAPEC-542) Target Influence via Eye Cues(CAPEC-429) Target Influence via Framing(CAPEC-425) Target Influence via The Human Buffer Overflow(CAPEC-433) Target Programs with Elevated Privileges(CAPEC-69) Task Impersonation(CAPEC-504) TCP ACK Ping(CAPEC-297) TCP ACK Scan(CAPEC-305) TCP Congestion Control Flag (ECN) Probe(CAPEC-325) TCP Connect Scan(CAPEC-301) TCP FIN Scan(CAPEC-302) TCP Flood(CAPEC-482) TCP Fragmentation(CAPEC-494) TCP Initial Window Size Probe(CAPEC-326) TCP (ISN) Counter Rate Probe(CAPEC-323) TCP (ISN) Greatest Common Divisor Probe(CAPEC-322) TCP (ISN) Sequence Predictability Probe(CAPEC-324) TCP Null Scan(CAPEC-304) TCP Options Probe(CAPEC-327) TCP RPC Scan(CAPEC-307) TCP 'RST' Flag Checksum Probe(CAPEC-328) TCP RST Injection(CAPEC-596) TCP Sequence Number Probe(CAPEC-321) TCP SYN Ping(CAPEC-299) TCP SYN Scan(CAPEC-287) TCP Timestamp Probe(CAPEC-320) TCP Window Scan(CAPEC-306) TCP Xmas Scan(CAPEC-303) Terrestrial Jamming(CAPEC-599) The UI Performs the Wrong Action(CWE-449) Time-of-check Time-of-use (TOCTOU) Race Condition(CWE-367) Timestamp Request(CAPEC-295) Token Impersonation(CAPEC-633) Traceroute Route Enumeration(CAPEC-293) Traffic Injection(CAPEC-594) Transaction or Event Tampering via Application API Manipulation(CAPEC-385) Transmission of Private Resources into a New Sphere ('Resource Leak')(CWE-402) Transparent Proxy Abuse(CAPEC-465) Trapdoor(CWE-510) Trojan Horse(CWE-507) Truncation of Security-relevant Information(CWE-222) Trust Boundary Violation(CWE-501) Trusting HTTP Permission Methods on the Server Side(CWE-650) Trust of System Event Data(CWE-360) Try All Common Switches(CAPEC-133) Try Common or Default Usernames and Passwords(CAPEC-70) Type Confusion(CWE-843) TypoSquatting(CAPEC-630) UDP Flood(CAPEC-486) UDP Fragmentation(CAPEC-495) UDP Ping(CAPEC-298) UDP Scan(CAPEC-308) UI Discrepancy for Security Feature(CWE-446) UI Redressing (Clickjacking)(CAPEC-103) Unauthorized Error Injection Can Degrade Hardware Redundancy(CWE-1334) Unauthorized Use of Device Resources(CAPEC-629) Uncaught Exception(CWE-248) Uncaught Exception in Servlet (CWE-600) Unchecked Error Condition(CWE-391) Unchecked Input for Loop Condition(CWE-606) Unchecked Return Value(CWE-252) Unchecked Return Value to NULL Pointer Dereference(CWE-690) Unconditional Control Flow Transfer outside of Switch Block(CWE-1075) Uncontrolled Recursion(CWE-674) Uncontrolled Resource Consumption(CWE-400) Uncontrolled Search Path Element(CWE-427) Undefined Behavior for Input to API(CWE-475) Unexpected Sign Extension(CWE-194) Unexpected Status Code or Return Value(CWE-394) Unimplemented or Unsupported Feature in UI(CWE-447) Uninitialized Value on Reset for Registers Holding Security Settings(CWE-1271) Unintended Proxy or Intermediary ('Confused Deputy')(CWE-441) Unintended Reentrant Invocation of Non-reentrant Code Via Nested Calls(CWE-1265) UNIX Hard Link(CWE-62) UNIX Symbolic Link (Symlink) Following(CWE-61) Unlock of a Resource that is not Locked(CWE-832) Unnecessary Complexity in Protection Mechanism (Not Using 'Economy of Mechanism')(CWE-637) Unparsed Raw Web Content Delivery(CWE-433) Unprotected Alternate Channel(CWE-420) Unprotected Confidential Information on Device is Accessible by OSAT Vendors(CWE-1297) Unprotected Primary Channel(CWE-419) Unprotected Transport of Credentials(CWE-523) Unprotected Windows Messaging Channel ('Shatter')(CWE-422) Unquoted Search Path or Element(CWE-428) Unrestricted Externally Accessible Lock(CWE-412) Unrestricted Upload of File with Dangerous Type(CWE-434) Unsafe ActiveX Control Marked Safe For Scripting(CWE-623) Unsigned to Signed Conversion Error(CWE-196) Unsynchronized Access to Shared Data in a Multithreaded Context(CWE-567) Untrusted Pointer Dereference(CWE-822) Untrusted Search Path(CWE-426) Unverified Ownership(CWE-283) Unverified Password Change(CWE-620) Upload a Web Shell to a Web Server(CAPEC-650) URL Encoding(CAPEC-72) USB Memory Attacks(CAPEC-457) Use After Free(CWE-416) Use of a Broken or Risky Cryptographic Algorithm(CWE-327) Use of a Cryptographic Primitive with a Risky Implementation(CWE-1240) Use of a Key Past its Expiration Date(CWE-324) Use of a Non-reentrant Function in a Concurrent Context(CWE-663) Use of a One-Way Hash with a Predictable Salt(CWE-760) Use of a One-Way Hash without a Salt(CWE-759) Use of Blocking Code in Single-threaded, Non-blocking Context(CWE-1322) Use of Cache Containing Sensitive Information(CWE-524) Use of Captured Hashes (Pass The Hash)(CAPEC-644) Use of Captured Tickets (Pass The Ticket)(CAPEC-645) Use of Client-Side Authentication(CWE-603) Use of Cryptographically Weak Pseudo-Random Number Generator (PRNG)(CWE-338) Use of Default Credentials(CWE-1392) Use of Default Cryptographic Key(CWE-1394) Use of Default Password(CWE-1393) Use of Expired File Descriptor(CWE-910) Use of Externally-Controlled Format String(CWE-134) Use of Externally-Controlled Input to Select Classes or Code ('Unsafe Reflection')(CWE-470) Use of Function with Inconsistent Implementations(CWE-474) Use of getlogin() in Multithreaded Application(CWE-558) Use of GET Request Method With Sensitive Query Strings(CWE-598) Use of Hard-coded Credentials(CWE-798) Use of Hard-coded Cryptographic Key(CWE-321) Use of Hard-coded Password(CWE-259) Use of Hard-coded, Security-relevant Constants(CWE-547) Use of Implicit Intent for Sensitive Communication(CWE-927) Use of Incorrect Byte Ordering(CWE-198) Use of Incorrectly-Resolved Name or Reference(CWE-706) Use of Incorrect Operator(CWE-480) Use of Inherently Dangerous Function(CWE-242) Use of Inner Class Containing Sensitive Data(CWE-492) Use of Insufficiently Random Values(CWE-330) Use of Invariant Value in Dynamically Changing Context(CWE-344) Use of Known Domain Credentials(CAPEC-560) Use of Known Kerberos Credentials(CAPEC-652) Use of Known Windows Credentials(CAPEC-653) Use of Less Trusted Source(CWE-348) Use of Low-Level Functionality(CWE-695) Use of Multiple Resources with Duplicate Identifier(CWE-694) Use of Non-Canonical URL Paths for Authorization Decisions(CWE-647) Use of NullPointerException Catch to Detect NULL Pointer Dereference(CWE-395) Use of Object without Invoking Destructor Method(CWE-1091) Use of Obsolete Function(CWE-477) Use of Out-of-range Pointer Offset(CWE-823) Use of Password Hash Instead of Password for Authentication(CWE-836) Use of Password Hash With Insufficient Computational Effort(CWE-916) Use of Password System for Primary Authentication(CWE-309) Use of Path Manipulation Function without Maximum-sized Buffer(CWE-785) Use of Persistent Cookies Containing Sensitive Information(CWE-539) Use of Platform-Dependent Third Party Components(CWE-1103) Use of Pointer Subtraction to Determine Size(CWE-469) Use of Potentially Dangerous Function(CWE-676) Use of Predictable Algorithm in Random Number Generator(CWE-1241) Use of Prohibited Code(CWE-1177) Use of Redundant Code(CWE-1041) Use of RSA Algorithm without OAEP(CWE-780) Use of Same Invokable Control Element in Multiple Architectural Layers(CWE-1092) Use of Same Variable for Multiple Purposes(CWE-1109) Use of Single-factor Authentication(CWE-308) Use of Singleton Pattern Without Synchronization in a Multithreaded Context(CWE-543) Use of sizeof() on a Pointer Type(CWE-467) Use of umask() with chmod-style Argument(CWE-560) Use of Uninitialized Resource(CWE-908) Use of Uninitialized Variable(CWE-457) Use of Unmaintained Third Party Components(CWE-1104) Use of Weak Credentials(CWE-1391) Use of Web Browser Cache Containing Sensitive Information(CWE-525) Use of Web Link to Untrusted Target with window.opener Access(CWE-1022) Use of Wrong Operator in String Comparison(CWE-597) User-Controlled Filename(CAPEC-73) User Interface (UI) Misrepresentation of Critical Information(CWE-451) Using Alternative IP Address Encodings(CAPEC-4) Using a Snap Gun Lock to Force a Lock(CAPEC-394) Using Components with Known Vulnerabilities(CWE-1035) Using Escaped Slashes in Alternate Encoding(CAPEC-78) Using Leading 'Ghost' Character Sequences to Bypass Input Filters(CAPEC-3) Using Malicious Files(CAPEC-17) Using Meta-characters in E-mail Headers to Inject Malicious Payloads(CAPEC-41) Using Referer Field for Authentication(CWE-293) Using Slashes and URL Encoding Combined to Bypass Validation Logic(CAPEC-64) Using Slashes in Alternate Encoding(CAPEC-79) Using Unicode Encoding to Bypass Validation Logic(CAPEC-71) Using Unpublished Interfaces(CAPEC-36) Using UTF-8 Encoding to Bypass Validation Logic(CAPEC-80) Utilizing REST's Trust in the System Resource to Obtain Sensitive Data(CAPEC-57) Variable Extraction Error(CWE-621) Violation of Secure Design Principles(CWE-657) Voice Phishing(CAPEC-656) Weak Authentication(CWE-1390) Weak Cryptography for Passwords(CWE-261) Weakening of Cellular Encryption(CAPEC-606) Weak Password Recovery Mechanism for Forgotten Password(CWE-640) Weak Password Requirements(CWE-521) Web Application Fingerprinting(CAPEC-170) Web Logs Tampering(CAPEC-81) Web Services API Signature Forgery Leveraging Hash Function Extension Weakness(CAPEC-461) Web Services Protocol Manipulation(CAPEC-278) WebView Exposure(CAPEC-503) WebView Injection(CAPEC-500) White Box Reverse Engineering(CAPEC-167) Wi-Fi Jamming(CAPEC-604) WiFi MAC Address Tracking(CAPEC-612) WiFi SSID Tracking(CAPEC-613) Windows Admin Shares with Stolen Credentials(CAPEC-561) Windows ::DATA Alternate Data Stream(CAPEC-168) Windows Hard Link(CWE-65) Windows Shortcut Following (.LNK)(CWE-64) Wrap-around Error(CWE-128) Write-what-where Condition(CWE-123) WSDL Scanning(CAPEC-95) XML Entity Expansion(CWE-776) XML External Entities (XXE)(CWE-611) XML Flood(CAPEC-528) XML Injection(CAPEC-250) XML Injection(CWE-91) XML Ping of the Death(CAPEC-147) XML Routing Detour Attacks(CAPEC-219) XML Schema Poisoning(CAPEC-146) XPath Injection(CAPEC-83) XQuery Injection(CAPEC-84) XSS Targeting Error Pages(CAPEC-198) XSS Targeting HTML Attributes(CAPEC-243) XSS Targeting Non-Script Elements(CAPEC-18) XSS Targeting URI Placeholders(CAPEC-244) XSS Through HTTP Headers(CAPEC-86) XSS Through HTTP Query Strings(CAPEC-32) XSS Using Alternate Syntax(CAPEC-199) XSS Using Doubled Characters(CAPEC-245) XSS Using Invalid Characters(CAPEC-247) XSS Using MIME Type Mismatch(CAPEC-209) LLM01: Prompt Injection LLM02: Insecure Output Handling LLM03: Training Data Poisoning LLM04: Model Denial of Service LLM05: Supply Chain Vulnerabilities LLM06: Sensitive Information Disclosure LLM07: Insecure Plugin Design LLM08: Excessive Agency LLM09: Overreliance LLM10: Model Theft LLM03:2025 Supply Chain LLM02:2025 Sensitive Information Disclosure LLM07:2025 System Prompt Leakage LLM06:2025 Excessive Agency LLM04:2025 Data and Model Poisoning LLM10:2025 Unbounded Consumption LLM09:2025 Misinformation ASI01: Agent Goal Hijack ASI04: Agentic Supply Chain Vulnerabilities ASI10: Rogue Agents LLM08:2025 Vector and Embedding Weaknesses ASI06: Memory & Context Poisoning ASI09: Human-Agent Trust Exploitation ASI07: Insecure Inter-Agent Communication LLM05:2025 Improper Output Handling ASI02: Tool Misuse and Exploitation ASI03: Identity and Privilege Abuse ASI05: Unexpected Code Execution (RCE) ASI08: Cascading Failures
Currently selected: None
2
Severity (optional)
Estimate the severity of this issue.
Submit report without severity
Submit report with severity
Severity calculation method
CVSS 4.0
The Common Vulnerability Scoring System (CVSS) is an open framework for communicating the characteristics and severity of software vulnerabilities. Learn more about CVSS 4.0
open in new tabopen in new tab.
Score
None
0
Attack Vector (AV)
NetworkAdjacentLocalPhysical
Expand attack vector (av) descriptionExpand attack vector (av) description
This metric reflects the context by which vulnerability exploitation is possible. This metric value (and consequently the resulting severity) will be larger the more remote (logically, and physically) an attacker can be in order to exploit the vulnerable system. The assumption is that the number of potential attackers for a vulnerability that could be exploited from across a network is larger than the number of potential attackers that could exploit a vulnerability requiring physical access to a device, and therefore warrants a greater severity.
Network (N): The vulnerable system is bound to the network stack and the set of possible attackers extends beyond the other options listed below, up to and including the entire Internet. Such a vulnerability is often termed “remotely exploitable” and can be thought of as an attack being exploitable at the protocol level one or more network hops away (e.g., across one or more routers). An example of a network attack is an attacker causing a denial of service (DoS) by sending a specially crafted TCP packet across a wide area network (e.g., CVE-2004-0230).
Adjacent (A): The vulnerable system is bound to a protocol stack, but the attack is limited at the protocol level to a logically adjacent topology. This can mean an attack must be launched from the same shared proximity (e.g., Bluetooth, NFC, or IEEE 802.11) or logical network (e.g., local IP subnet), or from within a secure or otherwise limited administrative domain (e.g., MPLS, secure VPN within an administrative network zone). One example of an Adjacent attack would be an ARP (IPv4) or neighbor discovery (IPv6) flood leading to a denial of service on the local LAN segment (e.g., CVE-2013-6014).
Local (L): The vulnerable system is not bound to the network stack and the attacker’s path is via read/write/execute capabilities. Either: the attacker exploits the vulnerability by accessing the target system locally (e.g., keyboard, console), or through terminal emulation (e.g., SSH); or the attacker relies on User Interaction by another person to perform actions required to exploit the vulnerability (e.g., using social engineering techniques to trick a legitimate user into opening a malicious document).
Physical (P): The attack requires the attacker to physically touch or manipulate the vulnerable system. Physical interaction may be brief (e.g., evil maid attack) or persistent. An example of such an attack is a cold boot attack in which an attacker gains access to disk encryption keys after physically accessing the target system. Other examples include peripheral attacks via FireWire/USB Direct Memory Access (DMA).
Attack Complexity (AC)
LowHigh
Expand attack complexity (ac) descriptionExpand attack complexity (ac) description
This metric captures measurable actions that must be taken by the attacker to actively evade or circumvent existing built-in security-enhancing conditions in order to obtain a working exploit. These are conditions whose primary purpose is to increase security and/or increase exploit engineering complexity. A vulnerability exploitable without a target-specific variable has a lower complexity than a vulnerability that would require non-trivial customization. This metric is meant to capture security mechanisms utilized by the vulnerable system and does not relate to the amount of time or attempts it would take for an attacker to succeed, e.g., a race condition. If the attacker does not take action to overcome these conditions, the attack will always fail.
The evasion or satisfaction of authentication mechanisms or requisites is included in the Privileges Required assessment and is not considered here as a factor of relevance for Attack Complexity.
Low (L): The attacker must take no measurable action to exploit the vulnerability. The attack requires no target-specific circumvention to exploit the vulnerability. An attacker can expect repeatable success against the vulnerable system.
High (H): The successful attack depends on the evasion or circumvention of security-enhancing techniques in place that would otherwise hinder the attack. These include:
Evasion of exploit mitigation techniques: The attacker must have additional methods available to bypass security measures in place. For example, circumvention of address space randomization (ASLR) or data execution prevention (DEP) must be performed for the attack to be successful.
Obtaining target-specific secrets: The attacker must gather some target-specific secret before the attack can be successful. A secret is any piece of information that cannot be obtained through any amount of reconnaissance. To obtain the secret, the attacker must perform additional attacks or break otherwise secure measures (e.g., knowledge of a secret key may be needed to break a crypto channel). This operation must be performed for each attacked target.
Attack Requirements (AT)
NonePresent
Expand attack requirements (at) descriptionExpand attack requirements (at) description
This metric captures the prerequisite deployment and execution conditions or variables of the vulnerable system that enable the attack. These differ from security-enhancing techniques or technologies (see Attack Complexity) as the primary purpose of these conditions is not to explicitly mitigate attacks, but rather, emerge naturally as a consequence of the deployment and execution of the vulnerable system. If the attacker does not take action to overcome these conditions, the attack may succeed only occasionally or not succeed at all.
None (N): The successful attack does not depend on the deployment and execution conditions of the vulnerable system. The attacker can expect to be able to reach the vulnerability and execute the exploit under all or most instances of the vulnerability.
Present (P): The successful attack depends on the presence of specific deployment and execution conditions of the vulnerable system that enable the attack. These include:
Race condition: A race condition must be won to successfully exploit the vulnerability.
Uncontrolled execution conditions: The success of the attack is conditioned on execution conditions that are not under full control of the attacker. The attack may need to be launched multiple times against a single target before being successful.
Network injection: The attacker must inject themselves into the logical network path between the target and the resource requested by the victim (e.g., vulnerabilities requiring an on-path attacker).
Privileges Required (PR)
NoneLowHigh
Expand privileges required (pr) descriptionExpand privileges required (pr) description
This metric describes the level of privileges an attacker must possess prior to successfully exploiting the vulnerability. The method by which the attacker obtains privileged credentials prior to the attack (e.g., free trial accounts) is outside the scope of this metric. Generally, self-service provisioned accounts do not constitute a privilege requirement if the attacker can grant themselves privileges as part of the attack.
The resulting score is greatest if no privileges are required.
None (N): The attacker is unauthenticated prior to the attack and therefore does not require any access to settings or files of the vulnerable system to carry out the attack.
Low (L): The attacker requires privileges that provide basic capabilities typically limited to settings and resources owned by a single low-privileged user. Alternatively, an attacker with Low privileges has the ability to access only non-sensitive resources.
High (H): The attacker requires privileges that provide significant (e.g., administrative) control over the vulnerable system, allowing full access to the system’s settings and files.
User Interaction (UI)
NonePassiveActive
Expand user interaction (ui) descriptionExpand user interaction (ui) description
This metric captures the requirement for a human user, other than the attacker, to participate in the successful compromise of the vulnerable system. This metric determines whether the vulnerability can be exploited solely at the will of the attacker, or whether a separate user (or user-initiated process) must participate in some manner. The resulting score is greatest when no user interaction is required.
None (N): The vulnerable system can be exploited without interaction from any human user, other than the attacker. Examples include:
A remote attacker is able to send packets to a target system.
- A locally authenticated attacker executes code to elevate privileges.
Passive (P): Successful exploitation of this vulnerability requires limited interaction by the targeted user with the vulnerable system and the attacker’s payload. These interactions are considered involuntary and do not require the user to actively subvert protections built into the vulnerable system. Examples include:
Utilizing a website that has been modified to display malicious content when the page is rendered (e.g., most stored XSS or CSRF).
- Running an application that calls a malicious binary that has been planted on the system.
- Using an application that generates traffic over an untrusted or compromised network (e.g., vulnerabilities requiring an on-path attacker).
Active (A): Successful exploitation of this vulnerability requires a targeted user to perform specific, conscious interactions with the vulnerable system and the attacker’s payload, or the user’s interactions must actively subvert protection mechanisms, leading to exploitation of the vulnerability. Examples include:
Importing a file into a vulnerable system in a specific manner.
- Placing files into a specific directory prior to executing code.
- Submitting a specific string into a web application (e.g., reflected or self XSS).
- Dismissing or accepting prompts or security warnings prior to taking an action (e.g., opening/editing a file, connecting a device).
Vulnerable System Confidentiality Impact (VC)
HighLowNone
Expand vulnerable system confidentiality impact (vc) descriptionExpand vulnerable system confidentiality impact (vc) description
This metric measures the impact to the confidentiality of the information managed by the system due to a successfully exploited vulnerability. Confidentiality refers to limiting information access and disclosure to only authorized users, as well as preventing access by, or disclosure to, unauthorized ones. The resulting score is greatest when the loss to the system is highest.
High (H): There is a total loss of confidentiality, resulting in all information within the Vulnerable System being divulged to the attacker. Alternatively, access to only some restricted information is obtained, but the disclosed information presents a direct, serious impact. For example, an attacker steals the administrator's password, or private encryption keys of a web server.
Low (L): There is some loss of confidentiality. Access to some restricted information is obtained, but the attacker does not have control over what information is obtained, or the amount or kind of loss is limited. The information disclosure does not cause a direct, serious loss to the Vulnerable System.
None (N): There is no loss of confidentiality within the Vulnerable System.
Vulnerable System Integrity Impact (VI)
HighLowNone
Expand vulnerable system integrity impact (vi) descriptionExpand vulnerable system integrity impact (vi) description
This metric measures the impact to integrity of a successfully exploited vulnerability. Integrity refers to the trustworthiness and veracity of information. Integrity of a system is impacted when an attacker causes unauthorized modification of system data. Integrity is also impacted when a system user can repudiate critical actions taken in the context of the system (e.g., due to insufficient logging). The resulting score is greatest when the consequence to the system is highest.
High (H): There is a total loss of integrity, or a complete loss of protection. For example, the attacker is able to modify any/all files protected by the Vulnerable System. Alternatively, only some files can be modified, but malicious modification would present a direct, serious consequence to the Vulnerable System.
Low (L): Modification of data is possible, but the attacker does not have control over the consequence of a modification, or the amount of modification is limited. The data modification does not have a direct, serious impact to the Vulnerable System.
None (N): There is no loss of integrity within the Vulnerable System.
Vulnerable System Availability Impact (VA)
HighLowNone
Expand vulnerable system availability impact (va) descriptionExpand vulnerable system availability impact (va) description
This metric measures the impact to the availability of the impacted system resulting from a successfully exploited vulnerability. While the Confidentiality and Integrity impact metrics apply to the loss of confidentiality or integrity of data (e.g., information, files) used by the system, this metric refers to the loss of availability of the impacted system itself, such as a networked service (e.g., web, database, email). Since availability refers to the accessibility of information resources, attacks that consume network bandwidth, processor cycles, or disk space all impact the availability of a system. The resulting score is greatest when the consequence to the system is highest.
High (H): There is a total loss of availability, resulting in the attacker being able to fully deny access to resources in the Vulnerable System; this loss is either sustained (while the attacker continues to deliver the attack) or persistent (the condition persists even after the attack has completed). Alternatively, the attacker has the ability to deny some availability, but the loss of availability presents a direct, serious consequence to the Vulnerable System (e.g., the attacker cannot disrupt existing connections, but can prevent new connections; the attacker can repeatedly exploit a vulnerability that, in each instance of a successful attack, leaks only a small amount of memory, but after repeated exploitation causes a service to become completely unavailable).
Low (L): Performance is reduced or there are interruptions in resource availability. Even if repeated exploitation of the vulnerability is possible, the attacker does not have the ability to completely deny service to legitimate users. The resources in the Vulnerable System are either partially available all of the time, or fully available only some of the time, but overall there is no direct, serious consequence to the Vulnerable System.
None (N): There is no impact to availability within the Vulnerable System.
Subsequent System Confidentiality Impact (SC)
HighLowNone
Expand subsequent system confidentiality impact (sc) descriptionExpand subsequent system confidentiality impact (sc) description
This metric measures the impact to the confidentiality of the information managed by the Subsequent System due to a successfully exploited vulnerability. The resulting score is greatest when the loss to the Subsequent System is highest.
High (H): There is a total loss of confidentiality, resulting in all resources within the Subsequent System being divulged to the attacker. Alternatively, access to only some restricted information is obtained, but the disclosed information presents a direct, serious impact. For example, an attacker steals the administrator's password, or private encryption keys of a web server.
Low (L): There is some loss of confidentiality. Access to some restricted information is obtained, but the attacker does not have control over what information is obtained, or the amount or kind of loss is limited. The information disclosure does not cause a direct, serious loss to the Subsequent System.
None (N): There is no loss of confidentiality within the Subsequent System or all confidentiality impact is constrained to the Vulnerable System.
Subsequent System Integrity Impact (SI)
HighLowNone
Expand subsequent system integrity impact (si) descriptionExpand subsequent system integrity impact (si) description
High (H): There is a total loss of integrity, or a complete loss of protection. For example, the attacker is able to modify any/all files protected by the Subsequent System. Alternatively, only some files can be modified, but malicious modification would present a direct, serious consequence to the Subsequent System.
Low (L): Modification of data is possible, but the attacker does not have control over the consequence of a modification, or the amount of modification is limited. The data modification does not have a direct, serious impact to the Subsequent System.
None (N): There is no loss of integrity within the Subsequent System or all integrity impact is constrained to the Vulnerable System.
Subsequent System Availability Impact (SA)
HighLowNone
Expand subsequent system availability impact (sa) descriptionExpand subsequent system availability impact (sa) description
High (H): There is a total loss of availability, resulting in the attacker being able to fully deny access to resources in the Subsequent System; this loss is either sustained (while the attacker continues to deliver the attack) or persistent (the condition persists even after the attack has completed). Alternatively, the attacker has the ability to deny some availability, but the loss of availability presents a direct, serious consequence to the Subsequent System (e.g., the attacker cannot disrupt existing connections, but can prevent new connections; the attacker can repeatedly exploit a vulnerability that, in each instance of a successful attack, leaks only a small amount of memory, but after repeated exploitation causes a service to become completely unavailable).
Low (L): Performance is reduced or there are interruptions in resource availability. Even if repeated exploitation of the vulnerability is possible, the attacker does not have the ability to completely deny service to legitimate users. The resources in the Subsequent System are either partially available all of the time, or fully available only some of the time, but overall there is no direct, serious consequence to the Subsequent System.
None (N): There is no impact to availability within the Subsequent System or all availability impact is constrained to the Vulnerable System.
CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:N/VI:N/VA:N/SC:N/SI:N/SA:NCopy
3
Proof of Concept
The proof of concept is the most important part of your report submission. Clear, reproducible steps will help us validate this issue as quickly as possible.
Title*
A clear and concise title includes the type of vulnerability and the impacted asset.
150
Description*
What is the vulnerability? In clear steps, how do you reproduce it?
WritePreview
Parsed with Markdown
Impact*
What security impact can an attacker achieve?
WritePreview
Parsed with Markdown
Uploading files is disabled
Enter your email to receive updates on the status of your submission. If you want to stay anonymous, you may leave this field blank.
Submit your report
By clicking 'Submit Report', you agree to HackerOne's Terms and Conditions and acknowledge that you have read HackerOne's Code of Conduct, Privacy Policy and Disclosure Guidelines.
Powered by
Submit Report
StripeM-Inner
Not a member of Fast Pastebin Alternative yet?
Sign Up, it unlocks many cool features!
We use cookies for various purposes including analytics. By continuing to use Fast Pastebin Alternative, you agree to our use of cookies as described in the Privacy Policy. OK, I Understand