2021 CWE Top 25 Most Dangerous Software Errors mapped to Klocwork C# checkers
| Rank and ID | Checker name |
|---|---|
| #01 - CWE-787: Out-of-bounds Write | |
| #02 - CWE-79: Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') | |
| #03 - CWE-125: Out-of-bounds Read | |
| #04 - CWE-20: Improper Input Validation |
CS.SV.TAINTED.CALL.INDEX_ACCESS CS.SV.TAINTED.CALL.LOOP_BOUND.RESOURCE |
| #05 - CWE-78: Improper Neutralization of Special Elements used in an OS Command ('OS Command Injection') | |
| #06 - CWE-89: Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') | |
| #07 - CWE-416: Use After Free | |
| #08 - CWE-22: Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal') | |
| #09 - CWE-352: Cross-Site Request Forgery (CSRF) | |
| #10 - CWE-434: Unrestricted Upload of File with Dangerous Type |
Currently, there is no applicable checker for this rule. |
| #11 - CWE-306: Missing Authentication for Critical Function |
Currently, there is no applicable checker for this rule. |
| #12 - CWE-190: Integer Overflow or Wraparound | |
| #13 - CWE-502: Deserialization of Untrusted Data | |
| #14 - CWE-287: Improper Authentication |
Currently, there is no applicable checker for this rule. |
| #15 - CWE-476: NULL Pointer Dereference | |
| #16 - CWE-798: Use of Hard-coded Credentials | |
| #17 - CWE-119: Improper Restriction of Operations within the Bounds of a Memory Buffer | |
| #18 - CWE-862: Missing Authorization | |
| #19 - CWE-276: Incorrect Default Permissions |
Currently, there is no applicable checker for this rule. |
| #20 - CWE-200: Exposure of Sensitive Information to an Unauthorized Actor | |
| #21 - CWE-522: Insufficiently Protected Credentials |
Currently, there is no applicable checker for this rule. |
| #22 - CWE-732: Incorrect Permission Assignment for Critical Resource | |
| #23 - CWE-611: Improper Restriction of XML External Entity Reference | |
| #24 - CWE-918: Server-Side Request Forgery (SSRF) |
Currently, there is no applicable checker for this rule. |
| #25 - CWE-77: Improper Neutralization of Special Elements used in a Command ('Command Injection') |
Support Summary:
- 18 of 25 weaknesses