CWE-1127 – Compilation with Insufficient Warnings or Errors

Read Time:12 Second

Description

The code is compiled without sufficient warnings enabled, which
may prevent the detection of subtle bugs or quality
issues.

Modes of Introduction:

– Build and Compilation

 

 

Related Weaknesses

CWE-710

 

Consequences

Other: Reduce Maintainability

 

Potential Mitigations

CVE References

CWE-112 – Missing XML Validation

Read Time:26 Second

Description

The software accepts XML from an untrusted source but does not validate the XML against the proper schema.

Most successful attacks begin with a violation of the programmer’s assumptions. By accepting an XML document without validating it against a DTD or XML schema, the programmer leaves a door open for attackers to provide unexpected, unreasonable, or malicious input.

Modes of Introduction:

– Implementation

 

 

Related Weaknesses

CWE-1286
CWE-20

 

Consequences

Integrity: Unexpected State

 

Potential Mitigations

Phase: Architecture and Design

Description: 

CVE References

News, Advisories and much more

Exit mobile version