CWE-827 – Improper Control of Document Type Definition
Description The software does not restrict a reference to a Document Type Definition (DTD) to the intended control sphere. This might allow attackers to reference...
CWE-829 – Inclusion of Functionality from Untrusted Control Sphere
Description The software imports, requires, or includes executable functionality (such as a library) from a source that is outside of the intended control sphere. Modes...