* Change config.toml, Auto-generate UUIDs, change structure of optional field * Detect processes affected by update using yum-ps (#482) Detect processes affected by update using yum-ps * Detect processes needs restart using checkrestart on Debian and Ubuntu. * pass cpename by args when calling FillCveInfo (#513) * fix new db (#502) * Include Version,Revision in JSON * Include hostname in JSON * Update goval-dictionary's commit hash in Gopkg.lock * Remove README.ja.md * update packages (#596) * fix: change ControlPath to .vuls of SSH option (#618) * feat: checkrestart for Ubuntu and Debian (#622) * feat: checkrestart for Ubuntu and Debian * fix: dependencies check logic of configtest * feat: need-restarting on RedHat * refactor: Process.ProcName to Process.Name * feat: detect a systemd service name of need-restarting-process * feat: detect a systemd service name of need-restarting-process on Ubuntu * feat: fill a service name of need-restarting-process, init-system * Support NVD JSON and CVSS3 of JVN (#605) * fix: compile errors * fix: Show CVSS3 on TUI * fix: test cases * fix: Avoid null in JSON * Fix maxCvssScore (#621) * Fix maxCvssScore * Update vulninfos.go * fix(init): remove unnecessary log initialization * refactor(nvd): use only json feed if exists json data. if not, use xml feed * fix(scan): make Confidence slice * feat(CWE): Display CWE name to TUI * feat(cwe): import CWE defs in Japanese * feat(cwe): add OWASP Top 10 ranking to CWE if applicable * feat(scan): add -fast-root mode, implement scan/amazon.go * refactor(const): change const name JVN to Jvn * feat(scan): add -fast-root mode, implement scan/centos.go * refactor(dep): update deps * fix(amazon): deps check * feat(scan): add -fast-root mode, implement scan/rhel.go * feat(scan): add -fast-root mode, implement scan/oracle.go * fix complile err * feat(scan): add -fast-root mode, implement scan/debian.go * fix testcase * fix(amazon): scan using yum * fix(configtest): change error message, status when no scannnable servers * Fix(scan): detect init process logic * fix(tui): display cvss as table format * fix(scan): parse a output of reboot-notifier on CentOS6.9 * fix(tui): don't display score, vector when score is zero * fix(scan): add -offline mode to suse scanner * fix(scan): fix help message * feat(scan): enable to define scan mode for each servers in config.toml #510 * refactor(config): chagne cpeNames to cpeURIs * refactor(config): change dependencyCheckXMLPath to owaspDCXMLPath * fix(config): containers -> containersIncluded, Excluded, containerType * feature(report): enable to define cpeURIs for each contaner * feature(report): enable to specify owasp dc xml path for each container * fix(discover): fix a template displayed at the end of discover * feature(report): add ignorePkgsRegexp #665 * feature(report): enable to define ignoreCves for each container #666 * fix(report): Displayed nothing in TUI detail area when CweID is nil * Gopkg.toml diet * feat(server): support server mode (#678) * feat(server): support server mode * Lock go version * Use the latest kernel release among the installed release when the running kernel release is unknown * Add TestViaHTTP * Set logger to go-cve-dictionary client * Add -to-localfile * Add -to-http option to report * Load -to-http conf from config.toml * Support gost (#676) * feat(gost): Support RedHat API * feat(gost): Support Debian Security Tracker * feat(db): display error msg when SQLite3 is locked at the beginning of reporting. * feat(gost): TUI * Only use RedHat information of installed packages * feat(tui): show mitigation on TUI * feat(gost): support redis backend * fix test case * fix nil pointer when db is nil * fix(gost): detect vulns of src packages for Debian * feat(gost): implement redis backend for gost redhat api * feat(report): display fixState of unfixed pkgs * fix(report): display distincted cweIDs * feat(slack): display gost info * feat(slack): display mitigation * feat(report): display available patch state as fixed/total * fix(tui): display - if source of reference is empty * update deps * fix(report): key in ScanResult JSON be lowerCamelcase. * some keys to lower camel * fix(configtest): dep check logic of yum-plugin-ps * fix(tui): format * feat(report): add -format-list option * fix(report): -format-full-text * fix(report): report -format-full-text * fix(report): display v3 score detected by gost * fix(scan): scan in fast mode if not defined in config.toml * fix(gost): fetch RedHat data for fixed CVEs * feat(report): show number of cves detected in each database * fix(report): show new version as `Unknown` in offline and fast scan mode * fix(report): fix num of upadtable and fixed * fix(report): set `Not fixed yet` if packageStatus is empty * refact(gost): make convertToModel public * fix(test): fix test case * update deps * fix(report): include gost score in MaxCvssScore * [WIP] feat(config): enable to set options in config.toml instead of cmd opt (#690) * feat(config): enable to set options in config.toml instead of cmd opt * fix(config): change Conf.Report.Slack to Conf.Slack * fix(discover): change tempalte * fix(report): fix config.toml auto-generate with -uuid * Add endpoint for health check and change endpoint * refact(cmd): refactor flag set * fix(report): enable to specify opts with cmd arg and env value * fix(scan): enable to parse the release version of amazon linux 2 * add(report) add -to-saas option (#695) * add(report) add -to-saas option * ignore other writer if -to-saas * fix(saas) fix bug * fix(scan): need-restarting needs internet connection * fix(scan,configtest): check scan mode * refactor(scan): change func name * fix(suse): support offline mode, bug fix on AWS, zypper --no-color * fix(tui): fix nil pointer when no vulns in tui * feat(report): enable to define CPE FS format in config.toml * fix(vet): fix warnings of go vet * fix(travis): go version to 1.11 * update deps
1028 lines
29 KiB
Go
1028 lines
29 KiB
Go
package cwe
|
|
|
|
// CweDictJa is the Cwe dictionary
|
|
var CweDictJa = map[string]Cwe{
|
|
"119": {
|
|
CweID: "119",
|
|
Name: "バッファエラー(CWE-119)",
|
|
Description: "",
|
|
ExtendedDescription: "",
|
|
Lang: "ja",
|
|
},
|
|
"20": {
|
|
CweID: "20",
|
|
Name: "不適切な入力確認(CWE-20)",
|
|
Description: "",
|
|
ExtendedDescription: "",
|
|
Lang: "ja",
|
|
},
|
|
"264": {
|
|
CweID: "264",
|
|
Name: "認可・権限・アクセス制御(CWE-264)",
|
|
Description: "",
|
|
ExtendedDescription: "",
|
|
Lang: "ja",
|
|
},
|
|
"362": {
|
|
CweID: "362",
|
|
Name: "競合状態(CWE-362)",
|
|
Description: "",
|
|
ExtendedDescription: "",
|
|
Lang: "ja",
|
|
},
|
|
"59": {
|
|
CweID: "59",
|
|
Name: "リンク解釈の問題(CWE-59)",
|
|
Description: "",
|
|
ExtendedDescription: "",
|
|
Lang: "ja",
|
|
},
|
|
"310": {
|
|
CweID: "310",
|
|
Name: "暗号の問題(CWE-310)",
|
|
Description: "",
|
|
ExtendedDescription: "",
|
|
Lang: "ja",
|
|
},
|
|
"288": {
|
|
CweID: "288",
|
|
Name: "代替パスまたはチャネルを使用した認証回避(CWE-288)",
|
|
Description: "",
|
|
ExtendedDescription: "",
|
|
Lang: "ja",
|
|
},
|
|
"384": {
|
|
CweID: "384",
|
|
Name: "セッションの固定化(CWE-384)",
|
|
Description: "",
|
|
ExtendedDescription: "",
|
|
Lang: "ja",
|
|
},
|
|
"89": {
|
|
CweID: "89",
|
|
Name: "SQLインジェクション(CWE-89)",
|
|
Description: "",
|
|
ExtendedDescription: "",
|
|
Lang: "ja",
|
|
},
|
|
"74": {
|
|
CweID: "74",
|
|
Name: "インジェクション(CWE-74)",
|
|
Description: "",
|
|
ExtendedDescription: "",
|
|
Lang: "ja",
|
|
},
|
|
"79": {
|
|
CweID: "79",
|
|
Name: "クロスサイトスクリプティング(CWE-79)",
|
|
Description: "",
|
|
ExtendedDescription: "",
|
|
Lang: "ja",
|
|
},
|
|
"601": {
|
|
CweID: "601",
|
|
Name: "オープンリダイレクト(CWE-601)",
|
|
Description: "",
|
|
ExtendedDescription: "",
|
|
Lang: "ja",
|
|
},
|
|
"352": {
|
|
CweID: "352",
|
|
Name: "クロスサイトリクエストフォージェリ(CWE-352)",
|
|
Description: "",
|
|
ExtendedDescription: "",
|
|
Lang: "ja",
|
|
},
|
|
"200": {
|
|
CweID: "200",
|
|
Name: "情報漏えい(CWE-200)",
|
|
Description: "",
|
|
ExtendedDescription: "",
|
|
Lang: "ja",
|
|
},
|
|
"285": {
|
|
CweID: "285",
|
|
Name: "不適切な認可(CWE-285)",
|
|
Description: "",
|
|
ExtendedDescription: "",
|
|
Lang: "ja",
|
|
},
|
|
"77": {
|
|
CweID: "77",
|
|
Name: "コマンドインジェクション(CWE-77)",
|
|
Description: "",
|
|
ExtendedDescription: "",
|
|
Lang: "ja",
|
|
},
|
|
"611": {
|
|
CweID: "611",
|
|
Name: "XML 外部エンティティ参照の不適切な制限(CWE-611)",
|
|
Description: "",
|
|
ExtendedDescription: "",
|
|
Lang: "ja",
|
|
},
|
|
"noinfo": {
|
|
CweID: "noinfo",
|
|
Name: "情報不足(CWE-noinfo)",
|
|
Description: "",
|
|
ExtendedDescription: "",
|
|
Lang: "ja",
|
|
},
|
|
"284": {
|
|
CweID: "284",
|
|
Name: "不適切なアクセス制御(CWE-284)",
|
|
Description: "",
|
|
ExtendedDescription: "",
|
|
Lang: "ja",
|
|
},
|
|
"190": {
|
|
CweID: "190",
|
|
Name: "整数オーバーフローまたはラップアラウンド(CWE-190)",
|
|
Description: "",
|
|
ExtendedDescription: "",
|
|
Lang: "ja",
|
|
},
|
|
"129": {
|
|
CweID: "129",
|
|
Name: "配列インデックスの不適切な検証(CWE-129)",
|
|
Description: "",
|
|
ExtendedDescription: "",
|
|
Lang: "ja",
|
|
},
|
|
"416": {
|
|
CweID: "416",
|
|
Name: "解放済みメモリの使用(CWE-416)",
|
|
Description: "",
|
|
ExtendedDescription: "",
|
|
Lang: "ja",
|
|
},
|
|
"918": {
|
|
CweID: "918",
|
|
Name: "サーバサイドのリクエストフォージェリ(CWE-918)",
|
|
Description: "",
|
|
ExtendedDescription: "",
|
|
Lang: "ja",
|
|
},
|
|
"22": {
|
|
CweID: "22",
|
|
Name: "パス・トラバーサル(CWE-22)",
|
|
Description: "",
|
|
ExtendedDescription: "",
|
|
Lang: "ja",
|
|
},
|
|
"78": {
|
|
CweID: "78",
|
|
Name: "OSコマンドインジェクション(CWE-78)",
|
|
Description: "",
|
|
ExtendedDescription: "",
|
|
Lang: "ja",
|
|
},
|
|
"287": {
|
|
CweID: "287",
|
|
Name: "不適切な認証(CWE-287)",
|
|
Description: "",
|
|
ExtendedDescription: "",
|
|
Lang: "ja",
|
|
},
|
|
"254": {
|
|
CweID: "254",
|
|
Name: "セキュリティ機能(CWE-254)",
|
|
Description: "",
|
|
ExtendedDescription: "",
|
|
Lang: "ja",
|
|
},
|
|
"798": {
|
|
CweID: "798",
|
|
Name: "ハードコードされた認証情報の使用(CWE-798)",
|
|
Description: "",
|
|
ExtendedDescription: "",
|
|
Lang: "ja",
|
|
},
|
|
"415": {
|
|
CweID: "415",
|
|
Name: "二重解放(CWE-415)",
|
|
Description: "",
|
|
ExtendedDescription: "",
|
|
Lang: "ja",
|
|
},
|
|
"399": {
|
|
CweID: "399",
|
|
Name: "リソース管理の問題(CWE-399)",
|
|
Description: "",
|
|
ExtendedDescription: "",
|
|
Lang: "ja",
|
|
},
|
|
"125": {
|
|
CweID: "125",
|
|
Name: "境界外読み取り(CWE-125)",
|
|
Description: "",
|
|
ExtendedDescription: "",
|
|
Lang: "ja",
|
|
},
|
|
"434": {
|
|
CweID: "434",
|
|
Name: "危険なタイプのファイルの無制限アップロード(CWE-434)",
|
|
Description: "",
|
|
ExtendedDescription: "",
|
|
Lang: "ja",
|
|
},
|
|
"295": {
|
|
CweID: "295",
|
|
Name: "不正な証明書検証(CWE-295)",
|
|
Description: "",
|
|
ExtendedDescription: "",
|
|
Lang: "ja",
|
|
},
|
|
"16": {
|
|
CweID: "16",
|
|
Name: "環境設定(CWE-16)",
|
|
Description: "",
|
|
ExtendedDescription: "",
|
|
Lang: "ja",
|
|
},
|
|
"172": {
|
|
CweID: "172",
|
|
Name: "エンコーディングエラー(CWE-172)",
|
|
Description: "",
|
|
ExtendedDescription: "",
|
|
Lang: "ja",
|
|
},
|
|
"134": {
|
|
CweID: "134",
|
|
Name: "書式文字列の問題(CWE-134)",
|
|
Description: "",
|
|
ExtendedDescription: "",
|
|
Lang: "ja",
|
|
},
|
|
"255": {
|
|
CweID: "255",
|
|
Name: "証明書・パスワードの管理(CWE-255)",
|
|
Description: "",
|
|
ExtendedDescription: "",
|
|
Lang: "ja",
|
|
},
|
|
"476": {
|
|
CweID: "476",
|
|
Name: "NULL ポインタデリファレンス(CWE-476)",
|
|
Description: "",
|
|
ExtendedDescription: "",
|
|
Lang: "ja",
|
|
},
|
|
"787": {
|
|
CweID: "787",
|
|
Name: "境界外書き込み(CWE-787)",
|
|
Description: "",
|
|
ExtendedDescription: "",
|
|
Lang: "ja",
|
|
},
|
|
"275": {
|
|
CweID: "275",
|
|
Name: "パーミッションの問題(CWE-275)",
|
|
Description: "",
|
|
ExtendedDescription: "",
|
|
Lang: "ja",
|
|
},
|
|
"502": {
|
|
CweID: "502",
|
|
Name: "信頼性のないデータのデシリアライゼーション(CWE-502)",
|
|
Description: "",
|
|
ExtendedDescription: "",
|
|
Lang: "ja",
|
|
},
|
|
"19": {
|
|
CweID: "19",
|
|
Name: "データ処理(CWE-19)",
|
|
Description: "",
|
|
ExtendedDescription: "",
|
|
Lang: "ja",
|
|
},
|
|
"94": {
|
|
CweID: "94",
|
|
Name: "コード・インジェクション(CWE-94)",
|
|
Description: "",
|
|
ExtendedDescription: "",
|
|
Lang: "ja",
|
|
},
|
|
"189": {
|
|
CweID: "189",
|
|
Name: "数値処理の問題(CWE-189)",
|
|
Description: "",
|
|
ExtendedDescription: "",
|
|
Lang: "ja",
|
|
},
|
|
"121": {
|
|
CweID: "121",
|
|
Name: "スタックベースのバッファオーバーフロー(CWE-121)",
|
|
Description: "",
|
|
ExtendedDescription: "",
|
|
Lang: "ja",
|
|
},
|
|
"326": {
|
|
CweID: "326",
|
|
Name: "不適切な暗号強度(CWE-326)",
|
|
Description: "",
|
|
ExtendedDescription: "",
|
|
Lang: "ja",
|
|
},
|
|
"532": {
|
|
CweID: "532",
|
|
Name: "ログファイルからの情報漏えい(CWE-532)",
|
|
Description: "",
|
|
ExtendedDescription: "",
|
|
Lang: "ja",
|
|
},
|
|
"320": {
|
|
CweID: "320",
|
|
Name: "鍵管理のエラー(CWE-320)",
|
|
Description: "",
|
|
ExtendedDescription: "",
|
|
Lang: "ja",
|
|
},
|
|
"306": {
|
|
CweID: "306",
|
|
Name: "重要な機能に対する認証の欠如(CWE-306)",
|
|
Description: "",
|
|
ExtendedDescription: "",
|
|
Lang: "ja",
|
|
},
|
|
"754": {
|
|
CweID: "754",
|
|
Name: "例外的な状態における不適切なチェック(CWE-754)",
|
|
Description: "",
|
|
ExtendedDescription: "",
|
|
Lang: "ja",
|
|
},
|
|
"613": {
|
|
CweID: "613",
|
|
Name: "不適切なセッション期限(CWE-613)",
|
|
Description: "",
|
|
ExtendedDescription: "",
|
|
Lang: "ja",
|
|
},
|
|
"400": {
|
|
CweID: "400",
|
|
Name: "リソースの枯渇(CWE-400)",
|
|
Description: "",
|
|
ExtendedDescription: "",
|
|
Lang: "ja",
|
|
},
|
|
"228": {
|
|
CweID: "228",
|
|
Name: "不正な構文構造の不適切な処理(CWE-228)",
|
|
Description: "",
|
|
ExtendedDescription: "",
|
|
Lang: "ja",
|
|
},
|
|
"428": {
|
|
CweID: "428",
|
|
Name: "引用されない検索パスまたは要素(CWE-428)",
|
|
Description: "",
|
|
ExtendedDescription: "",
|
|
Lang: "ja",
|
|
},
|
|
"184": {
|
|
CweID: "184",
|
|
Name: "不完全なブラックリスト(CWE-184)",
|
|
Description: "",
|
|
ExtendedDescription: "",
|
|
Lang: "ja",
|
|
},
|
|
"426": {
|
|
CweID: "426",
|
|
Name: "信頼性のない検索パス(CWE-426)",
|
|
Description: "",
|
|
ExtendedDescription: "",
|
|
Lang: "ja",
|
|
},
|
|
"347": {
|
|
CweID: "347",
|
|
Name: "デジタル署名の不適切な検証(CWE-347)",
|
|
Description: "",
|
|
ExtendedDescription: "",
|
|
Lang: "ja",
|
|
},
|
|
"345": {
|
|
CweID: "345",
|
|
Name: "データの信頼性についての不十分な検証(CWE-345)",
|
|
Description: "",
|
|
ExtendedDescription: "",
|
|
Lang: "ja",
|
|
},
|
|
"388": {
|
|
CweID: "388",
|
|
Name: "エラー処理(CWE-388)",
|
|
Description: "",
|
|
ExtendedDescription: "",
|
|
Lang: "ja",
|
|
},
|
|
"704": {
|
|
CweID: "704",
|
|
Name: "不正な型変換またはキャスト(CWE-704)",
|
|
Description: "",
|
|
ExtendedDescription: "",
|
|
Lang: "ja",
|
|
},
|
|
"369": {
|
|
CweID: "369",
|
|
Name: "ゼロ除算(CWE-369)",
|
|
Description: "",
|
|
ExtendedDescription: "",
|
|
Lang: "ja",
|
|
},
|
|
"122": {
|
|
CweID: "122",
|
|
Name: "ヒープベースのバッファオーバーフロー(CWE-122)",
|
|
Description: "",
|
|
ExtendedDescription: "",
|
|
Lang: "ja",
|
|
},
|
|
"824": {
|
|
CweID: "824",
|
|
Name: "初期化されていないポインタのアクセス(CWE-824)",
|
|
Description: "",
|
|
ExtendedDescription: "",
|
|
Lang: "ja",
|
|
},
|
|
"822": {
|
|
CweID: "822",
|
|
Name: "信頼性のないポインタデリファレンス(CWE-822)",
|
|
Description: "",
|
|
ExtendedDescription: "",
|
|
Lang: "ja",
|
|
},
|
|
"90": {
|
|
CweID: "90",
|
|
Name: "LDAP インジェクション(CWE-90)",
|
|
Description: "",
|
|
ExtendedDescription: "",
|
|
Lang: "ja",
|
|
},
|
|
"nocwe": {
|
|
CweID: "nocwe",
|
|
Name: "CWE以外(CWE-nocwe)",
|
|
Description: "",
|
|
ExtendedDescription: "",
|
|
Lang: "ja",
|
|
},
|
|
"330": {
|
|
CweID: "330",
|
|
Name: "不十分なランダム値の使用(CWE-330)",
|
|
Description: "",
|
|
ExtendedDescription: "",
|
|
Lang: "ja",
|
|
},
|
|
"91": {
|
|
CweID: "91",
|
|
Name: "ブラインド XPath インジェクション(CWE-91)",
|
|
Description: "",
|
|
ExtendedDescription: "",
|
|
Lang: "ja",
|
|
},
|
|
"404": {
|
|
CweID: "404",
|
|
Name: "リソースの不適切なシャットダウンおよびリリース(CWE-404)",
|
|
Description: "",
|
|
ExtendedDescription: "",
|
|
Lang: "ja",
|
|
},
|
|
"327": {
|
|
CweID: "327",
|
|
Name: "不完全、または危険な暗号アルゴリズムの使用(CWE-327)",
|
|
Description: "",
|
|
ExtendedDescription: "",
|
|
Lang: "ja",
|
|
},
|
|
"441": {
|
|
CweID: "441",
|
|
Name: "フィルタリング回避(CWE-441)",
|
|
Description: "",
|
|
ExtendedDescription: "",
|
|
Lang: "ja",
|
|
},
|
|
"294": {
|
|
CweID: "294",
|
|
Name: "Capture-replay による認証回避(CWE-294)",
|
|
Description: "",
|
|
ExtendedDescription: "",
|
|
Lang: "ja",
|
|
},
|
|
"821": {
|
|
CweID: "821",
|
|
Name: "不正な同期(CWE-821)",
|
|
Description: "",
|
|
ExtendedDescription: "",
|
|
Lang: "ja",
|
|
},
|
|
"835": {
|
|
CweID: "835",
|
|
Name: "無限ループ(CWE-835)",
|
|
Description: "",
|
|
ExtendedDescription: "",
|
|
Lang: "ja",
|
|
},
|
|
"123": {
|
|
CweID: "123",
|
|
Name: "任意の場所に任意の値を書き込むことができる状態(CWE-123)",
|
|
Description: "",
|
|
ExtendedDescription: "",
|
|
Lang: "ja",
|
|
},
|
|
"640": {
|
|
CweID: "640",
|
|
Name: "パスワードを忘れた場合の脆弱なパスワードリカバリの仕組み(CWE-640)",
|
|
Description: "",
|
|
ExtendedDescription: "",
|
|
Lang: "ja",
|
|
},
|
|
"93": {
|
|
CweID: "93",
|
|
Name: "CRLF インジェクション(CWE-93)",
|
|
Description: "",
|
|
ExtendedDescription: "",
|
|
Lang: "ja",
|
|
},
|
|
"361": {
|
|
CweID: "361",
|
|
Name: "時間とステータス(CWE-361)",
|
|
Description: "",
|
|
ExtendedDescription: "",
|
|
Lang: "ja",
|
|
},
|
|
"191": {
|
|
CweID: "191",
|
|
Name: "整数アンダーフロー(CWE-191)",
|
|
Description: "",
|
|
ExtendedDescription: "",
|
|
Lang: "ja",
|
|
},
|
|
"534": {
|
|
CweID: "534",
|
|
Name: "デバッグログファイルからの情報漏えい(CWE-534)",
|
|
Description: "",
|
|
ExtendedDescription: "",
|
|
Lang: "ja",
|
|
},
|
|
"331": {
|
|
CweID: "331",
|
|
Name: "エントロピー不足(CWE-331)",
|
|
Description: "",
|
|
ExtendedDescription: "",
|
|
Lang: "ja",
|
|
},
|
|
"113": {
|
|
CweID: "113",
|
|
Name: "HTTP レスポンスの分割(CWE-113)",
|
|
Description: "",
|
|
ExtendedDescription: "",
|
|
Lang: "ja",
|
|
},
|
|
"444": {
|
|
CweID: "444",
|
|
Name: "HTTP リクエストスマグリング(CWE-444)",
|
|
Description: "",
|
|
ExtendedDescription: "",
|
|
Lang: "ja",
|
|
},
|
|
"757": {
|
|
CweID: "757",
|
|
Name: "アルゴリズムのダウングレード(CWE-757)",
|
|
Description: "",
|
|
ExtendedDescription: "",
|
|
Lang: "ja",
|
|
},
|
|
"120": {
|
|
CweID: "120",
|
|
Name: "古典的バッファオーバーフロー(CWE-120)",
|
|
Description: "",
|
|
ExtendedDescription: "",
|
|
Lang: "ja",
|
|
},
|
|
"257": {
|
|
CweID: "257",
|
|
Name: "復元可能な形式でのパスワード保存(CWE-257)",
|
|
Description: "",
|
|
ExtendedDescription: "",
|
|
Lang: "ja",
|
|
},
|
|
"451": {
|
|
CweID: "451",
|
|
Name: "ユーザインターフェースにおける重要情報の誤った表示(CWE-451)",
|
|
Description: "",
|
|
ExtendedDescription: "",
|
|
Lang: "ja",
|
|
},
|
|
"775": {
|
|
CweID: "775",
|
|
Name: "有効期限後のファイル記述子またはハンドルの解放の欠如(CWE-775)",
|
|
Description: "",
|
|
ExtendedDescription: "",
|
|
Lang: "ja",
|
|
},
|
|
"332": {
|
|
CweID: "332",
|
|
Name: "PRNG における不十分なエントロピー(CWE-332)",
|
|
Description: "",
|
|
ExtendedDescription: "",
|
|
Lang: "ja",
|
|
},
|
|
"749": {
|
|
CweID: "749",
|
|
Name: "危険なメソッドや機能の公開(CWE-749)",
|
|
Description: "",
|
|
ExtendedDescription: "",
|
|
Lang: "ja",
|
|
},
|
|
"590": {
|
|
CweID: "590",
|
|
Name: "ヒープ領域の不適切な解放(CWE-590)",
|
|
Description: "",
|
|
ExtendedDescription: "",
|
|
Lang: "ja",
|
|
},
|
|
"290": {
|
|
CweID: "290",
|
|
Name: "スプーフィングによる認証回避(CWE-290)",
|
|
Description: "",
|
|
ExtendedDescription: "",
|
|
Lang: "ja",
|
|
},
|
|
"843": {
|
|
CweID: "843",
|
|
Name: "型の取り違え(CWE-843)",
|
|
Description: "",
|
|
ExtendedDescription: "",
|
|
Lang: "ja",
|
|
},
|
|
"417": {
|
|
CweID: "417",
|
|
Name: "チャネルおよびパスのエラー(CWE-417)",
|
|
Description: "",
|
|
ExtendedDescription: "",
|
|
Lang: "ja",
|
|
},
|
|
"410": {
|
|
CweID: "410",
|
|
Name: "不十分なリソースプール(CWE-410)",
|
|
Description: "",
|
|
ExtendedDescription: "",
|
|
Lang: "ja",
|
|
},
|
|
"18": {
|
|
CweID: "18",
|
|
Name: "ソースコード(CWE-18)",
|
|
Description: "",
|
|
ExtendedDescription: "",
|
|
Lang: "ja",
|
|
},
|
|
"605": {
|
|
CweID: "605",
|
|
Name: "同一ポートに複数のソケットをバインドする問題(CWE-605)",
|
|
Description: "",
|
|
ExtendedDescription: "",
|
|
Lang: "ja",
|
|
},
|
|
"682": {
|
|
CweID: "682",
|
|
Name: "計算の誤り(CWE-682)",
|
|
Description: "",
|
|
ExtendedDescription: "",
|
|
Lang: "ja",
|
|
},
|
|
"17": {
|
|
CweID: "17",
|
|
Name: "コード(CWE-17)",
|
|
Description: "",
|
|
ExtendedDescription: "",
|
|
Lang: "ja",
|
|
},
|
|
"338": {
|
|
CweID: "338",
|
|
Name: "暗号における脆弱な PRNG の使用(CWE-338)",
|
|
Description: "",
|
|
ExtendedDescription: "",
|
|
Lang: "ja",
|
|
},
|
|
"358": {
|
|
CweID: "358",
|
|
Name: "不適切に実装されたセキュリティチェック(CWE-358)",
|
|
Description: "",
|
|
ExtendedDescription: "",
|
|
Lang: "ja",
|
|
},
|
|
"674": {
|
|
CweID: "674",
|
|
Name: "不適切な再帰制御(CWE-674)",
|
|
Description: "",
|
|
ExtendedDescription: "",
|
|
Lang: "ja",
|
|
},
|
|
"412": {
|
|
CweID: "412",
|
|
Name: "外部からの操作の制限不備(CWE-412)",
|
|
Description: "",
|
|
ExtendedDescription: "",
|
|
Lang: "ja",
|
|
},
|
|
"378": {
|
|
CweID: "378",
|
|
Name: "不適切なアクセスパーミションでの一時ファイル作成(CWE-378)",
|
|
Description: "",
|
|
ExtendedDescription: "",
|
|
Lang: "ja",
|
|
},
|
|
"379": {
|
|
CweID: "379",
|
|
Name: "不適切なアクセスパーミションのディレクトリに一時ファイル作成(CWE-379)",
|
|
Description: "",
|
|
ExtendedDescription: "",
|
|
Lang: "ja",
|
|
},
|
|
"302": {
|
|
CweID: "302",
|
|
Name: "認証回避の脆弱性(CWE-302)",
|
|
Description: "",
|
|
ExtendedDescription: "",
|
|
Lang: "ja",
|
|
},
|
|
"75": {
|
|
CweID: "75",
|
|
Name: "特殊要素の不適切なサニタイジング(CWE-75)",
|
|
Description: "",
|
|
ExtendedDescription: "",
|
|
Lang: "ja",
|
|
},
|
|
"116": {
|
|
CweID: "116",
|
|
Name: "不適切なエンコード、または出力のエスケープ(CWE-116)",
|
|
Description: "",
|
|
ExtendedDescription: "",
|
|
Lang: "ja",
|
|
},
|
|
"346": {
|
|
CweID: "346",
|
|
Name: "同一生成元ポリシー違反(CWE-346)",
|
|
Description: "",
|
|
ExtendedDescription: "",
|
|
Lang: "ja",
|
|
},
|
|
"521": {
|
|
CweID: "521",
|
|
Name: "脆弱なパスワードの要求(CWE-521)",
|
|
Description: "",
|
|
ExtendedDescription: "",
|
|
Lang: "ja",
|
|
},
|
|
"664": {
|
|
CweID: "664",
|
|
Name: "ライフタイムを通してのリソースの不適切な制御(CWE-664)",
|
|
Description: "",
|
|
ExtendedDescription: "",
|
|
Lang: "ja",
|
|
},
|
|
"80": {
|
|
CweID: "80",
|
|
Name: "クロスサイトスクリプティング (Basic XSS)(CWE-80)",
|
|
Description: "",
|
|
ExtendedDescription: "",
|
|
Lang: "ja",
|
|
},
|
|
"204": {
|
|
CweID: "204",
|
|
Name: "リクエストに対するレスポンス内容の違いに起因する情報漏えい(CWE-204)",
|
|
Description: "",
|
|
ExtendedDescription: "",
|
|
Lang: "ja",
|
|
},
|
|
"199": {
|
|
CweID: "199",
|
|
Name: "情報管理の問題(CWE-199)",
|
|
Description: "",
|
|
ExtendedDescription: "",
|
|
Lang: "ja",
|
|
},
|
|
"88": {
|
|
CweID: "88",
|
|
Name: "引数の挿入または変更(CWE-88)",
|
|
Description: "",
|
|
ExtendedDescription: "",
|
|
Lang: "ja",
|
|
},
|
|
"407": {
|
|
CweID: "407",
|
|
Name: "アルゴリズムの複雑性(CWE-407)",
|
|
Description: "",
|
|
ExtendedDescription: "",
|
|
Lang: "ja",
|
|
},
|
|
"913": {
|
|
CweID: "913",
|
|
Name: "動的に操作されるコードリソースの不適切な制御(CWE-913)",
|
|
Description: "",
|
|
ExtendedDescription: "",
|
|
Lang: "ja",
|
|
},
|
|
"118": {
|
|
CweID: "118",
|
|
Name: "インデックス化が可能なリソースの不適切なアクセス (範囲エラー)(CWE-118)",
|
|
Description: "",
|
|
ExtendedDescription: "",
|
|
Lang: "ja",
|
|
},
|
|
"427": {
|
|
CweID: "427",
|
|
Name: "制御されていない検索パスの要素(CWE-427)",
|
|
Description: "",
|
|
ExtendedDescription: "",
|
|
Lang: "ja",
|
|
},
|
|
"485": {
|
|
CweID: "485",
|
|
Name: "不十分なカプセル化(CWE-485)",
|
|
Description: "",
|
|
ExtendedDescription: "",
|
|
Lang: "ja",
|
|
},
|
|
"494": {
|
|
CweID: "494",
|
|
Name: "ダウンロードしたコードの完全性検証不備(CWE-494)",
|
|
Description: "",
|
|
ExtendedDescription: "",
|
|
Lang: "ja",
|
|
},
|
|
"639": {
|
|
CweID: "639",
|
|
Name: "ユーザ制御の鍵による認証回避(CWE-639)",
|
|
Description: "",
|
|
ExtendedDescription: "",
|
|
Lang: "ja",
|
|
},
|
|
"99": {
|
|
CweID: "99",
|
|
Name: "リソースの挿入(CWE-99)",
|
|
Description: "",
|
|
ExtendedDescription: "",
|
|
Lang: "ja",
|
|
},
|
|
"276": {
|
|
CweID: "276",
|
|
Name: "不適切なデフォルトパーミッション(CWE-276)",
|
|
Description: "",
|
|
ExtendedDescription: "",
|
|
Lang: "ja",
|
|
},
|
|
"598": {
|
|
CweID: "598",
|
|
Name: "GET リクエストにおけるクエリ文字列からの情報漏えい(CWE-598)",
|
|
Description: "",
|
|
ExtendedDescription: "",
|
|
Lang: "ja",
|
|
},
|
|
"260": {
|
|
CweID: "260",
|
|
Name: "設定ファイル内のパスワード(CWE-260)",
|
|
Description: "",
|
|
ExtendedDescription: "",
|
|
Lang: "ja",
|
|
},
|
|
"836": {
|
|
CweID: "836",
|
|
Name: "パスワードの代わりにパスワードハッシュを使用する認証(CWE-836)",
|
|
Description: "",
|
|
ExtendedDescription: "",
|
|
Lang: "ja",
|
|
},
|
|
"943": {
|
|
CweID: "943",
|
|
Name: "データクエリロジックの特殊要素の不適切な中立化(CWE-943)",
|
|
Description: "",
|
|
ExtendedDescription: "",
|
|
Lang: "ja",
|
|
},
|
|
"665": {
|
|
CweID: "665",
|
|
Name: "不適切な初期化(CWE-665)",
|
|
Description: "",
|
|
ExtendedDescription: "",
|
|
Lang: "ja",
|
|
},
|
|
"769": {
|
|
CweID: "769",
|
|
Name: "ファイル記述子の枯渇(CWE-769)",
|
|
Description: "",
|
|
ExtendedDescription: "",
|
|
Lang: "ja",
|
|
},
|
|
"522": {
|
|
CweID: "522",
|
|
Name: "認証情報の不十分な保護(CWE-522)",
|
|
Description: "",
|
|
ExtendedDescription: "",
|
|
Lang: "ja",
|
|
},
|
|
"693": {
|
|
CweID: "693",
|
|
Name: "保護メカニズムの不具合(CWE-693)",
|
|
Description: "",
|
|
ExtendedDescription: "",
|
|
Lang: "ja",
|
|
},
|
|
"538": {
|
|
CweID: "538",
|
|
Name: "ファイルおよびディレクトリ情報の漏えい(CWE-538)",
|
|
Description: "",
|
|
ExtendedDescription: "",
|
|
Lang: "ja",
|
|
},
|
|
"863": {
|
|
CweID: "863",
|
|
Name: "不正な認証(CWE-863)",
|
|
Description: "",
|
|
ExtendedDescription: "",
|
|
Lang: "ja",
|
|
},
|
|
"862": {
|
|
CweID: "862",
|
|
Name: "認証の欠如(CWE-862)",
|
|
Description: "",
|
|
ExtendedDescription: "",
|
|
Lang: "ja",
|
|
},
|
|
"321": {
|
|
CweID: "321",
|
|
Name: "ハードコードされた暗号鍵の使用(CWE-321)",
|
|
Description: "",
|
|
ExtendedDescription: "",
|
|
Lang: "ja",
|
|
},
|
|
"1": {
|
|
CweID: "1",
|
|
Name: "ロケーション(CWE-1)",
|
|
Description: "",
|
|
ExtendedDescription: "",
|
|
Lang: "ja",
|
|
},
|
|
"354": {
|
|
CweID: "354",
|
|
Name: "データの整合性検証不備(CWE-354)",
|
|
Description: "",
|
|
ExtendedDescription: "",
|
|
Lang: "ja",
|
|
},
|
|
"552": {
|
|
CweID: "552",
|
|
Name: "外部からアクセス可能なファイルまたはディレクトリ(CWE-552)",
|
|
Description: "",
|
|
ExtendedDescription: "",
|
|
Lang: "ja",
|
|
},
|
|
"297": {
|
|
CweID: "297",
|
|
Name: "ホストの不一致による証明書の不適切な検証(CWE-297)",
|
|
Description: "",
|
|
ExtendedDescription: "",
|
|
Lang: "ja",
|
|
},
|
|
"150": {
|
|
CweID: "150",
|
|
Name: "エスケープ、メタ、またはコントロールシーケンスの不適切な無効化(CWE-150)",
|
|
Description: "",
|
|
ExtendedDescription: "",
|
|
Lang: "ja",
|
|
},
|
|
"371": {
|
|
CweID: "371",
|
|
Name: "状態の問題(CWE-371)",
|
|
Description: "",
|
|
ExtendedDescription: "",
|
|
Lang: "ja",
|
|
},
|
|
"203": {
|
|
CweID: "203",
|
|
Name: "セキュリティ関連の処理に対するレスポンスの違いに起因する情報漏えい(CWE-203)",
|
|
Description: "",
|
|
ExtendedDescription: "",
|
|
Lang: "ja",
|
|
},
|
|
"208": {
|
|
CweID: "208",
|
|
Name: "タイミングの違いに起因する情報漏えい(CWE-208)",
|
|
Description: "",
|
|
ExtendedDescription: "",
|
|
Lang: "ja",
|
|
},
|
|
"329": {
|
|
CweID: "329",
|
|
Name: "CBC モードにおけるランダムな初期化ベクトルの不使用(CWE-329)",
|
|
Description: "",
|
|
ExtendedDescription: "",
|
|
Lang: "ja",
|
|
},
|
|
"21": {
|
|
CweID: "21",
|
|
Name: "パス名トラバーサルおよび同値エラー(CWE-21)",
|
|
Description: "",
|
|
ExtendedDescription: "",
|
|
Lang: "ja",
|
|
},
|
|
}
|