Movatterモバイル変換


[0]ホーム

URL:


CodeQL documentation
CodeQL resources

CWE coverage for Swift

An overview of CWE coverage for Swift in the latest release of CodeQL.

Overview

CWELanguageQuery idQuery name
CWE-20Swiftswift/incomplete-hostname-regexpIncomplete regular expression for hostnames
CWE-20Swiftswift/missing-regexp-anchorMissing regular expression anchor
CWE-20Swiftswift/bad-tag-filterBad HTML filtering regexp
CWE-22Swiftswift/unsafe-unpackingArbitrary file write during a zip extraction from a user controlled source
CWE-22Swiftswift/path-injectionUncontrolled data used in path expression
CWE-23Swiftswift/path-injectionUncontrolled data used in path expression
CWE-36Swiftswift/path-injectionUncontrolled data used in path expression
CWE-73Swiftswift/path-injectionUncontrolled data used in path expression
CWE-74Swiftswift/path-injectionUncontrolled data used in path expression
CWE-74Swiftswift/command-line-injectionSystem command built from user-controlled sources
CWE-74Swiftswift/unsafe-webview-fetchUnsafe WebView fetch
CWE-74Swiftswift/sql-injectionDatabase query built from user-controlled sources
CWE-74Swiftswift/unsafe-js-evalJavaScript Injection
CWE-74Swiftswift/uncontrolled-format-stringUncontrolled format string
CWE-74Swiftswift/predicate-injectionPredicate built from user-controlled sources
CWE-77Swiftswift/command-line-injectionSystem command built from user-controlled sources
CWE-78Swiftswift/command-line-injectionSystem command built from user-controlled sources
CWE-79Swiftswift/unsafe-webview-fetchUnsafe WebView fetch
CWE-88Swiftswift/command-line-injectionSystem command built from user-controlled sources
CWE-89Swiftswift/sql-injectionDatabase query built from user-controlled sources
CWE-94Swiftswift/unsafe-webview-fetchUnsafe WebView fetch
CWE-94Swiftswift/unsafe-js-evalJavaScript Injection
CWE-95Swiftswift/unsafe-webview-fetchUnsafe WebView fetch
CWE-95Swiftswift/unsafe-js-evalJavaScript Injection
CWE-99Swiftswift/path-injectionUncontrolled data used in path expression
CWE-116Swiftswift/bad-tag-filterBad HTML filtering regexp
CWE-134Swiftswift/uncontrolled-format-stringUncontrolled format string
CWE-135Swiftswift/string-length-conflationString length conflation
CWE-185Swiftswift/bad-tag-filterBad HTML filtering regexp
CWE-186Swiftswift/bad-tag-filterBad HTML filtering regexp
CWE-200Swiftswift/cleartext-loggingCleartext logging of sensitive information
CWE-227Swiftswift/static-initialization-vectorStatic initialization vector for encryption
CWE-259Swiftswift/constant-passwordConstant password
CWE-284Swiftswift/constant-passwordConstant password
CWE-284Swiftswift/hardcoded-keyHard-coded encryption key
CWE-287Swiftswift/constant-passwordConstant password
CWE-287Swiftswift/hardcoded-keyHard-coded encryption key
CWE-311Swiftswift/cleartext-storage-databaseCleartext storage of sensitive information in a local database
CWE-311Swiftswift/cleartext-transmissionCleartext transmission of sensitive information
CWE-311Swiftswift/cleartext-loggingCleartext logging of sensitive information
CWE-311Swiftswift/cleartext-storage-preferencesCleartext storage of sensitive information in an application preference store
CWE-312Swiftswift/cleartext-storage-databaseCleartext storage of sensitive information in a local database
CWE-312Swiftswift/cleartext-loggingCleartext logging of sensitive information
CWE-312Swiftswift/cleartext-storage-preferencesCleartext storage of sensitive information in an application preference store
CWE-319Swiftswift/cleartext-transmissionCleartext transmission of sensitive information
CWE-321Swiftswift/hardcoded-keyHard-coded encryption key
CWE-326Swiftswift/weak-password-hashingUse of an inappropriate cryptographic hashing algorithm on passwords
CWE-326Swiftswift/weak-sensitive-data-hashingUse of a broken or weak cryptographic hashing algorithm on sensitive data
CWE-327Swiftswift/ecb-encryptionEncryption using ECB
CWE-327Swiftswift/weak-password-hashingUse of an inappropriate cryptographic hashing algorithm on passwords
CWE-327Swiftswift/weak-sensitive-data-hashingUse of a broken or weak cryptographic hashing algorithm on sensitive data
CWE-327Swiftswift/constant-saltUse of constant salts
CWE-327Swiftswift/insufficient-hash-iterationsInsufficient hash iterations
CWE-328Swiftswift/weak-password-hashingUse of an inappropriate cryptographic hashing algorithm on passwords
CWE-328Swiftswift/weak-sensitive-data-hashingUse of a broken or weak cryptographic hashing algorithm on sensitive data
CWE-329Swiftswift/static-initialization-vectorStatic initialization vector for encryption
CWE-330Swiftswift/static-initialization-vectorStatic initialization vector for encryption
CWE-330Swiftswift/constant-passwordConstant password
CWE-330Swiftswift/hardcoded-keyHard-coded encryption key
CWE-344Swiftswift/constant-passwordConstant password
CWE-344Swiftswift/hardcoded-keyHard-coded encryption key
CWE-359Swiftswift/cleartext-loggingCleartext logging of sensitive information
CWE-400Swiftswift/redosInefficient regular expression
CWE-400Swiftswift/regex-injectionRegular expression injection
CWE-405Swiftswift/xxeResolving XML external entity in user-controlled data
CWE-409Swiftswift/xxeResolving XML external entity in user-controlled data
CWE-485Swiftswift/unsafe-webview-fetchUnsafe WebView fetch
CWE-485Swiftswift/unsafe-js-evalJavaScript Injection
CWE-532Swiftswift/cleartext-loggingCleartext logging of sensitive information
CWE-538Swiftswift/cleartext-loggingCleartext logging of sensitive information
CWE-552Swiftswift/cleartext-loggingCleartext logging of sensitive information
CWE-573Swiftswift/static-initialization-vectorStatic initialization vector for encryption
CWE-610Swiftswift/path-injectionUncontrolled data used in path expression
CWE-610Swiftswift/xxeResolving XML external entity in user-controlled data
CWE-611Swiftswift/xxeResolving XML external entity in user-controlled data
CWE-642Swiftswift/path-injectionUncontrolled data used in path expression
CWE-657Swiftswift/constant-passwordConstant password
CWE-657Swiftswift/hardcoded-keyHard-coded encryption key
CWE-664Swiftswift/unsafe-unpackingArbitrary file write during a zip extraction from a user controlled source
CWE-664Swiftswift/path-injectionUncontrolled data used in path expression
CWE-664Swiftswift/unsafe-webview-fetchUnsafe WebView fetch
CWE-664Swiftswift/unsafe-js-evalJavaScript Injection
CWE-664Swiftswift/redosInefficient regular expression
CWE-664Swiftswift/constant-passwordConstant password
CWE-664Swiftswift/cleartext-storage-databaseCleartext storage of sensitive information in a local database
CWE-664Swiftswift/cleartext-loggingCleartext logging of sensitive information
CWE-664Swiftswift/cleartext-storage-preferencesCleartext storage of sensitive information in an application preference store
CWE-664Swiftswift/hardcoded-keyHard-coded encryption key
CWE-664Swiftswift/xxeResolving XML external entity in user-controlled data
CWE-664Swiftswift/regex-injectionRegular expression injection
CWE-668Swiftswift/unsafe-unpackingArbitrary file write during a zip extraction from a user controlled source
CWE-668Swiftswift/path-injectionUncontrolled data used in path expression
CWE-668Swiftswift/cleartext-loggingCleartext logging of sensitive information
CWE-669Swiftswift/xxeResolving XML external entity in user-controlled data
CWE-671Swiftswift/constant-passwordConstant password
CWE-671Swiftswift/hardcoded-keyHard-coded encryption key
CWE-674Swiftswift/xxeResolving XML external entity in user-controlled data
CWE-682Swiftswift/string-length-conflationString length conflation
CWE-691Swiftswift/unsafe-webview-fetchUnsafe WebView fetch
CWE-691Swiftswift/unsafe-js-evalJavaScript Injection
CWE-691Swiftswift/xxeResolving XML external entity in user-controlled data
CWE-693Swiftswift/incomplete-hostname-regexpIncomplete regular expression for hostnames
CWE-693Swiftswift/missing-regexp-anchorMissing regular expression anchor
CWE-693Swiftswift/bad-tag-filterBad HTML filtering regexp
CWE-693Swiftswift/constant-passwordConstant password
CWE-693Swiftswift/cleartext-storage-databaseCleartext storage of sensitive information in a local database
CWE-693Swiftswift/cleartext-transmissionCleartext transmission of sensitive information
CWE-693Swiftswift/cleartext-loggingCleartext logging of sensitive information
CWE-693Swiftswift/cleartext-storage-preferencesCleartext storage of sensitive information in an application preference store
CWE-693Swiftswift/hardcoded-keyHard-coded encryption key
CWE-693Swiftswift/ecb-encryptionEncryption using ECB
CWE-693Swiftswift/weak-password-hashingUse of an inappropriate cryptographic hashing algorithm on passwords
CWE-693Swiftswift/weak-sensitive-data-hashingUse of a broken or weak cryptographic hashing algorithm on sensitive data
CWE-693Swiftswift/insecure-tlsInsecure TLS configuration
CWE-693Swiftswift/constant-saltUse of constant salts
CWE-693Swiftswift/insufficient-hash-iterationsInsufficient hash iterations
CWE-697Swiftswift/bad-tag-filterBad HTML filtering regexp
CWE-706Swiftswift/unsafe-unpackingArbitrary file write during a zip extraction from a user controlled source
CWE-706Swiftswift/path-injectionUncontrolled data used in path expression
CWE-706Swiftswift/xxeResolving XML external entity in user-controlled data
CWE-707Swiftswift/path-injectionUncontrolled data used in path expression
CWE-707Swiftswift/command-line-injectionSystem command built from user-controlled sources
CWE-707Swiftswift/unsafe-webview-fetchUnsafe WebView fetch
CWE-707Swiftswift/sql-injectionDatabase query built from user-controlled sources
CWE-707Swiftswift/unsafe-js-evalJavaScript Injection
CWE-707Swiftswift/bad-tag-filterBad HTML filtering regexp
CWE-707Swiftswift/uncontrolled-format-stringUncontrolled format string
CWE-707Swiftswift/predicate-injectionPredicate built from user-controlled sources
CWE-710Swiftswift/static-initialization-vectorStatic initialization vector for encryption
CWE-710Swiftswift/constant-passwordConstant password
CWE-710Swiftswift/hardcoded-keyHard-coded encryption key
CWE-749Swiftswift/unsafe-webview-fetchUnsafe WebView fetch
CWE-749Swiftswift/unsafe-js-evalJavaScript Injection
CWE-757Swiftswift/insecure-tlsInsecure TLS configuration
CWE-760Swiftswift/constant-saltUse of constant salts
CWE-776Swiftswift/xxeResolving XML external entity in user-controlled data
CWE-798Swiftswift/constant-passwordConstant password
CWE-798Swiftswift/hardcoded-keyHard-coded encryption key
CWE-827Swiftswift/xxeResolving XML external entity in user-controlled data
CWE-829Swiftswift/xxeResolving XML external entity in user-controlled data
CWE-834Swiftswift/xxeResolving XML external entity in user-controlled data
CWE-913Swiftswift/unsafe-webview-fetchUnsafe WebView fetch
CWE-913Swiftswift/unsafe-js-evalJavaScript Injection
CWE-916Swiftswift/weak-password-hashingUse of an inappropriate cryptographic hashing algorithm on passwords
CWE-916Swiftswift/constant-saltUse of constant salts
CWE-916Swiftswift/insufficient-hash-iterationsInsufficient hash iterations
CWE-922Swiftswift/cleartext-storage-databaseCleartext storage of sensitive information in a local database
CWE-922Swiftswift/cleartext-loggingCleartext logging of sensitive information
CWE-922Swiftswift/cleartext-storage-preferencesCleartext storage of sensitive information in an application preference store
CWE-943Swiftswift/sql-injectionDatabase query built from user-controlled sources
CWE-943Swiftswift/predicate-injectionPredicate built from user-controlled sources
CWE-1204Swiftswift/static-initialization-vectorStatic initialization vector for encryption
CWE-1333Swiftswift/redosInefficient regular expression

[8]ページ先頭

©2009-2025 Movatter.jp