The patterns behind every CVE

A CVE is one bug. A CWE is the root-cause pattern that let it happen — learn one and you’ll recognise it the next time it shows up wearing a different CVE ID.

969
Weaknesses catalogued
CWENameAbstractionCVEs mapped
CWE-1304Improperly Preserved Integrity of Hardware Configuration State During a Power Save/Restore OperationBase2
CWE-131Incorrect Calculation of Buffer SizeBase127
CWE-1310Missing Ability to Patch ROM CodeBase2
CWE-1311Improper Translation of Security Attributes by Fabric BridgeBase0
CWE-1312Missing Protection for Mirrored Regions in On-Chip Fabric FirewallBase1
CWE-1313Hardware Allows Activation of Test or Debug Logic at RuntimeBase1
CWE-1314Missing Write Protection for Parametric Data ValuesBase1
CWE-1315Improper Setting of Bus Controlling Capability in Fabric End-pointBase0
CWE-1316Fabric-Address Map Allows Programming of Unwarranted Overlaps of Protected and Unprotected RangesBase1
CWE-1317Improper Access Control in Fabric BridgeBase0
CWE-1318Missing Support for Security Features in On-chip Fabrics or BusesBase0
CWE-1319Improper Protection against Electromagnetic Fault Injection (EM-FI)Base4
CWE-132DEPRECATED: Miscalculated Null TerminationBase0
CWE-1320Improper Protection for Outbound Error Messages and Alert SignalsBase6
CWE-1321Improperly Controlled Modification of Object Prototype Attributes ('Prototype Pollution')Variant253
CWE-1322Use of Blocking Code in Single-threaded, Non-blocking ContextBase3
CWE-1323Improper Management of Sensitive Trace DataBase2
CWE-1324DEPRECATED: Sensitive Information Accessible by Physical Probing of JTAG InterfaceBase0
CWE-1325Improperly Controlled Sequential Memory AllocationBase19
CWE-1326Missing Immutable Root of Trust in HardwareBase9
Page 12 of 49 · 969 total