CWE-1038: Insecure Automated Optimizations
ID
CWE-1038
Abstraction
Class
Structure
Simple
Status
Draft
Number of CVEs
2
The product uses a mechanism that automatically optimizes code, e.g. to improve a characteristic such as performance, but the optimizations can have an unintended side effect that might violate an intended security assumption.
Modes of Introduction
Phase | Note |
---|---|
Architecture and Design | Optimizations built into the design of a product can have unintended consequences during execution. |
Applicable Platforms
Type | Class | Name | Prevalence |
---|---|---|---|
Language | Not Language-Specific |
Relationships
View | Weakness | |||||||
---|---|---|---|---|---|---|---|---|
# ID | View | Status | # ID | Name | Abstraction | Structure | Status | |
CWE-1000 | Research Concepts | Draft | CWE-435 | Improper Interaction Between Multiple Correctly-Behaving Entities | Pillar | Simple | Draft | |
CWE-1000 | Research Concepts | Draft | CWE-758 | Reliance on Undefined, Unspecified, or Implementation-Defined Behavior | Class | Simple | Incomplete |
CVEs Published
CVSS Severity
CVSS Severity - By Year
CVSS Base Score
# CVE | Description | CVSS | EPSS | EPSS Trend (30 days) | Affected Products | Weaknesses | Security Advisories | Exploits | PoC | Pubblication Date | Modification Date |
---|---|---|---|---|---|---|---|---|---|---|---|
# CVE | Description | CVSS | EPSS | EPSS Trend (30 days) | Affected Products | Weaknesses | Security Advisories | PoC | Pubblication Date | Modification Date |
Loading...