CWE-546: Suspicious Comment
The code contains comments that suggest the presence of bugs, incomplete functionality, or weaknesses.
Browse cwe in documentation with official CWE context and Glexia analysis.
Search And Filters
Showing 8 of 8 CWE records.
The code contains comments that suggest the presence of bugs, incomplete functionality, or weaknesses.
The product specifies permissions for a security-critical resource in a way that allows that resource to be read or modified by unintended actors.
The product does not contain sufficient technical or engineering documentation (whether on paper or in electronic form) that contains descriptions of all the relevant software/hardware elements of the product, such as its usage, structure, architectural components, interfaces, design, implementation, configuration, operation, etc.
The product uses default passwords for potentially critical functionality.
A processor event or prediction may allow incorrect operations (or correct operations with incorrect data) to execute transiently, potentially exposing data over a covert channel.
A processor event or prediction may allow incorrect or stale data to be forwarded to transient operations, potentially exposing data over a covert channel.
Shared microarchitectural predictor state may allow code to influence transient execution across a hardware boundary, potentially exposing data that is accessible beyond the boundary over a covert channel.
The product has a component that relies on a generative AI/ML model configured with inference parameters that produce an unacceptably high rate of erroneous or unexpected outputs.