Improper Handling of Missing Values |
Weakness ID: 230 (Weakness Base) | Status: Draft |
Description Summary
The software does not handle or incorrectly handles when a parameter, field, or argument name is specified, but the associated value is missing, i.e. it is empty, blank, or null.
Reference | Description |
---|---|
CVE-2002-0422 | Blank Host header triggers resultant infoleak. |
CVE-2000-1006 | Blank "charset" attribute in MIME header triggers crash. |
CVE-2004-1504 | Blank parameter causes external error infoleak. |
CVE-2005-2053 | Blank parameter causes external error infoleak. |
Nature | Type | ID | Name | View(s) this relationship pertains to![]() |
---|---|---|---|---|
ChildOf | ![]() | 229 | Improper Handling of Values | Development Concepts (primary)699 Research Concepts (primary)1000 |
Some "crash by port scan" bugs are probably due to this, but lack of diagnosis makes it difficult to be certain. |
Submissions | ||||
---|---|---|---|---|
Submission Date | Submitter | Organization | Source | |
PLOVER | Externally Mined | |||
Modifications | ||||
Modification Date | Modifier | Organization | Source | |
2008-07-01 | Eric Dalci | Cigital | External | |
updated Time of Introduction | ||||
2008-09-08 | CWE Content Team | MITRE | Internal | |
updated Relationships, Other Notes, Taxonomy Mappings | ||||
2009-03-10 | CWE Content Team | MITRE | Internal | |
updated Description, Name | ||||
2009-10-29 | CWE Content Team | MITRE | Internal | |
updated Other Notes, Research Gaps | ||||
Previous Entry Names | ||||
Change Date | Previous Entry Name | |||
2008-04-11 | Missing Value Error | |||
2009-03-10 | Failure to Handle Missing Value | |||