Expected Behavior Violation |
Weakness ID: 440 (Weakness Base) | Status: Draft |
Description Summary
A feature, API, or function being used by a product behaves differently than the product expects.
Reference | Description |
---|---|
CVE-2003-0187 | Inconsistency in support of linked lists causes program to use large timeouts on "undeserving" connections. |
CVE-2003-0465 | "strncpy" in Linux kernel acts different than libc on x86, leading to expected behavior difference - sort of a multiple interpretation error? |
CVE-2005-3265 | Buffer overflow in product stems to the use of a third party library function that is expected to have internal protection against overflows, but doesn't. |
Nature | Type | ID | Name | View(s) this relationship pertains to![]() |
---|---|---|---|---|
ChildOf | ![]() | 438 | Behavioral Problems | Development Concepts (primary)699 |
ChildOf | ![]() | 684 | Failure to Provide Specified Functionality | Research Concepts (primary)1000 |
The consistency dimension of validity is the most appropriate relevant property of an expected behavior violation. That is, the behavior of the application is not consistent with the expectations of the developer, leading to a violation of the validity property of the software. |
Submissions | ||||
---|---|---|---|---|
Submission Date | Submitter | Organization | Source | |
PLOVER | Externally Mined | |||
Modifications | ||||
Modification Date | Modifier | Organization | Source | |
2008-07-01 | Eric Dalci | Cigital | External | |
updated Time of Introduction | ||||
2008-09-08 | CWE Content Team | MITRE | Internal | |
updated Relationships, Other Notes, Taxonomy Mappings | ||||
2009-10-29 | CWE Content Team | MITRE | Internal | |
updated Other Notes, Relevant Properties, Theoretical Notes |