Memory String and Unmanaged Code
V5.4.1
Verify that the application uses memory-safe string, safer memory copy and pointer arithmetic to detect or prevent stack, buffer, or heap overflows.
Level 1 required: False
Level 2 required: True
Level 3 required: True
CWE: 120
V5.4.2
Verify that format strings do not take potentially hostile input, and are constant.
Level 1 required: False
Level 2 required: True
Level 3 required: True
CWE: 134
V5.4.3
Verify that sign, range, and input validation techniques are used to prevent integer overflows.
Level 1 required: False
Level 2 required: True
Level 3 required: True
CWE: 190
Disclaimer:
Credit via OWASP ASVS. For more information visit The OWASP ASVS Project or Github respository.. OWASP ASVS is under the Creative Commons Attribution-Share Alike v3.0 license.