...
Tool | Version | Checker | Description |
---|
Coverity | v7.5 | FORWARD_NULL NULL_RETURNS REVERSE_INULL FB.BC_NULL_INSTANCEOF FB.NP_ALWAYS_NULL FB.NP_ALWAYS_NULL_EXCEPTION FB.NP_ARGUMENT_MIGHT_BE_NULL FB.NP_BOOLEAN_RETURN_NULL FB.NP_CLONE_COULD_RETURN_NULL FB.NP_CLOSING_NULL FB.NP_DEREFERENCE_OF_ READLINE_VALUE FB.NP_DOES_NOT_HANDLE_NULL FB.NP_EQUALS_SHOULD_HANDLE_ NULL_ARGUMENT FB.NP_FIELD_NOT_INITIALIZED_ IN_CONSTRUCTOR FB.NP_GUARANTEED_DEREF FB.NP_GUARANTEED_DEREF_ON_ EXCEPTION_PATH FB.NP_IMMEDIATE_DEREFERENCE_ OF_READLINE FB.NP_LOAD_OF_KNOWN_NULL_ VALUE FB.NP_NONNULL_FIELD_NOT_ INITIALIZED_IN_CONSTRUCTOR FB.NP_NONNULL_PARAM_VIOLATION FB.NP_NONNULL_RETURN_VIOLATION FB.NP_NULL_INSTANCEOF FB.NP_NULL_ON_SOME_PATH FB.NP_NULL_ON_SOME_PATH_ EXCEPTION FB.NP_NULL_ON_SOME_PATH_ FROM_RETURN_VALUE FB.NP_NULL_ON_SOME_PATH_ MIGHT_BE_INFEASIBLE FB.NP_NULL_PARAM_DEREF FB.NP_NULL_PARAM_DEREF_ALL_ TARGETS_DANGEROUS FB.NP_NULL_PARAM_DEREF_ NONVIRTUAL FB.NP_PARAMETER_MUST_BE_NON - NULL_BUT_MARKED_AS_NULLABLE FB.NP_STORE_INTO_NONNULL_FIELD FB.NP_TOSTRING_COULD_ RETURN_NULL FB.NP_UNWRITTEN_FIELD FB.NP_UNWRITTEN_PUBLIC_OR_ PROTECTED_FIELD FB.RCN_REDUNDANT_COMPARISON_ OF_NULL_AND_NONNULL_VALUE FB.RCN_REDUNDANT_COMPARISON_ TWO_NULL_VALUES FB.RCN_REDUNDANT_NULLCHECK_ OF_NONNULL_VALUE FB.RCN_REDUNDANT_NULLCHECK_ OF_NULL_VALUE FB.RCN_REDUNDANT_NULLCHECK_ WOULD_HAVE_BEEN_A_NPE | Implemented |
Fortify | | Missing_Check_against_Null Null_Dereference Redundant_Null_Check | Implemented |
Findbugs | | NP_DEREFERENCE_OF_READLINE_VALUE NP_NULL_PARAM_DEREF NP_TOSTRING_COULD_RETURN_NULL | Implemented |
Parasoft Jtest | 9.5 | BD.EXCEPT.NP, PB-RE-NMCD | |
Related Vulnerabilities
Java Web Start applications and applets particular to JDK version 1.6, prior to update 4, were affected by a bug that had some noteworthy security consequences. In some isolated cases, the application or applet's attempt to establish an HTTPS connection with a server generated a NullPointerException
[SDN 2008]. The resulting failure to establish a secure HTTPS connection with the server caused a denial of service. Clients were temporarily forced to use an insecure HTTP channel for data exchange.
...