Flawfinder version 2.0.10, (C) 2001-2019 David A. Wheeler. Number of rules (primarily dangerous function names) in C/C++ ruleset: 223 Examining data/kompare-20.04.3/kompare_shell.cpp Examining data/kompare-20.04.3/kompareurldialog.cpp Examining data/kompare-20.04.3/kompareurldialog.h Examining data/kompare-20.04.3/libdialogpages/viewpage.h Examining data/kompare-20.04.3/libdialogpages/viewsettings.cpp Examining data/kompare-20.04.3/libdialogpages/diffpage.h Examining data/kompare-20.04.3/libdialogpages/viewpage.cpp Examining data/kompare-20.04.3/libdialogpages/filessettings.cpp Examining data/kompare-20.04.3/libdialogpages/filessettings.h Examining data/kompare-20.04.3/libdialogpages/viewsettings.h Examining data/kompare-20.04.3/libdialogpages/filespage.cpp Examining data/kompare-20.04.3/libdialogpages/diffpage.cpp Examining data/kompare-20.04.3/libdialogpages/filespage.h Examining data/kompare-20.04.3/kompare_shell.h Examining data/kompare-20.04.3/main.cpp Examining data/kompare-20.04.3/komparenavtreepart/komparenavtreepart.cpp Examining data/kompare-20.04.3/komparenavtreepart/komparenavtreepart.h Examining data/kompare-20.04.3/interfaces/kompareinterface.cpp Examining data/kompare-20.04.3/interfaces/kompareinterface.h Examining data/kompare-20.04.3/komparepart/komparesaveoptionsbase.cpp Examining data/kompare-20.04.3/komparepart/komparesaveoptionsbase.h Examining data/kompare-20.04.3/komparepart/komparesaveoptionswidget.cpp Examining data/kompare-20.04.3/komparepart/kompareview.cpp Examining data/kompare-20.04.3/komparepart/komparelistview.h Examining data/kompare-20.04.3/komparepart/komparesplitter.cpp Examining data/kompare-20.04.3/komparepart/kompareview.h Examining data/kompare-20.04.3/komparepart/kompare_part.cpp Examining data/kompare-20.04.3/komparepart/kompare_part.h Examining data/kompare-20.04.3/komparepart/komparelistview.cpp Examining data/kompare-20.04.3/komparepart/kompare_partfactory.cpp Examining data/kompare-20.04.3/komparepart/kompareprefdlg.cpp Examining data/kompare-20.04.3/komparepart/kompareprefdlg.h Examining data/kompare-20.04.3/komparepart/kompareconnectwidget.cpp Examining data/kompare-20.04.3/komparepart/komparesplitter.h Examining data/kompare-20.04.3/komparepart/kompare_partfactory.h Examining data/kompare-20.04.3/komparepart/kompareconnectwidget.h Examining data/kompare-20.04.3/komparepart/komparesaveoptionswidget.h FINAL RESULTS: data/kompare-20.04.3/kompare_shell.cpp:173:10: [2] (misc) open: Check when opening files - can an attacker redirect it (via symlinks), force the opening of special file type (e.g., device files), move things around to create a race condition, control its ancestors, or change its contents? (CWE-362). file.open(stdin, QIODevice::ReadOnly); data/kompare-20.04.3/kompare_shell.cpp:203:26: [2] (misc) open: Check when opening files - can an attacker redirect it (via symlinks), force the opening of special file type (e.g., device files), move things around to create a race condition, control its ancestors, or change its contents? (CWE-362). a = KStandardAction::open(this, &KompareShell::slotFileOpen, actionCollection()); data/kompare-20.04.3/libdialogpages/filespage.cpp:52:62: [2] (misc) open: Check when opening files - can an attacker redirect it (via symlinks), force the opening of special file type (e.g., device files), move things around to create a race condition, control its ancestors, or change its contents? (CWE-362). connect(button, &QPushButton::clicked, this, &FilesPage::open); data/kompare-20.04.3/libdialogpages/filespage.cpp:64:62: [2] (misc) open: Check when opening files - can an attacker redirect it (via symlinks), force the opening of special file type (e.g., device files), move things around to create a race condition, control its ancestors, or change its contents? (CWE-362). connect(button, &QPushButton::clicked, this, &FilesPage::open); data/kompare-20.04.3/libdialogpages/filespage.cpp:81:62: [2] (misc) open: Check when opening files - can an attacker redirect it (via symlinks), force the opening of special file type (e.g., device files), move things around to create a race condition, control its ancestors, or change its contents? (CWE-362). connect(button, &QPushButton::clicked, this, &FilesPage::open); data/kompare-20.04.3/libdialogpages/filespage.cpp:93:62: [2] (misc) open: Check when opening files - can an attacker redirect it (via symlinks), force the opening of special file type (e.g., device files), move things around to create a race condition, control its ancestors, or change its contents? (CWE-362). connect(button, &QPushButton::clicked, this, &FilesPage::open); data/kompare-20.04.3/libdialogpages/filespage.cpp:122:17: [2] (misc) open: Check when opening files - can an attacker redirect it (via symlinks), force the opening of special file type (e.g., device files), move things around to create a race condition, control its ancestors, or change its contents? (CWE-362). void FilesPage::open() data/kompare-20.04.3/libdialogpages/filespage.h:69:10: [2] (misc) open: Check when opening files - can an attacker redirect it (via symlinks), force the opening of special file type (e.g., device files), move things around to create a race condition, control its ancestors, or change its contents? (CWE-362). void open(); ANALYSIS SUMMARY: Hits = 8 Lines analyzed = 7795 in approximately 1.36 seconds (5749 lines/second) Physical Source Lines of Code (SLOC) = 5447 Hits@level = [0] 0 [1] 0 [2] 8 [3] 0 [4] 0 [5] 0 Hits@level+ = [0+] 8 [1+] 8 [2+] 8 [3+] 0 [4+] 0 [5+] 0 Hits/KSLOC@level+ = [0+] 1.4687 [1+] 1.4687 [2+] 1.4687 [3+] 0 [4+] 0 [5+] 0 Dot directories skipped = 1 (--followdotdir overrides) Minimum risk level = 1 Not every hit is necessarily a security vulnerability. There may be other security vulnerabilities; review your code! See 'Secure Programming HOWTO' (https://dwheeler.com/secure-programs) for more information.