Flawfinder version 2.0.10, (C) 2001-2019 David A. Wheeler. Number of rules (primarily dangerous function names) in C/C++ ruleset: 223 Examining data/gnumail-1.3.0/Framework/GNUMail/PreferencesWindow.h Examining data/gnumail-1.3.0/Framework/GNUMail/ExtendedTableView.h Examining data/gnumail-1.3.0/Framework/GNUMail/GNUMail+MenuValidation.h Examining data/gnumail-1.3.0/Framework/GNUMail/NSPasteboard+Extensions.h Examining data/gnumail-1.3.0/Framework/GNUMail/ApplicationIconController.h Examining data/gnumail-1.3.0/Framework/GNUMail/ImageTextCell.h Examining data/gnumail-1.3.0/Framework/GNUMail/NSAttributedString+Extensions.h Examining data/gnumail-1.3.0/Framework/GNUMail/NavigationToolbarItem.h Examining data/gnumail-1.3.0/Framework/GNUMail/NSUserDefaults+Extensions.h Examining data/gnumail-1.3.0/Framework/GNUMail/AutoCompletingTextField.h Examining data/gnumail-1.3.0/Framework/GNUMail/MailboxInspectorPanelController.h Examining data/gnumail-1.3.0/Framework/GNUMail/NewMailboxPanel.h Examining data/gnumail-1.3.0/Framework/GNUMail/MailboxManagerController.h Examining data/gnumail-1.3.0/Framework/GNUMail/ExtendedOutlineView.h Examining data/gnumail-1.3.0/Framework/GNUMail/AboutPanelController.h Examining data/gnumail-1.3.0/Framework/GNUMail/Constants.h Examining data/gnumail-1.3.0/Framework/GNUMail/EditWindowToolbar.h Examining data/gnumail-1.3.0/Framework/GNUMail/ExtendedFileWrapper.h Examining data/gnumail-1.3.0/Framework/GNUMail/MailboxInspectorPanel.h Examining data/gnumail-1.3.0/Framework/GNUMail/PreferencesModule.h Examining data/gnumail-1.3.0/Framework/GNUMail/FindWindowController.h Examining data/gnumail-1.3.0/Framework/GNUMail/AddressTaker.h Examining data/gnumail-1.3.0/Framework/GNUMail/ExtendedTextAttachmentCell.h Examining data/gnumail-1.3.0/Framework/GNUMail/EditWindowController.h Examining data/gnumail-1.3.0/Framework/GNUMail/MimeType.h Examining data/gnumail-1.3.0/Framework/GNUMail/MailboxManager.h Examining data/gnumail-1.3.0/Framework/GNUMail/NSBezierPath+Extensions.h Examining data/gnumail-1.3.0/Framework/GNUMail/GNUMail.h Examining data/gnumail-1.3.0/Framework/GNUMail/ExtendedMenuItem.h Examining data/gnumail-1.3.0/Framework/GNUMail/STScriptingSupport.h Examining data/gnumail-1.3.0/Framework/GNUMail/MailboxManagerCache.h Examining data/gnumail-1.3.0/Framework/GNUMail/LabelWidget.h Examining data/gnumail-1.3.0/Framework/GNUMail/MimeTypeManager.h Examining data/gnumail-1.3.0/Framework/GNUMail/Task.h Examining data/gnumail-1.3.0/Framework/GNUMail/PasswordPanelController.h Examining data/gnumail-1.3.0/Framework/GNUMail/GetURLScriptCommand.h Examining data/gnumail-1.3.0/Framework/GNUMail/ExtendedTextView.h Examining data/gnumail-1.3.0/Framework/GNUMail/NSFont+Extensions.h Examining data/gnumail-1.3.0/Framework/GNUMail/MessageViewWindow.h Examining data/gnumail-1.3.0/Framework/GNUMail/NSColor+Extensions.h Examining data/gnumail-1.3.0/Framework/GNUMail/FilterManager.h Examining data/gnumail-1.3.0/Framework/GNUMail/ThreadArcsCell.h Examining data/gnumail-1.3.0/Framework/GNUMail/ExtendedWindow.h Examining data/gnumail-1.3.0/Framework/GNUMail/PreferencesWindowController.h Examining data/gnumail-1.3.0/Framework/GNUMail/TaskManager.h Examining data/gnumail-1.3.0/Framework/GNUMail/ConsoleWindowController.h Examining data/gnumail-1.3.0/Framework/GNUMail/NSBundle+Extensions.h Examining data/gnumail-1.3.0/Framework/GNUMail/MessageComposition.h Examining data/gnumail-1.3.0/Framework/GNUMail/StripeTableView.h Examining data/gnumail-1.3.0/Framework/GNUMail/MessageViewWindowController.h Examining data/gnumail-1.3.0/Framework/GNUMail/ExtendedCell.h Examining data/gnumail-1.3.0/Framework/GNUMail/MailboxManagerToolbar.h Examining data/gnumail-1.3.0/Framework/GNUMail/GNUMail+Services.h Examining data/gnumail-1.3.0/Framework/GNUMail/WelcomePanel.h Examining data/gnumail-1.3.0/Framework/GNUMail/Utilities.h Examining data/gnumail-1.3.0/Framework/GNUMail/MailWindowController.h Examining data/gnumail-1.3.0/Framework/GNUMail/AddressBookPanel.h Examining data/gnumail-1.3.0/Framework/GNUMail/NSAttributedString+TextEnriched.h Examining data/gnumail-1.3.0/Framework/GNUMail/GNUMail+Extensions.h Examining data/gnumail-1.3.0/Framework/GNUMail/NewMailboxPanelController.h Examining data/gnumail-1.3.0/Framework/GNUMail/MessageViewWindowToolbar.h Examining data/gnumail-1.3.0/Framework/GNUMail/MailHeaderCell.h Examining data/gnumail-1.3.0/Framework/GNUMail/MailWindowToolbar.h Examining data/gnumail-1.3.0/Framework/GNUMail/AddressBookController.h Examining data/gnumail-1.3.0/Framework/GNUMail/MailWindow.h Examining data/gnumail-1.3.0/Framework/GNUMail/FolderNode.h Examining data/gnumail-1.3.0/Framework/GNUMail/FolderNodePopUpItem.h Examining data/gnumail-1.3.0/Framework/GNUMail/Filter.h Examining data/gnumail-1.3.0/Framework/GNUMail/GNUMailBundle.h Examining data/gnumail-1.3.0/Bundles/Advanced/AdvancedViewController.h Examining data/gnumail-1.3.0/Bundles/Advanced/AdvancedView.h Examining data/gnumail-1.3.0/Bundles/Compose/ComposeView.h Examining data/gnumail-1.3.0/Bundles/Compose/ComposeViewController.h Examining data/gnumail-1.3.0/Bundles/PGP/PGPView.h Examining data/gnumail-1.3.0/Bundles/PGP/PGPViewController.h Examining data/gnumail-1.3.0/Bundles/PGP/PGPController.h Examining data/gnumail-1.3.0/Bundles/MIME/MIMEView.h Examining data/gnumail-1.3.0/Bundles/MIME/MIMEViewController.h Examining data/gnumail-1.3.0/Bundles/MIME/MimeTypeEditorWindow.h Examining data/gnumail-1.3.0/Bundles/MIME/MimeTypeEditorWindowController.h Examining data/gnumail-1.3.0/Bundles/Sending/SendingViewController.h Examining data/gnumail-1.3.0/Bundles/Sending/SendingView.h Examining data/gnumail-1.3.0/Bundles/Viewing/HeadersWindow.h Examining data/gnumail-1.3.0/Bundles/Viewing/ViewingView.h Examining data/gnumail-1.3.0/Bundles/Viewing/HeadersWindowController.h Examining data/gnumail-1.3.0/Bundles/Viewing/ViewingViewController.h Examining data/gnumail-1.3.0/Bundles/Fonts/FontsViewController.h Examining data/gnumail-1.3.0/Bundles/Fonts/FontsView.h Examining data/gnumail-1.3.0/Bundles/Import/MailboxImportController.h Examining data/gnumail-1.3.0/Bundles/Import/Views.h Examining data/gnumail-1.3.0/Bundles/Import/MailboxImportController+Filters.h Examining data/gnumail-1.3.0/Bundles/Clock/Clock.h Examining data/gnumail-1.3.0/Bundles/Clock/ClockController.h Examining data/gnumail-1.3.0/Bundles/Receiving/ReceivingView.h Examining data/gnumail-1.3.0/Bundles/Receiving/ReceivingViewController.h Examining data/gnumail-1.3.0/Bundles/Account/AccountEditorWindow.h Examining data/gnumail-1.3.0/Bundles/Account/AccountViewController.h Examining data/gnumail-1.3.0/Bundles/Account/AccountEditorWindowController.h Examining data/gnumail-1.3.0/Bundles/Account/POP3View.h Examining data/gnumail-1.3.0/Bundles/Account/ReceiveView.h Examining data/gnumail-1.3.0/Bundles/Account/PersonalView.h Examining data/gnumail-1.3.0/Bundles/Account/UNIXView.h Examining data/gnumail-1.3.0/Bundles/Account/IMAPView.h Examining data/gnumail-1.3.0/Bundles/Account/SendView.h Examining data/gnumail-1.3.0/Bundles/Account/AccountView.h Examining data/gnumail-1.3.0/Bundles/Emoticon/EmoticonController.h Examining data/gnumail-1.3.0/Bundles/Colors/ColorsView.h Examining data/gnumail-1.3.0/Bundles/Colors/ColorsViewController.h Examining data/gnumail-1.3.0/Bundles/Filtering/FilteringView.h Examining data/gnumail-1.3.0/Bundles/Filtering/FilteringViewController.h Examining data/gnumail-1.3.0/Bundles/Filtering/FilterMessageWindow.h Examining data/gnumail-1.3.0/Bundles/Filtering/FilterEditorWindow.h Examining data/gnumail-1.3.0/Bundles/Filtering/FilterMessageWindowController.h Examining data/gnumail-1.3.0/Bundles/Filtering/FilterEditorWindowController.h Examining data/gnumail-1.3.0/Bundles/Filtering/FilterHeaderEditorWindow.h Examining data/gnumail-1.3.0/Bundles/Filtering/FilterHeaderEditorWindowController.h FINAL RESULTS: data/gnumail-1.3.0/Framework/GNUMail/AddressBookController.h:62:22: [2] (misc) open: Check when opening files - can an attacker redirect it (via symlinks), force the opening of special file type (e.g., device files), move things around to create a race condition, control its ancestors, or change its contents? (CWE-362). IBOutlet NSButton *open; data/gnumail-1.3.0/Framework/GNUMail/MailboxManagerController.h:80:14: [2] (misc) open: Check when opening files - can an attacker redirect it (via symlinks), force the opening of special file type (e.g., device files), move things around to create a race condition, control its ancestors, or change its contents? (CWE-362). - (IBAction) open: (id) sender; ANALYSIS SUMMARY: Hits = 2 Lines analyzed = 7694 in approximately 0.25 seconds (30989 lines/second) Physical Source Lines of Code (SLOC) = 3238 Hits@level = [0] 0 [1] 0 [2] 2 [3] 0 [4] 0 [5] 0 Hits@level+ = [0+] 2 [1+] 2 [2+] 2 [3+] 0 [4+] 0 [5+] 0 Hits/KSLOC@level+ = [0+] 0.617665 [1+] 0.617665 [2+] 0.617665 [3+] 0 [4+] 0 [5+] 0 Dot directories skipped = 1 (--followdotdir overrides) Minimum risk level = 1 Not every hit is necessarily a security vulnerability. There may be other security vulnerabilities; review your code! See 'Secure Programming HOWTO' (https://dwheeler.com/secure-programs) for more information.