Flawfinder version 2.0.10, (C) 2001-2019 David A. Wheeler. Number of rules (primarily dangerous function names) in C/C++ ruleset: 223 Examining data/grantlee-editor-20.08.2/headerthemeeditor/previewwidget.cpp Examining data/grantlee-editor-20.08.2/headerthemeeditor/themetemplatewidget.cpp Examining data/grantlee-editor-20.08.2/headerthemeeditor/themeeditorutil.h Examining data/grantlee-editor-20.08.2/headerthemeeditor/themeeditormainwindow.h Examining data/grantlee-editor-20.08.2/headerthemeeditor/themeconfiguredialog.h Examining data/grantlee-editor-20.08.2/headerthemeeditor/editorpage.cpp Examining data/grantlee-editor-20.08.2/headerthemeeditor/themeeditorwidget.h Examining data/grantlee-editor-20.08.2/headerthemeeditor/themeeditormainwindow.cpp Examining data/grantlee-editor-20.08.2/headerthemeeditor/themeeditorpage.cpp Examining data/grantlee-editor-20.08.2/headerthemeeditor/defaultcompletion.h Examining data/grantlee-editor-20.08.2/headerthemeeditor/themedefaulttemplate.h Examining data/grantlee-editor-20.08.2/headerthemeeditor/main.cpp Examining data/grantlee-editor-20.08.2/headerthemeeditor/themeeditorpage.h Examining data/grantlee-editor-20.08.2/headerthemeeditor/editorpage.h Examining data/grantlee-editor-20.08.2/headerthemeeditor/themeconfiguredialog.cpp Examining data/grantlee-editor-20.08.2/headerthemeeditor/themedefaulttemplate.cpp Examining data/grantlee-editor-20.08.2/headerthemeeditor/defaultcompletion.cpp Examining data/grantlee-editor-20.08.2/headerthemeeditor/themetemplatewidget.h Examining data/grantlee-editor-20.08.2/headerthemeeditor/themeeditorwidget.cpp Examining data/grantlee-editor-20.08.2/headerthemeeditor/previewwidget.h Examining data/grantlee-editor-20.08.2/headerthemeeditor/themeeditorutil.cpp Examining data/grantlee-editor-20.08.2/grantleethemeeditor/previewwidget.cpp Examining data/grantlee-editor-20.08.2/grantleethemeeditor/newthemedialog.h Examining data/grantlee-editor-20.08.2/grantleethemeeditor/editorwidget.h Examining data/grantlee-editor-20.08.2/grantleethemeeditor/desktopfilepage.cpp Examining data/grantlee-editor-20.08.2/grantleethemeeditor/configurewidget.h Examining data/grantlee-editor-20.08.2/grantleethemeeditor/grantleeplaintexteditor.cpp Examining data/grantlee-editor-20.08.2/grantleethemeeditor/editorwidget.cpp Examining data/grantlee-editor-20.08.2/grantleethemeeditor/themeeditortabwidget.cpp Examining data/grantlee-editor-20.08.2/grantleethemeeditor/editorpage.cpp Examining data/grantlee-editor-20.08.2/grantleethemeeditor/configurewidget.cpp Examining data/grantlee-editor-20.08.2/grantleethemeeditor/desktopfilepage.h Examining data/grantlee-editor-20.08.2/grantleethemeeditor/editorpage.h Examining data/grantlee-editor-20.08.2/grantleethemeeditor/managethemes.cpp Examining data/grantlee-editor-20.08.2/grantleethemeeditor/themeeditortabwidget.h Examining data/grantlee-editor-20.08.2/grantleethemeeditor/grantleeplaintexteditor.h Examining data/grantlee-editor-20.08.2/grantleethemeeditor/managethemes.h Examining data/grantlee-editor-20.08.2/grantleethemeeditor/newthemedialog.cpp Examining data/grantlee-editor-20.08.2/grantleethemeeditor/themesession.cpp Examining data/grantlee-editor-20.08.2/grantleethemeeditor/previewwidget.h Examining data/grantlee-editor-20.08.2/grantleethemeeditor/themesession.h Examining data/grantlee-editor-20.08.2/contactthemeeditor/previewwidget.cpp Examining data/grantlee-editor-20.08.2/contactthemeeditor/contacteditormainwindow.cpp Examining data/grantlee-editor-20.08.2/contactthemeeditor/contacteditorwidget.cpp Examining data/grantlee-editor-20.08.2/contactthemeeditor/contacteditorpage.h Examining data/grantlee-editor-20.08.2/contactthemeeditor/contacteditorpage.cpp Examining data/grantlee-editor-20.08.2/contactthemeeditor/contactconfigurationdialog.h Examining data/grantlee-editor-20.08.2/contactthemeeditor/contacteditorutil.h Examining data/grantlee-editor-20.08.2/contactthemeeditor/contactdefaulttemplate.h Examining data/grantlee-editor-20.08.2/contactthemeeditor/editorpage.cpp Examining data/grantlee-editor-20.08.2/contactthemeeditor/contactpreviewwidget.h Examining data/grantlee-editor-20.08.2/contactthemeeditor/contacttemplatewidget.cpp Examining data/grantlee-editor-20.08.2/contactthemeeditor/contacttemplatewidget.h Examining data/grantlee-editor-20.08.2/contactthemeeditor/contacteditormainwindow.h Examining data/grantlee-editor-20.08.2/contactthemeeditor/defaultcompletion.h Examining data/grantlee-editor-20.08.2/contactthemeeditor/contactpreviewwidget.cpp Examining data/grantlee-editor-20.08.2/contactthemeeditor/main.cpp Examining data/grantlee-editor-20.08.2/contactthemeeditor/contacteditorutil.cpp Examining data/grantlee-editor-20.08.2/contactthemeeditor/editorpage.h Examining data/grantlee-editor-20.08.2/contactthemeeditor/contactconfigurationdialog.cpp Examining data/grantlee-editor-20.08.2/contactthemeeditor/contacteditorwidget.h Examining data/grantlee-editor-20.08.2/contactthemeeditor/defaultcompletion.cpp Examining data/grantlee-editor-20.08.2/contactthemeeditor/contactdefaulttemplate.cpp Examining data/grantlee-editor-20.08.2/contactthemeeditor/previewwidget.h Examining data/grantlee-editor-20.08.2/contactprintthemeeditor/themetemplatewidget.cpp Examining data/grantlee-editor-20.08.2/contactprintthemeeditor/contactprintthemepreview.h Examining data/grantlee-editor-20.08.2/contactprintthemeeditor/contactprintthemeeditorutil.cpp Examining data/grantlee-editor-20.08.2/contactprintthemeeditor/themeeditormainwindow.h Examining data/grantlee-editor-20.08.2/contactprintthemeeditor/contactprintthemeconfiguredialog.h Examining data/grantlee-editor-20.08.2/contactprintthemeeditor/editorpage.cpp Examining data/grantlee-editor-20.08.2/contactprintthemeeditor/themeeditorwidget.h Examining data/grantlee-editor-20.08.2/contactprintthemeeditor/themeeditormainwindow.cpp Examining data/grantlee-editor-20.08.2/contactprintthemeeditor/themeeditorpage.cpp Examining data/grantlee-editor-20.08.2/contactprintthemeeditor/defaultcompletion.h Examining data/grantlee-editor-20.08.2/contactprintthemeeditor/themedefaulttemplate.h Examining data/grantlee-editor-20.08.2/contactprintthemeeditor/contactprintthemeeditorutil.h Examining data/grantlee-editor-20.08.2/contactprintthemeeditor/contactprintthemeconfiguredialog.cpp Examining data/grantlee-editor-20.08.2/contactprintthemeeditor/main.cpp Examining data/grantlee-editor-20.08.2/contactprintthemeeditor/themeeditorpage.h Examining data/grantlee-editor-20.08.2/contactprintthemeeditor/editorpage.h Examining data/grantlee-editor-20.08.2/contactprintthemeeditor/contactprintthemepreview.cpp Examining data/grantlee-editor-20.08.2/contactprintthemeeditor/themedefaulttemplate.cpp Examining data/grantlee-editor-20.08.2/contactprintthemeeditor/defaultcompletion.cpp Examining data/grantlee-editor-20.08.2/contactprintthemeeditor/themetemplatewidget.h Examining data/grantlee-editor-20.08.2/contactprintthemeeditor/themeeditorwidget.cpp FINAL RESULTS: data/grantlee-editor-20.08.2/contactprintthemeeditor/themeeditormainwindow.cpp:111:36: [2] (misc) open: Check when opening files - can an attacker redirect it (via symlinks), force the opening of special file type (e.g., device files), move things around to create a race condition, control its ancestors, or change its contents? (CWE-362). mOpenAction = KStandardAction::open(this, &ThemeEditorMainWindow::slotOpenTheme, actionCollection()); data/grantlee-editor-20.08.2/contactprintthemeeditor/themeeditorpage.cpp:169:14: [2] (misc) open: Check when opening files - can an attacker redirect it (via symlinks), force the opening of special file type (e.g., device files), move things around to create a race condition, control its ancestors, or change its contents? (CWE-362). if (zip->open(QIODevice::WriteOnly)) { data/grantlee-editor-20.08.2/contactthemeeditor/contacteditormainwindow.cpp:110:36: [2] (misc) open: Check when opening files - can an attacker redirect it (via symlinks), force the opening of special file type (e.g., device files), move things around to create a race condition, control its ancestors, or change its contents? (CWE-362). mOpenAction = KStandardAction::open(this, &ContactEditorMainWindow::slotOpenTheme, actionCollection()); data/grantlee-editor-20.08.2/contactthemeeditor/contacteditorpage.cpp:168:14: [2] (misc) open: Check when opening files - can an attacker redirect it (via symlinks), force the opening of special file type (e.g., device files), move things around to create a race condition, control its ancestors, or change its contents? (CWE-362). if (zip->open(QIODevice::WriteOnly)) { data/grantlee-editor-20.08.2/grantleethemeeditor/desktopfilepage.cpp:140:9: [2] (misc) open: Check when opening files - can an attacker redirect it (via symlinks), force the opening of special file type (e.g., device files), move things around to create a race condition, control its ancestors, or change its contents? (CWE-362). tmp.open(); data/grantlee-editor-20.08.2/grantleethemeeditor/editorpage.cpp:80:14: [2] (misc) open: Check when opening files - can an attacker redirect it (via symlinks), force the opening of special file type (e.g., device files), move things around to create a race condition, control its ancestors, or change its contents? (CWE-362). if (file.open(QIODevice::Text | QIODevice::ReadOnly)) { data/grantlee-editor-20.08.2/grantleethemeeditor/editorpage.cpp:101:14: [2] (misc) open: Check when opening files - can an attacker redirect it (via symlinks), force the opening of special file type (e.g., device files), move things around to create a race condition, control its ancestors, or change its contents? (CWE-362). if (file.open(QIODevice::WriteOnly | QIODevice::Text)) { data/grantlee-editor-20.08.2/grantleethemeeditor/editorpage.cpp:114:9: [2] (misc) open: Check when opening files - can an attacker redirect it (via symlinks), force the opening of special file type (e.g., device files), move things around to create a race condition, control its ancestors, or change its contents? (CWE-362). tmp.open(); data/grantlee-editor-20.08.2/grantleethemeeditor/editorwidget.cpp:38:18: [2] (misc) open: Check when opening files - can an attacker redirect it (via symlinks), force the opening of special file type (e.g., device files), move things around to create a race condition, control its ancestors, or change its contents? (CWE-362). if (file.open(QIODevice::ReadOnly)) { data/grantlee-editor-20.08.2/headerthemeeditor/themeeditormainwindow.cpp:115:36: [2] (misc) open: Check when opening files - can an attacker redirect it (via symlinks), force the opening of special file type (e.g., device files), move things around to create a race condition, control its ancestors, or change its contents? (CWE-362). mOpenAction = KStandardAction::open(this, &ThemeEditorMainWindow::slotOpenTheme, actionCollection()); data/grantlee-editor-20.08.2/headerthemeeditor/themeeditorpage.cpp:193:14: [2] (misc) open: Check when opening files - can an attacker redirect it (via symlinks), force the opening of special file type (e.g., device files), move things around to create a race condition, control its ancestors, or change its contents? (CWE-362). if (zip->open(QIODevice::WriteOnly)) { ANALYSIS SUMMARY: Hits = 11 Lines analyzed = 7263 in approximately 0.27 seconds (26767 lines/second) Physical Source Lines of Code (SLOC) = 4807 Hits@level = [0] 0 [1] 0 [2] 11 [3] 0 [4] 0 [5] 0 Hits@level+ = [0+] 11 [1+] 11 [2+] 11 [3+] 0 [4+] 0 [5+] 0 Hits/KSLOC@level+ = [0+] 2.28833 [1+] 2.28833 [2+] 2.28833 [3+] 0 [4+] 0 [5+] 0 Dot directories skipped = 1 (--followdotdir overrides) Minimum risk level = 1 Not every hit is necessarily a security vulnerability. There may be other security vulnerabilities; review your code! See 'Secure Programming HOWTO' (https://dwheeler.com/secure-programs) for more information.