Flawfinder version 2.0.10, (C) 2001-2019 David A. Wheeler. Number of rules (primarily dangerous function names) in C/C++ ruleset: 223 Examining data/kbookmarks-5.74.0/autotests/kbookmarkmenutest.cpp Examining data/kbookmarks-5.74.0/autotests/kbookmarktest.cpp Examining data/kbookmarks-5.74.0/tests/kbookmarkdialogtest.cpp Examining data/kbookmarks-5.74.0/src/kbookmarkdialog_p.h Examining data/kbookmarks-5.74.0/src/kbookmarkimporter.h Examining data/kbookmarks-5.74.0/src/kbookmarkdombuilder.h Examining data/kbookmarks-5.74.0/src/kbookmark.cpp Examining data/kbookmarks-5.74.0/src/kbookmarkowner.h Examining data/kbookmarks-5.74.0/src/kbookmarkmanageradaptor_p.h Examining data/kbookmarks-5.74.0/src/kbookmarkaction.h Examining data/kbookmarks-5.74.0/src/kbookmarkmenu_p.h Examining data/kbookmarks-5.74.0/src/kbookmarkactioninterface.cpp Examining data/kbookmarks-5.74.0/src/konqbookmarkmenu.h Examining data/kbookmarks-5.74.0/src/konqbookmarkmenu_p.h Examining data/kbookmarks-5.74.0/src/kbookmarkaction.cpp Examining data/kbookmarks-5.74.0/src/kbookmarkimporter_ie.cpp Examining data/kbookmarks-5.74.0/src/kbookmarkdombuilder.cpp Examining data/kbookmarks-5.74.0/src/kbookmarkactionmenu.h Examining data/kbookmarks-5.74.0/src/kbookmarkcontextmenu.h Examining data/kbookmarks-5.74.0/src/kbookmarkmenu.cpp Examining data/kbookmarks-5.74.0/src/kbookmarkowner.cpp Examining data/kbookmarks-5.74.0/src/kbookmarkdialog.h Examining data/kbookmarks-5.74.0/src/kbookmarkcontextmenu.cpp Examining data/kbookmarks-5.74.0/src/kbookmarkimporter_opera_p.h Examining data/kbookmarks-5.74.0/src/kbookmarkmanageradaptor.cpp Examining data/kbookmarks-5.74.0/src/kbookmarkimporter_ie.h Examining data/kbookmarks-5.74.0/src/kbookmarkimporter_opera.h Examining data/kbookmarks-5.74.0/src/kbookmarkdialog.cpp Examining data/kbookmarks-5.74.0/src/kbookmarkactioninterface.h Examining data/kbookmarks-5.74.0/src/kbookmarkactionmenu.cpp Examining data/kbookmarks-5.74.0/src/kbookmarkimporter_ns.cpp Examining data/kbookmarks-5.74.0/src/kbookmarkexporter.h Examining data/kbookmarks-5.74.0/src/kbookmarkmanager.h Examining data/kbookmarks-5.74.0/src/kbookmarkmanager.cpp Examining data/kbookmarks-5.74.0/src/kbookmarkimporter_ns.h Examining data/kbookmarks-5.74.0/src/kbookmark.h Examining data/kbookmarks-5.74.0/src/konqbookmarkmenu.cpp Examining data/kbookmarks-5.74.0/src/kbookmarkimporter_opera.cpp Examining data/kbookmarks-5.74.0/src/kbookmarkmenu.h Examining data/kbookmarks-5.74.0/src/kbookmarkimporter.cpp FINAL RESULTS: data/kbookmarks-5.74.0/autotests/kbookmarktest.cpp:125:18: [2] (misc) open: Check when opening files - can an attacker redirect it (via symlinks), force the opening of special file type (e.g., device files), move things around to create a race condition, control its ancestors, or change its contents? (CWE-362). QVERIFY(file.open(QIODevice::WriteOnly)); data/kbookmarks-5.74.0/src/kbookmarkdombuilder.cpp:56:31: [2] (misc) open: Check when opening files - can an attacker redirect it (via symlinks), force the opening of special file type (e.g., device files), move things around to create a race condition, control its ancestors, or change its contents? (CWE-362). const QString &text, bool open, const QString &additionalInfo data/kbookmarks-5.74.0/src/kbookmarkdombuilder.cpp:67:56: [2] (misc) open: Check when opening files - can an attacker redirect it (via symlinks), force the opening of special file type (e.g., device files), move things around to create a race condition, control its ancestors, or change its contents? (CWE-362). element.setAttribute(QStringLiteral("folded"), open ? QStringLiteral("no") : QStringLiteral("yes")); data/kbookmarks-5.74.0/src/kbookmarkdombuilder.h:29:46: [2] (misc) open: Check when opening files - can an attacker redirect it (via symlinks), force the opening of special file type (e.g., device files), move things around to create a race condition, control its ancestors, or change its contents? (CWE-362). void newFolder(const QString &text, bool open, const QString &additionalInfo); data/kbookmarks-5.74.0/src/kbookmarkimporter.h:51:46: [2] (misc) open: Check when opening files - can an attacker redirect it (via symlinks), force the opening of special file type (e.g., device files), move things around to create a race condition, control its ancestors, or change its contents? (CWE-362). void newFolder(const QString &text, bool open, const QString &additionalInfo); data/kbookmarks-5.74.0/src/kbookmarkimporter_ie.cpp:39:46: [2] (misc) open: Check when opening files - can an attacker redirect it (via symlinks), force the opening of special file type (e.g., device files), move things around to create a race condition, control its ancestors, or change its contents? (CWE-362). void newFolder(const QString &text, bool open, const QString &additionalInfo); data/kbookmarks-5.74.0/src/kbookmarkimporter_ie.cpp:56:11: [2] (misc) open: Check when opening files - can an attacker redirect it (via symlinks), force the opening of special file type (e.g., device files), move things around to create a race condition, control its ancestors, or change its contents? (CWE-362). if (f.open(QIODevice::ReadOnly)) { data/kbookmarks-5.74.0/src/kbookmarkimporter_ie.cpp:184:14: [2] (misc) open: Check when opening files - can an attacker redirect it (via symlinks), force the opening of special file type (e.g., device files), move things around to create a race condition, control its ancestors, or change its contents? (CWE-362). if (file.open(QIODevice::WriteOnly)) { data/kbookmarks-5.74.0/src/kbookmarkimporter_ns.cpp:32:11: [2] (misc) open: Check when opening files - can an attacker redirect it (via symlinks), force the opening of special file type (e.g., device files), move things around to create a race condition, control its ancestors, or change its contents? (CWE-362). if (f.open(QIODevice::ReadOnly)) { data/kbookmarks-5.74.0/src/kbookmarkimporter_ns.cpp:135:15: [2] (misc) open: Check when opening files - can an attacker redirect it (via symlinks), force the opening of special file type (e.g., device files), move things around to create a race condition, control its ancestors, or change its contents? (CWE-362). if (!file.open(QIODevice::WriteOnly)) { data/kbookmarks-5.74.0/src/kbookmarkimporter_opera.cpp:24:15: [2] (misc) open: Check when opening files - can an attacker redirect it (via symlinks), force the opening of special file type (e.g., device files), move things around to create a race condition, control its ancestors, or change its contents? (CWE-362). if (!file.open(QIODevice::ReadOnly)) { data/kbookmarks-5.74.0/src/kbookmarkimporter_opera.cpp:175:15: [2] (misc) open: Check when opening files - can an attacker redirect it (via symlinks), force the opening of special file type (e.g., device files), move things around to create a race condition, control its ancestors, or change its contents? (CWE-362). if (!file.open(QIODevice::WriteOnly)) { data/kbookmarks-5.74.0/src/kbookmarkimporter_opera_p.h:29:46: [2] (misc) open: Check when opening files - can an attacker redirect it (via symlinks), force the opening of special file type (e.g., device files), move things around to create a race condition, control its ancestors, or change its contents? (CWE-362). void newFolder(const QString &text, bool open, const QString &additionalInfo); data/kbookmarks-5.74.0/src/kbookmarkmanager.cpp:394:15: [2] (misc) open: Check when opening files - can an attacker redirect it (via symlinks), force the opening of special file type (e.g., device files), move things around to create a race condition, control its ancestors, or change its contents? (CWE-362). if (!file.open(QIODevice::ReadOnly)) { data/kbookmarks-5.74.0/src/kbookmarkmanager.cpp:452:23: [2] (misc) open: Check when opening files - can an attacker redirect it (via symlinks), force the opening of special file type (e.g., device files), move things around to create a race condition, control its ancestors, or change its contents? (CWE-362). if (cacheFile.open(QIODevice::WriteOnly)) { data/kbookmarks-5.74.0/src/kbookmarkmanager.cpp:469:14: [2] (misc) open: Check when opening files - can an attacker redirect it (via symlinks), force the opening of special file type (e.g., device files), move things around to create a race condition, control its ancestors, or change its contents? (CWE-362). if (file.open(QIODevice::WriteOnly)) { data/kbookmarks-5.74.0/src/kbookmarkmanager.cpp:523:22: [2] (misc) open: Check when opening files - can an attacker redirect it (via symlinks), force the opening of special file type (e.g., device files), move things around to create a race condition, control its ancestors, or change its contents? (CWE-362). if (file.open(QIODevice::ReadOnly)) { ANALYSIS SUMMARY: Hits = 17 Lines analyzed = 6409 in approximately 0.21 seconds (30221 lines/second) Physical Source Lines of Code (SLOC) = 4137 Hits@level = [0] 0 [1] 0 [2] 17 [3] 0 [4] 0 [5] 0 Hits@level+ = [0+] 17 [1+] 17 [2+] 17 [3+] 0 [4+] 0 [5+] 0 Hits/KSLOC@level+ = [0+] 4.10926 [1+] 4.10926 [2+] 4.10926 [3+] 0 [4+] 0 [5+] 0 Dot directories skipped = 1 (--followdotdir overrides) Minimum risk level = 1 Not every hit is necessarily a security vulnerability. There may be other security vulnerabilities; review your code! See 'Secure Programming HOWTO' (https://dwheeler.com/secure-programs) for more information.