Flawfinder version 2.0.10, (C) 2001-2019 David A. Wheeler. Number of rules (primarily dangerous function names) in C/C++ ruleset: 223 Examining data/mathic-1.0~git20200526/include/mathic/mathic.cpp Examining data/mathic-1.0~git20200526/include/mathic/mathic.h Examining data/mathic-1.0~git20200526/src/divsim/DivListModel.h Examining data/mathic-1.0~git20200526/src/divsim/KDTreeModel.h Examining data/mathic-1.0~git20200526/src/divsim/Monomial.h Examining data/mathic-1.0~git20200526/src/divsim/Simulation.cpp Examining data/mathic-1.0~git20200526/src/divsim/Simulation.h Examining data/mathic-1.0~git20200526/src/divsim/divMain.cpp Examining data/mathic-1.0~git20200526/src/divsim/divMain.h Examining data/mathic-1.0~git20200526/src/divsim/stdinc.h Examining data/mathic-1.0~git20200526/src/mathic.cpp Examining data/mathic-1.0~git20200526/src/mathic.h Examining data/mathic-1.0~git20200526/src/mathic/Action.cpp Examining data/mathic-1.0~git20200526/src/mathic/Action.h Examining data/mathic-1.0~git20200526/src/mathic/BinaryKDTree.h Examining data/mathic-1.0~git20200526/src/mathic/BitTriangle.cpp Examining data/mathic-1.0~git20200526/src/mathic/BitTriangle.h Examining data/mathic-1.0~git20200526/src/mathic/BoolParameter.cpp Examining data/mathic-1.0~git20200526/src/mathic/BoolParameter.h Examining data/mathic-1.0~git20200526/src/mathic/CliParameter.cpp Examining data/mathic-1.0~git20200526/src/mathic/CliParameter.h Examining data/mathic-1.0~git20200526/src/mathic/CliParser.cpp Examining data/mathic-1.0~git20200526/src/mathic/CliParser.h Examining data/mathic-1.0~git20200526/src/mathic/ColumnPrinter.cpp Examining data/mathic-1.0~git20200526/src/mathic/ColumnPrinter.h Examining data/mathic-1.0~git20200526/src/mathic/ComTree.h Examining data/mathic-1.0~git20200526/src/mathic/Comparer.h Examining data/mathic-1.0~git20200526/src/mathic/DivFinder.h Examining data/mathic-1.0~git20200526/src/mathic/DivList.h Examining data/mathic-1.0~git20200526/src/mathic/DivMask.cpp Examining data/mathic-1.0~git20200526/src/mathic/DivMask.h Examining data/mathic-1.0~git20200526/src/mathic/GeoFront.h Examining data/mathic-1.0~git20200526/src/mathic/Geobucket.h Examining data/mathic-1.0~git20200526/src/mathic/HashTable.h Examining data/mathic-1.0~git20200526/src/mathic/Heap.h Examining data/mathic-1.0~git20200526/src/mathic/HelpAction.cpp Examining data/mathic-1.0~git20200526/src/mathic/HelpAction.h Examining data/mathic-1.0~git20200526/src/mathic/IntegerParameter.cpp Examining data/mathic-1.0~git20200526/src/mathic/IntegerParameter.h Examining data/mathic-1.0~git20200526/src/mathic/KDEntryArray.h Examining data/mathic-1.0~git20200526/src/mathic/KDTree.h Examining data/mathic-1.0~git20200526/src/mathic/NameFactory.h Examining data/mathic-1.0~git20200526/src/mathic/PackedKDTree.h Examining data/mathic-1.0~git20200526/src/mathic/PairQueue.h Examining data/mathic-1.0~git20200526/src/mathic/StlSet.h Examining data/mathic-1.0~git20200526/src/mathic/StringParameter.cpp Examining data/mathic-1.0~git20200526/src/mathic/StringParameter.h Examining data/mathic-1.0~git20200526/src/mathic/Timer.cpp Examining data/mathic-1.0~git20200526/src/mathic/Timer.h Examining data/mathic-1.0~git20200526/src/mathic/TourTree.h Examining data/mathic-1.0~git20200526/src/mathic/display.cpp Examining data/mathic-1.0~git20200526/src/mathic/display.h Examining data/mathic-1.0~git20200526/src/mathic/error.cpp Examining data/mathic-1.0~git20200526/src/mathic/error.h Examining data/mathic-1.0~git20200526/src/mathic/main.cpp Examining data/mathic-1.0~git20200526/src/mathic/stdinc.h Examining data/mathic-1.0~git20200526/src/pqsim/GeobucketModel.h Examining data/mathic-1.0~git20200526/src/pqsim/HeapModel.h Examining data/mathic-1.0~git20200526/src/pqsim/Item.cpp Examining data/mathic-1.0~git20200526/src/pqsim/Item.h Examining data/mathic-1.0~git20200526/src/pqsim/Model.cpp Examining data/mathic-1.0~git20200526/src/pqsim/Model.h Examining data/mathic-1.0~git20200526/src/pqsim/Simulator.cpp Examining data/mathic-1.0~git20200526/src/pqsim/Simulator.h Examining data/mathic-1.0~git20200526/src/pqsim/StlSetModel.h Examining data/mathic-1.0~git20200526/src/pqsim/TourTreeModel.h Examining data/mathic-1.0~git20200526/src/pqsim/pqMain.cpp Examining data/mathic-1.0~git20200526/src/pqsim/pqMain.h Examining data/mathic-1.0~git20200526/src/pqsim/stdinc.h Examining data/mathic-1.0~git20200526/src/test/BitTriangle.cpp Examining data/mathic-1.0~git20200526/src/test/DivFinder.cpp Examining data/mathic-1.0~git20200526/src/test/HashTable.cpp Examining data/mathic-1.0~git20200526/src/test/PairQueue.cpp Examining data/mathic-1.0~git20200526/src/test/gtestInclude.cpp Examining data/mathic-1.0~git20200526/src/test/testMain.cpp FINAL RESULTS: data/mathic-1.0~git20200526/src/divsim/Simulation.cpp:17:3: [3] (random) srand: This function is not sufficiently random for security-related functions such as key and nonce creation (CWE-327). Use a more secure technique for acquiring random values. srand(0); data/mathic-1.0~git20200526/src/pqsim/pqMain.cpp:21:3: [3] (random) srand: This function is not sufficiently random for security-related functions such as key and nonce creation (CWE-327). Use a more secure technique for acquiring random values. srand(static_cast<unsigned int>(time(0))); data/mathic-1.0~git20200526/src/pqsim/pqMain.cpp:22:3: [3] (random) srand: This function is not sufficiently random for security-related functions such as key and nonce creation (CWE-327). Use a more secure technique for acquiring random values. srand(0); data/mathic-1.0~git20200526/src/mathic/KDEntryArray.h:120:5: [2] (buffer) char: Statically-sized arrays can be improperly restricted, leading to potential overflows or other issues (CWE-119!/CWE-120). Perform bounds checking, use functions that limit length, or ensure that the size is larger than the maximum possible length. char _beginMemory[C::LeafSize * sizeof(ExtEntry)]; data/mathic-1.0~git20200526/src/mathic/GeoFront.h:365:21: [1] (buffer) equal: Function does not check the second iterator for over-read conditions (CWE-126). This function is often discouraged by most C++ coding standards in favor of its safer alternatives provided since C++14. Consider using a form of this function that checks the second iterator before potentially overflowing it. MATHIC_ASSERT(std::equal(frontCopy.begin(), frontCopy.end(), nonEmpty.begin())); ANALYSIS SUMMARY: Hits = 5 Lines analyzed = 11145 in approximately 0.29 seconds (37990 lines/second) Physical Source Lines of Code (SLOC) = 8680 Hits@level = [0] 5 [1] 1 [2] 1 [3] 3 [4] 0 [5] 0 Hits@level+ = [0+] 10 [1+] 5 [2+] 4 [3+] 3 [4+] 0 [5+] 0 Hits/KSLOC@level+ = [0+] 1.15207 [1+] 0.576037 [2+] 0.460829 [3+] 0.345622 [4+] 0 [5+] 0 Dot directories skipped = 1 (--followdotdir overrides) Minimum risk level = 1 Not every hit is necessarily a security vulnerability. There may be other security vulnerabilities; review your code! See 'Secure Programming HOWTO' (https://dwheeler.com/secure-programs) for more information.