vulnerability
security weakness which allows an attacker to reduce a system's information assurance
format string attack
type of software vulnerability
cross-site tracing
network security vulnerability exploiting the HTTP TRACE method
physical access
ability of people to physically gain access to a computer system
Shellshock
security bug in the Unix Bash shell
GHOST
vulnerability in glibc
backdoor
backdoor is a hidden way to bypass security and gain unauthorized access to a system
cross-site cooking
browser exploit which allows a site attacker to set a cookie for a browser into the cookie domain of another site server
Lucky Thirteen attack
cryptographic timing attack against implementations of TLS that use the CBC mode, reported in February 2013 by N. J. AlFardan and K. Paterson
POODLE
man-in-the-middle exploit taking advantage of fallback to SSL 3.0, disclosed on October 2014
Stagefright
software bug in Android
Meltdown
vulnerability in modern microprocessors which permits unauthorized memory reads
VENOM
computer security flaw
Pacman
processor security vulnerability
random number generator attack
class of attack on cryptographic systems
cache poisoning
attack in which invalid entiries are placed into a cache
Prototype pollution
class of web security vulnerabilities
Virtual machine escape
computer vulnerability related to virtialuzation
Spectre
security vulnerability in microprocessors performing branch prediction
Terrapin attack
computer security vulnerability
rogue access point
unauthorized wireless access point attached to a computer network
cross-zone scripting
browser exploit taking advantage of a vulnerability within a zone-based security solution; allows content in unprivileged zones to be executed with the permissions of a privileged zone
malware vector
method which malicious code utilizes to infect a computer or propagates itself
Load Value Injection
computer security vulnerability
cross-site leaks
class of web security attacks
covert channel
type of computer security attack that creates a capability to transfer information objects between processes that are not supposed to be allowed to communicate
remote file inclusion
Type of web vulnerability
remote file inclusion
Type of web vulnerability
CRIME
security exploit against secret web cookies
FREAK
security exploit
Unauthorized Cross-App Resource Access
category of zero-day vulnerabilities in computer software systems
Dirty COW
computer security vulnerability
ROCA vulnerability
cryptographic weakness
Trojan Source
software vulnerability in source code
DOM Clobbering
Class of web security vulnerabilities
cross-site scripting
type of computer security vulnerability typically found in web applications
social engineering
information security concept: psychological manipulation of people into performing actions or divulging confidential information
race condition
situation in computer system that occurs when multiple processes try to access a common resource
zero-day
cyberattack that utilizes a recently-publicized computer software vulnerability on systems which are yet to be mitigated
arbitrary code execution
an attacker's ability to run any commands or code of the attacker's choice on a target machine or in a target process
DROWN attack
cross-protocol attack against TLS using the SSLv2 protocol
Default Credential vulnerability
type of vulnerability that is most commonly found in devices having some pre-set (default) administrative credentials
insecure direct object reference
type of access control vulnerability in digital security
Downfall
security vulnerability
mass assignment vulnerability
inability of software to discern authorized from unauthorized data modification requests
Logjam
security vulnerability against a Diffie–Hellman key exchange ranging from 512-bit to 1024-bit keys, publicly reported on 20 May 2015