Buffer overflow occurs when a program writes more data to a buffer than it can hold.
Format string vulnerabilities allow reading and writing arbitrary memory locations.
SQL injection happens when untrusted input is concatenated into SQL queries.
Cross-site scripting (XSS) injects malicious scripts into web pages viewed by others.
Privilege escalation exploits bugs to gain higher level access than authorized.
Race conditions occur when the timing of events affects program behavior in unintended ways.
Integer overflow wraps around to negative or small values causing logic errors.
Use-after-free vulnerabilities access memory after it has been freed causing corruption.
ASLR randomizes memory addresses to make exploitation more difficult.
Stack canaries protect against stack buffer overflows by detecting corruption before return.
NX bit marks memory pages as non-executable preventing code execution in data regions.
Kernel exploits target vulnerabilities in the operating system kernel for full system compromise.
The heartbleed bug in OpenSSL allowed reading memory from servers without authentication.
Spectre and Meltdown are CPU vulnerabilities that leak information through side channels.
The principle of least privilege says code should run with only the permissions it needs.
Defense in depth uses multiple layers of security controls so no single failure is catastrophic.
Zero day vulnerabilities are unknown to the vendor and have no available patch.
A threat model identifies potential attackers their capabilities and the assets they target.
