18 lines
1.5 KiB
Text
18 lines
1.5 KiB
Text
Buffer overflow occurs when a program writes more data to a buffer than it can hold.
|
|
Format string vulnerabilities allow reading and writing arbitrary memory locations.
|
|
SQL injection happens when untrusted input is concatenated into SQL queries.
|
|
Cross-site scripting (XSS) injects malicious scripts into web pages viewed by others.
|
|
Privilege escalation exploits bugs to gain higher level access than authorized.
|
|
Race conditions occur when the timing of events affects program behavior in unintended ways.
|
|
Integer overflow wraps around to negative or small values causing logic errors.
|
|
Use-after-free vulnerabilities access memory after it has been freed causing corruption.
|
|
ASLR randomizes memory addresses to make exploitation more difficult.
|
|
Stack canaries protect against stack buffer overflows by detecting corruption before return.
|
|
NX bit marks memory pages as non-executable preventing code execution in data regions.
|
|
Kernel exploits target vulnerabilities in the operating system kernel for full system compromise.
|
|
The heartbleed bug in OpenSSL allowed reading memory from servers without authentication.
|
|
Spectre and Meltdown are CPU vulnerabilities that leak information through side channels.
|
|
The principle of least privilege says code should run with only the permissions it needs.
|
|
Defense in depth uses multiple layers of security controls so no single failure is catastrophic.
|
|
Zero day vulnerabilities are unknown to the vendor and have no available patch.
|
|
A threat model identifies potential attackers their capabilities and the assets they target.
|