Vulnerabilities
Named vulnerabilities, weakness classes, and exploit categories
- Arbitrary code execution664 words
**Arbitrary code execution** is a term used in cybersecurity to describe a situation where an attacker can execute any command or code of their choice
- Windows Metafile vulnerability534 words
**Windows Metafile Vulnerability** The **Windows Metafile vulnerability** refers to a security flaw in the handling of Windows Metafile (WMF) images,
- ReDoS719 words
**ReDoS (Regular Expression Denial of Service)** is a type of denial-of-service (DoS) attack that exploits the inefficiencies in the processing of reg
- Transient execution CPU vulnerability752 words
**Transient execution CPU vulnerability** refers to a class of security weaknesses in modern processors that arise during speculative execution. Specu
- IDN homograph attack595 words
**IDN Homograph Attack** An Internationalized Domain Name (IDN) homograph attack is a type of phishing attack that exploits the visual similarity of
- 2021 FBI email hack593 words
The 2021 FBI email hack was a significant cybersecurity incident where unauthorized emails were sent from a legitimate Federal Bureau of Investigation
- 2012 Yahoo! Voices hack632 words
The **2012 Yahoo! Voices hack** was a significant cybersecurity incident where attackers compromised Yahoo's Voices service, resulting in the exposure
- DOM clobbering650 words
**DOM Clobbering** **Overview**
- Foreshadow (security vulnerability)594 words
**Foreshadow (security vulnerability)** is a hardware-based security vulnerability that affects Intel processors. It was publicly disclosed in August
- ANT catalog472 words
The ANT catalog is a collection of surveillance and cyber-espionage tools reportedly used by the United States National Security Agency (NSA). The cat
- Meltdown (security vulnerability)653 words
**Meltdown** is a security vulnerability that affects modern microprocessors, allowing unauthorized access to sensitive data. Discovered in 2018, Melt
- Billion laughs446 words
**Billion Laughs** The "Billion Laughs" attack, also known as an XML bomb, is a type of denial-of-service (DoS) attack that exploits the extensible m
- Buffer overflow600 words
**Buffer Overflow in Cybersecurity** A **buffer overflow** is a common vulnerability in computer security that occurs when a program writes more data
- Vulnerability Management Lifecycle630 words
The **Vulnerability Management Lifecycle** is a critical process in cybersecurity that involves identifying, evaluating, treating, and reporting on se
- Domain Name System Security Extensions680 words
**Domain Name System Security Extensions (DNSSEC)** is a suite of specifications designed to protect the Domain Name System (DNS) from certain types o
- DOM-Based XSS780 words
**DOM-Based XSS** **Overview**
- Downfall (security vulnerability)459 words
**Downfall (security vulnerability)** Downfall is a security vulnerability that affects certain computer systems, potentially allowing unauthorized a
- 2023 MOVEit data breach796 words
The 2023 MOVEit data breach was a significant cybersecurity incident involving the unauthorized access and exfiltration of sensitive data from organiz
- 2021 Microsoft Exchange Server data breach567 words
The 2021 Microsoft Exchange Server data breach was a significant cybersecurity incident involving the exploitation of vulnerabilities in Microsoft Exc
- Cross-Site Scripting (XSS)657 words
**Cross-Site Scripting (XSS)** is a type of security vulnerability typically found in web applications. It allows attackers to inject malicious script