Micron Document
<!DOCTYPE html>
<html class="client-nojs vector-feature-night-mode-disabled vector-feature-language-in-header-enabled vector-feature-language-in-main-page-header-disabled vector-feature-page-tools-pinned-disabled vector-feature-toc-pinned-clientpref-1 vector-feature-main-menu-pinned-disabled vector-feature-limited-width-clientpref-1 vector-feature-limited-width-content-enabled vector-feature-custom-font-size-clientpref-1 vector-feature-appearance-pinned-clientpref-1 vector-sticky-header-enabled" lang="en" dir="ltr"><head>
<meta charset="UTF-8">
<title>Vulnerability (computer security)</title>
<meta name="viewport" content="width=device-width, initial-scale=1.0">
<link rel="canonical" href="https://en.wikipedia.org/wiki/Vulnerability_(computer_security)"> <link href="./mw/ext.cite.styles.css" rel="stylesheet" type="text/css">
<link href="./mw/skins.vector.icons.css" rel="stylesheet" type="text/css">
<link href="./mw/skins.vector.search.codex.styles.css" rel="stylesheet" type="text/css">
<link href="./mw/skins.vector.styles.css" rel="stylesheet" type="text/css">
<link href="./mw/user.styles.css" rel="stylesheet" type="text/css">
<meta name="ResourceLoaderDynamicStyles" content="">
<link rel="stylesheet" type="text/css" href="./mw/site.styles.css">
<link rel="stylesheet" type="text/css" href="./mw/noscript.css">
<link rel="stylesheet" type="text/css" href="./footer.css">
<link rel="stylesheet" type="text/css" href="./vector-2022.css">
</head>
<body class="skin--responsive skin-vector skin-vector-search-vue mediawiki ltr sitedir-ltr mw-hide-empty-elt ns-0 ns-subject page-Vulnerability_computer_security rootpage-Vulnerability_computer_security skin-vector-2022 action-view">
<div class="mw-page-container">
<div class="mw-page-container-inner">
<div class="mw-content-container">
<main id="content" class="mw-body">
<header class="mw-body-header vector-page-titlebar">
<h1 id="firstHeading" class="firstHeading mw-first-heading">
<span id="openzim-page-title" class="mw-page-title-main"><span class="mw-page-title-main">Vulnerability (computer security)</span></span>
</h1>
</header>
<a id="top"></a>
<div id="bodyContent" class="vector-body ve-init-mw-desktopArticleTarget-targetContainer" aria-labelledby="firstHeading" data-mw-ve-target-container="">
<div id="mw-content-text" class="mw-body-content mw-content-ltr" lang="en" dir="ltr"><div class="mw-content-ltr mw-parser-output" lang="en" dir="ltr">
<style data-mw-deduplicate="TemplateStyles:r1129693374">
/* start https://en.wikipedia.org/ */


.mw-parser-output .hlist dl,.mw-parser-output .hlist ol,.mw-parser-output .hlist ul{margin:0;padding:0}.mw-parser-output .hlist dd,.mw-parser-output .hlist dt,.mw-parser-output .hlist li{margin:0;display:inline}.mw-parser-output .hlist.inline,.mw-parser-output .hlist.inline dl,.mw-parser-output .hlist.inline ol,.mw-parser-output .hlist.inline ul,.mw-parser-output .hlist dl dl,.mw-parser-output .hlist dl ol,.mw-parser-output .hlist dl ul,.mw-parser-output .hlist ol dl,.mw-parser-output .hlist ol ol,.mw-parser-output .hlist ol ul,.mw-parser-output .hlist ul dl,.mw-parser-output .hlist ul ol,.mw-parser-output .hlist ul ul{display:inline}.mw-parser-output .hlist .mw-empty-li{display:none}.mw-parser-output .hlist dt::after{content:": "}.mw-parser-output .hlist dd::after,.mw-parser-output .hlist li::after{content:" · ";font-weight:bold}.mw-parser-output .hlist dd:last-child::after,.mw-parser-output .hlist dt:last-child::after,.mw-parser-output .hlist li:last-child::after{content:none}.mw-parser-output .hlist dd dd:first-child::before,.mw-parser-output .hlist dd dt:first-child::before,.mw-parser-output .hlist dd li:first-child::before,.mw-parser-output .hlist dt dd:first-child::before,.mw-parser-output .hlist dt dt:first-child::before,.mw-parser-output .hlist dt li:first-child::before,.mw-parser-output .hlist li dd:first-child::before,.mw-parser-output .hlist li dt:first-child::before,.mw-parser-output .hlist li li:first-child::before{content:" (";font-weight:normal}.mw-parser-output .hlist dd dd:last-child::after,.mw-parser-output .hlist dd dt:last-child::after,.mw-parser-output .hlist dd li:last-child::after,.mw-parser-output .hlist dt dd:last-child::after,.mw-parser-output .hlist dt dt:last-child::after,.mw-parser-output .hlist dt li:last-child::after,.mw-parser-output .hlist li dd:last-child::after,.mw-parser-output .hlist li dt:last-child::after,.mw-parser-output .hlist li li:last-child::after{content:")";font-weight:normal}.mw-parser-output .hlist ol{counter-reset:listitem}.mw-parser-output .hlist ol>li{counter-increment:listitem}.mw-parser-output .hlist ol>li::before{content:" "counter(listitem)"\a0 "}.mw-parser-output .hlist dd ol>li:first-child::before,.mw-parser-output .hlist dt ol>li:first-child::before,.mw-parser-output .hlist li ol>li:first-child::before{content:" ("counter(listitem)"\a0 "}


/* end https://en.wikipedia.org/ */
</style><style data-mw-deduplicate="TemplateStyles:r1246091330">
/* start https://en.wikipedia.org/ */


.mw-parser-output .sidebar{width:22em;float:right;clear:right;margin:0.5em 0 1em 1em;background:var(--background-color-neutral-subtle,#f8f9fa);border:1px solid var(--border-color-base,#a2a9b1);padding:0.2em;text-align:center;line-height:1.4em;font-size:88%;border-collapse:collapse;display:table}body.skin-minerva .mw-parser-output .sidebar{display:table!important;float:right!important;margin:0.5em 0 1em 1em!important}.mw-parser-output .sidebar-subgroup{width:100%;margin:0;border-spacing:0}.mw-parser-output .sidebar-left{float:left;clear:left;margin:0.5em 1em 1em 0}.mw-parser-output .sidebar-none{float:none;clear:both;margin:0.5em 1em 1em 0}.mw-parser-output .sidebar-outer-title{padding:0 0.4em 0.2em;font-size:125%;line-height:1.2em;font-weight:bold}.mw-parser-output .sidebar-top-image{padding:0.4em}.mw-parser-output .sidebar-top-caption,.mw-parser-output .sidebar-pretitle-with-top-image,.mw-parser-output .sidebar-caption{padding:0.2em 0.4em 0;line-height:1.2em}.mw-parser-output .sidebar-pretitle{padding:0.4em 0.4em 0;line-height:1.2em}.mw-parser-output .sidebar-title,.mw-parser-output .sidebar-title-with-pretitle{padding:0.2em 0.8em;font-size:145%;line-height:1.2em}.mw-parser-output .sidebar-title-with-pretitle{padding:0.1em 0.4em}.mw-parser-output .sidebar-image{padding:0.2em 0.4em 0.4em}.mw-parser-output .sidebar-heading{padding:0.1em 0.4em}.mw-parser-output .sidebar-content{padding:0 0.5em 0.4em}.mw-parser-output .sidebar-content-with-subgroup{padding:0.1em 0.4em 0.2em}.mw-parser-output .sidebar-above,.mw-parser-output .sidebar-below{padding:0.3em 0.8em;font-weight:bold}.mw-parser-output .sidebar-collapse .sidebar-above,.mw-parser-output .sidebar-collapse .sidebar-below{border-top:1px solid #aaa;border-bottom:1px solid #aaa}.mw-parser-output .sidebar-navbar{text-align:right;font-size:115%;padding:0 0.4em 0.4em}.mw-parser-output .sidebar-list-title{padding:0 0.4em;text-align:left;font-weight:bold;line-height:1.6em;font-size:105%}.mw-parser-output .sidebar-list-title-c{padding:0 0.4em;text-align:center;margin:0 3.3em}@media(max-width:640px){body.mediawiki .mw-parser-output .sidebar{width:100%!important;clear:both;float:none!important;margin-left:0!important;margin-right:0!important}}body.skin--responsive .mw-parser-output .sidebar a>img{max-width:none!important}@media screen{html.skin-theme-clientpref-night .mw-parser-output .sidebar:not(.notheme) .sidebar-list-title,html.skin-theme-clientpref-night .mw-parser-output .sidebar:not(.notheme) .sidebar-title-with-pretitle{background:transparent!important}html.skin-theme-clientpref-night .mw-parser-output .sidebar:not(.notheme) .sidebar-title-with-pretitle a{color:var(--color-progressive)!important}}@media screen and (prefers-color-scheme:dark){html.skin-theme-clientpref-os .mw-parser-output .sidebar:not(.notheme) .sidebar-list-title,html.skin-theme-clientpref-os .mw-parser-output .sidebar:not(.notheme) .sidebar-title-with-pretitle{background:transparent!important}html.skin-theme-clientpref-os .mw-parser-output .sidebar:not(.notheme) .sidebar-title-with-pretitle a{color:var(--color-progressive)!important}}@media print{body.ns-0 .mw-parser-output .sidebar{display:none!important}}


/* end https://en.wikipedia.org/ */
</style><style data-mw-deduplicate="TemplateStyles:r1289573984">
/* start https://en.wikipedia.org/ */


.mw-parser-output .computer-hacking .sidebar-list-title{border-top:1px solid #aaa}


/* end https://en.wikipedia.org/ */
</style><table class="sidebar sidebar-collapse nomobile computer-hacking"><tbody><tr><td class="sidebar-pretitle">Part of a series on</td></tr><tr><th class="sidebar-title-with-pretitle"><a href="Security_hacker" title="Security hacker">Computer hacking</a></th></tr><tr><td class="sidebar-image"><span typeof="mw:File"></span></td></tr><tr><td class="sidebar-content">
<div class="sidebar-list mw-collapsible mw-collapsed"><div class="sidebar-list-title" style="color: var(--color-base)"><div class="sidebar-list-title-c"><a href="List_of_security_hacking_incidents" title="List of security hacking incidents">History</a></div></div><div class="sidebar-list-content mw-collapsible-content hlist">
<ul><li><a href="Phreaking" title="Phreaking">Phreaking</a></li>
<li><a href="Cryptovirology" title="Cryptovirology">Cryptovirology</a></li>
<li><a href="Hacking_of_consumer_electronics" title="Hacking of consumer electronics">Hacking of consumer electronics</a></li>
<li><a href="List_of_hackers" title="List of hackers">List of hackers</a></li></ul></div></div></td>
</tr><tr><td class="sidebar-content">
<div class="sidebar-list mw-collapsible mw-collapsed"><div class="sidebar-list-title" style="color: var(--color-base)"><div class="sidebar-list-title-c"><a href="Hacker_culture" title="Hacker culture">Hacker culture</a> and <a href="Hacker_ethic" title="Hacker ethic">ethic</a></div></div><div class="sidebar-list-content mw-collapsible-content hlist">
<ul><li><a href="Hackathon" title="Hackathon">Hackathon</a></li>
<li><i><a href="Hacker_Manifesto" title="Hacker Manifesto">Hacker Manifesto</a></i></li>
<li><a href="Hackerspace" title="Hackerspace">Hackerspace</a></li>
<li><a href="Hacktivism" title="Hacktivism">Hacktivism</a></li>
<li><a href="Maker_culture" title="Maker culture">Maker culture</a></li>
<li>Types of <a href="Hacker" title="Hacker">hackers</a>
<ul><li><a href="Black_hat_(computer_security)" title="Black hat (computer security)">Black hat</a></li>
<li><a href="Grey_hat" title="Grey hat">Grey hat</a></li>
<li><a href="White_hat_(computer_security)" title="White hat (computer security)">White hat</a></li></ul></li></ul></div></div></td>
</tr><tr><td class="sidebar-content">
<div class="sidebar-list mw-collapsible mw-collapsed"><div class="sidebar-list-title" style="color: var(--color-base)"><div class="sidebar-list-title-c"><a href="Computer_security_conference" title="Computer security conference">Conferences</a></div></div><div class="sidebar-list-content mw-collapsible-content hlist">
<ul><li><a href="Black_Hat_Briefings" title="Black Hat Briefings">Black Hat Briefings</a></li>
<li><a href="Chaos_Communication_Congress" title="Chaos Communication Congress">Chaos Communication Congress</a></li>
<li><a href="DEF_CON" title="DEF CON">DEF CON</a></li>
<li><a href="Hackers_on_Planet_Earth" title="Hackers on Planet Earth">Hackers on Planet Earth</a></li>
<li><a href="Security_BSides" title="Security BSides">Security BSides</a></li>
<li><a href="ShmooCon" title="ShmooCon">ShmooCon</a></li>
<li><a href="Summercon" title="Summercon">Summercon</a></li></ul></div></div></td>
</tr><tr><td class="sidebar-content">
<div class="sidebar-list mw-collapsible mw-collapsed"><div class="sidebar-list-title" style="color: var(--color-base)"><div class="sidebar-list-title-c"><a href="Computer_crime" class="mw-redirect" title="Computer crime">Computer crime</a></div></div><div class="sidebar-list-content mw-collapsible-content hlist">
<ul><li><a href="Crimeware" title="Crimeware">Crimeware</a></li>
<li><a href="List_of_computer_criminals" class="mw-redirect" title="List of computer criminals">List of computer criminals</a></li>
<li><a href="Script_kiddie" title="Script kiddie">Script kiddie</a></li></ul></div></div></td>
</tr><tr><td class="sidebar-content">
<div class="sidebar-list mw-collapsible mw-collapsed"><div class="sidebar-list-title" style="color: var(--color-base)"><div class="sidebar-list-title-c"><a href="Hacking_tool" class="mw-redirect" title="Hacking tool">Hacking tools</a></div></div><div class="sidebar-list-content mw-collapsible-content hlist">
<ul><li><a href="Exploit_(computer_security)" title="Exploit (computer security)">Exploit</a></li>
<li><a href="List_of_digital_forensics_tools#Forensics-focused_operating_systems" title="List of digital forensics tools">forensics-focused operating systems</a></li>
<li><a href="Payload_(computing)" title="Payload (computing)">Payload</a></li>
<li><a href="Social_engineering_(security)" title="Social engineering (security)">Social engineering</a></li>
<li><a href="Vulnerability_(computing)" class="mw-redirect" title="Vulnerability (computing)">Vulnerability</a></li></ul></div></div></td>
</tr><tr><td class="sidebar-content">
<div class="sidebar-list mw-collapsible mw-collapsed"><div class="sidebar-list-title" style="color: var(--color-base)"><div class="sidebar-list-title-c"><a href="Hacker_culture" title="Hacker culture">Practice sites</a></div></div><div class="sidebar-list-content mw-collapsible-content hlist">
<ul><li><a href="HackThisSite" title="HackThisSite">HackThisSite</a></li>
<li><a href="Zone-H" title="Zone-H">Zone-H</a></li></ul></div></div></td>
</tr><tr><td class="sidebar-content">
<div class="sidebar-list mw-collapsible mw-collapsed"><div class="sidebar-list-title" style="color: var(--color-base)"><div class="sidebar-list-title-c"><a href="Malware" title="Malware">Malware</a></div></div><div class="sidebar-list-content mw-collapsible-content hlist">
<ul><li><a href="Rootkit" title="Rootkit">Rootkit</a></li>
<li><a href="Backdoor_(computing)" title="Backdoor (computing)">Backdoor</a></li>
<li><a href="Trojan_horse_(computing)" title="Trojan horse (computing)">Trojan horse</a></li>
<li><a href="Computer_virus" title="Computer virus">Virus</a></li>
<li><a href="Computer_worm" title="Computer worm">Worm</a></li>
<li><a href="Spyware" title="Spyware">Spyware</a></li>
<li><a href="Ransomware" title="Ransomware">Ransomware</a></li>
<li><a href="Logic_bomb" title="Logic bomb">Logic bomb</a></li>
<li><a href="Botnet" title="Botnet">Botnet</a></li>
<li><a href="Keystroke_logging" title="Keystroke logging">Keystroke logging</a></li>
<li><a href="Host-based_intrusion_detection_system" title="Host-based intrusion detection system">HIDS</a></li>
<li><a href="Web_shell" title="Web shell">Web shell</a></li>
<li><a href="Arbitrary_code_execution" title="Arbitrary code execution">RCE</a></li>
<li><a href="Infostealer" title="Infostealer">Infostealer</a></li></ul></div></div></td>
</tr><tr><td class="sidebar-content">
<div class="sidebar-list mw-collapsible mw-collapsed"><div class="sidebar-list-title" style="color: var(--color-base)"><div class="sidebar-list-title-c"><a href="Computer_security" title="Computer security">Computer security</a></div></div><div class="sidebar-list-content mw-collapsible-content hlist">
<ul><li><a href="Application_security" title="Application security">Application security</a></li>
<li><a href="Cloud_computing_security" title="Cloud computing security">Cloud computing security</a></li>
<li><a href="Network_security" title="Network security">Network security</a></li></ul></div></div></td>
</tr><tr><td class="sidebar-content">
<div class="sidebar-list mw-collapsible mw-collapsed"><div class="sidebar-list-title" style="color: var(--color-base)"><div class="sidebar-list-title-c"><a href="Hacker_group" title="Hacker group">Groups</a></div></div><div class="sidebar-list-content mw-collapsible-content hlist">
<ul><li><a href="Anonymous_(group)" class="mw-redirect" title="Anonymous (group)">Anonymous</a></li>
<li><a href="Chaos_Computer_Club" title="Chaos Computer Club">Chaos Computer Club</a></li>
<li><a href="Homebrew_Computer_Club" title="Homebrew Computer Club">Homebrew Computer Club</a> (defunct)</li>
<li><a href="Legion_of_Doom_(hacking)" class="mw-redirect" title="Legion of Doom (hacking)">Legion of Doom</a> (defunct)</li>
<li><a href="LulzSec" title="LulzSec">LulzSec</a> (defunct)</li>
<li><a href="Masters_of_Deception" title="Masters of Deception">Masters of Deception</a> (defunct)</li>
<li><a href="Red_team" title="Red team">Red team</a> / <a href="Blue_team_(computer_security)" title="Blue team (computer security)">Blue team</a></li></ul></div></div></td>
</tr><tr><td class="sidebar-content">
<div class="sidebar-list mw-collapsible mw-collapsed"><div class="sidebar-list-title" style="color: var(--color-base)"><div class="sidebar-list-title-c">Publications</div></div><div class="sidebar-list-content mw-collapsible-content hlist">
<ul><li><i><a href="2600%3A_The_Hacker_Quarterly" title="2600: The Hacker Quarterly">2600: The Hacker Quarterly</a></i></li>
<li><a href="Hacker_News" title="Hacker News">Hacker News</a></li>
<li><i><a href="Nuts_and_Volts" title="Nuts and Volts">Nuts and Volts</a></i></li>
<li><i><a href="Phrack" title="Phrack">Phrack</a></i></li></ul></div></div></td>
</tr><tr><td class="sidebar-navbar"><style data-mw-deduplicate="TemplateStyles:r1239400231">
/* start https://en.wikipedia.org/ */


.mw-parser-output .navbar{display:inline;font-size:88%;font-weight:normal}.mw-parser-output .navbar-collapse{float:left;text-align:left}.mw-parser-output .navbar-boxtext{word-spacing:0}.mw-parser-output .navbar ul{display:inline-block;white-space:nowrap;line-height:inherit}.mw-parser-output .navbar-brackets::before{margin-right:-0.125em;content:"[ "}.mw-parser-output .navbar-brackets::after{margin-left:-0.125em;content:" ]"}.mw-parser-output .navbar li{word-spacing:-0.125em}.mw-parser-output .navbar a>span,.mw-parser-output .navbar a>abbr{text-decoration:inherit}.mw-parser-output .navbar-mini abbr{font-variant:small-caps;border-bottom:none;text-decoration:none;cursor:inherit}.mw-parser-output .navbar-ct-full{font-size:114%;margin:0 7em}.mw-parser-output .navbar-ct-mini{font-size:114%;margin:0 4em}html.skin-theme-clientpref-night .mw-parser-output .navbar li a abbr{color:var(--color-base)!important}@media(prefers-color-scheme:dark){html.skin-theme-clientpref-os .mw-parser-output .navbar li a abbr{color:var(--color-base)!important}}@media print{.mw-parser-output .navbar{display:none!important}}


/* end https://en.wikipedia.org/ */
</style></td></tr></tbody></table>
<p><b>Vulnerabilities</b> are flaws or weaknesses in a system's design, implementation, or management that can be exploited by a malicious actor to compromise its security.
</p><p>Despite a <a href="System_administrator" title="System administrator">system administrator</a>'s best efforts to achieve complete correctness, virtually all hardware and software contain <a href="Software_bug" title="Software bug">bugs</a> where the system does not behave as expected. If the bug could enable an attacker to compromise the <a href="Confidentiality" title="Confidentiality">confidentiality</a>, <a href="Data_integrity" title="Data integrity">integrity</a>, or <a href="Availability" title="Availability">availability</a> of system resources, it can be considered a vulnerability. Insecure <a href="Software_development" title="Software development">software development</a> practices as well as design factors such as complexity can increase the burden of vulnerabilities.
</p><p><a href="Vulnerability_management" title="Vulnerability management">Vulnerability management</a> is a process that includes identifying systems and prioritizing which are most important, scanning for vulnerabilities, and taking action to secure the system. Vulnerability management typically is a combination of remediation, mitigation, and acceptance.
</p><p>Vulnerabilities can be scored for severity according to the <a href="Common_Vulnerability_Scoring_System" title="Common Vulnerability Scoring System">Common Vulnerability Scoring System</a> (CVSS) and added to vulnerability databases such as the <a href="Common_Vulnerabilities_and_Exposures" title="Common Vulnerabilities and Exposures">Common Vulnerabilities and Exposures</a> (CVE) database. As of November 2024, there are more than 240,000 vulnerabilities catalogued in the CVE database.<sup id="cite_ref-Metrics_1-0" class="reference"><a href="#cite_note-Metrics-1"><span class="cite-bracket">[</span>1<span class="cite-bracket">]</span></a></sup>
</p><p>A vulnerability is initiated when it is introduced into hardware or software. It becomes active and exploitable when the software or hardware containing the vulnerability is running. The vulnerability may be discovered by the administrator, vendor, or a third party. Publicly <a href="Full_disclosure_(computer_security)" title="Full disclosure (computer security)">disclosing the vulnerability</a> (through a <a href="Patch_(computing)" title="Patch (computing)">patch</a> or otherwise) is associated with an increased risk of compromise, as attackers can use this knowledge to target existing systems before patches are implemented. Vulnerabilities will eventually end when the system is either patched or removed from use.
</p>
<meta property="mw:PageProp/toc">
<div class="mw-heading mw-heading2"><h2 id="Causes">Causes</h2></div>
<p>Despite a system administrator's best efforts, virtually all hardware and software contain bugs.<sup id="cite_ref-FOOTNOTEAblonBogart20171_2-0" class="reference"><a href="#cite_note-FOOTNOTEAblonBogart20171-2"><span class="cite-bracket">[</span>2<span class="cite-bracket">]</span></a></sup> If a bug creates a security risk, it is called a vulnerability.<sup id="cite_ref-FOOTNOTEAblonBogart20172_3-0" class="reference"><a href="#cite_note-FOOTNOTEAblonBogart20172-3"><span class="cite-bracket">[</span>3<span class="cite-bracket">]</span></a></sup><sup id="cite_ref-FOOTNOTEDaswaniElbayadi202125_4-0" class="reference"><a href="#cite_note-FOOTNOTEDaswaniElbayadi202125-4"><span class="cite-bracket">[</span>4<span class="cite-bracket">]</span></a></sup><sup id="cite_ref-FOOTNOTESeaman202047–48_5-0" class="reference"><a href="#cite_note-FOOTNOTESeaman202047–48-5"><span class="cite-bracket">[</span>5<span class="cite-bracket">]</span></a></sup> Software patches are often released to fix identified vulnerabilities, but <a href="Zero-days" class="mw-redirect" title="Zero-days">zero-days</a> are still liable for exploitation.<sup id="cite_ref-FOOTNOTEDaswaniElbayadi202126–27_6-0" class="reference"><a href="#cite_note-FOOTNOTEDaswaniElbayadi202126–27-6"><span class="cite-bracket">[</span>6<span class="cite-bracket">]</span></a></sup> Vulnerabilities vary in their ability to be <a href="Exploit_(computer_security)" title="Exploit (computer security)">exploited</a> by malicious actors, and the actual risk is dependent on the nature of the vulnerability as well as the value of the surrounding system.<sup id="cite_ref-FOOTNOTEHaberHibbert20185–6_7-0" class="reference"><a href="#cite_note-FOOTNOTEHaberHibbert20185–6-7"><span class="cite-bracket">[</span>7<span class="cite-bracket">]</span></a></sup> Although some vulnerabilities can only be used for <a href="Denial_of_service" class="mw-redirect" title="Denial of service">denial of service</a> attacks, more dangerous ones allow the attacker to perform <a href="Code_injection" title="Code injection">code injection</a> without the user's awareness.<sup id="cite_ref-FOOTNOTEAblonBogart20172_3-1" class="reference"><a href="#cite_note-FOOTNOTEAblonBogart20172-3"><span class="cite-bracket">[</span>3<span class="cite-bracket">]</span></a></sup> Only a minority of vulnerabilities allow for <a href="Privilege_escalation" title="Privilege escalation">privilege escalation</a>, which is typically necessary for more severe attacks.<sup id="cite_ref-FOOTNOTEHaberHibbert20186_8-0" class="reference"><a href="#cite_note-FOOTNOTEHaberHibbert20186-8"><span class="cite-bracket">[</span>8<span class="cite-bracket">]</span></a></sup> Without a vulnerability, an exploit typically cannot gain access.<sup id="cite_ref-FOOTNOTEHaberHibbert201810_9-0" class="reference"><a href="#cite_note-FOOTNOTEHaberHibbert201810-9"><span class="cite-bracket">[</span>9<span class="cite-bracket">]</span></a></sup> It is also possible for <a href="Malware" title="Malware">malware</a> to be installed directly, without an exploit, through <a href="Social_engineering_(security)" title="Social engineering (security)">social engineering</a> or poor <a href="Physical_security" title="Physical security">physical security</a> such as an unlocked door or exposed port.<sup id="cite_ref-FOOTNOTEHaberHibbert201813–14_10-0" class="reference"><a href="#cite_note-FOOTNOTEHaberHibbert201813–14-10"><span class="cite-bracket">[</span>10<span class="cite-bracket">]</span></a></sup>
</p>
<div class="mw-heading mw-heading3"><h3 id="Design_factors">Design factors</h3></div>
<p>Vulnerabilities can be worsened by poor design factors, such as:
</p>
<ul><li>Complexity: Large, complex systems increase the possibility of flaws and unintended access points.<sup id="cite_ref-Vacca23_11-0" class="reference"><a href="#cite_note-Vacca23-11"><span class="cite-bracket">[</span>11<span class="cite-bracket">]</span></a></sup></li>
<li>Familiarity: Using common, well-known code, software, operating systems, and/or hardware increases the probability an attacker has or can find the knowledge and tools to exploit the flaw.<sup id="cite_ref-12" class="reference"><a href="#cite_note-12"><span class="cite-bracket">[</span>12<span class="cite-bracket">]</span></a></sup> However, using well-known software, particularly <a href="Free_and_open-source_software" title="Free and open-source software">free and open-source software</a>, comes with the benefit of having more frequent and reliable software patches for any discovered vulnerabilities.</li>
<li>Connectivity: any system connected to the internet can be accessed and compromised. <a href="Air_gap_(networking)" title="Air gap (networking)">Disconnecting systems from the internet</a> can be extremely effective at preventing attacks, but it is not always feasible.<sup id="cite_ref-FOOTNOTELinkovKott20192_13-0" class="reference"><a href="#cite_note-FOOTNOTELinkovKott20192-13"><span class="cite-bracket">[</span>13<span class="cite-bracket">]</span></a></sup></li>
<li><a href="Legacy_software" class="mw-redirect" title="Legacy software">Legacy software</a> and <a href="Legacy_hardware" class="mw-redirect" title="Legacy hardware">hardware</a> is at increased risk by nature.<sup id="cite_ref-FOOTNOTEHaberHibbert2018155_14-0" class="reference"><a href="#cite_note-FOOTNOTEHaberHibbert2018155-14"><span class="cite-bracket">[</span>14<span class="cite-bracket">]</span></a></sup> System administrators should consider upgrading from legacy systems, but this is often prohibitive in terms of cost and <a href="Downtime" title="Downtime">downtime</a>.</li></ul>
<div class="mw-heading mw-heading3"><h3 id="Development_factors">Development factors</h3></div>
<p>Some <a href="Software_development" title="Software development">software development</a> practices can affect the risk of vulnerabilities being introduced to a code base. Lack of knowledge about secure software development or excessive pressure to deliver features quickly can lead to avoidable vulnerabilities to enter production code, especially if security is not prioritized by the <a href="Company_culture" class="mw-redirect" title="Company culture">company culture</a>. This can lead to unintended vulnerabilities. The more complex the system is, the easier it is for vulnerabilities to go undetected. Some vulnerabilities are deliberately planted, which could be for any reason from a disgruntled employee selling access to cyber criminals, to sophisticated state-sponsored schemes to introduce vulnerabilities to software.
</p><p>Poor <a href="Software_development" title="Software development">software development</a> practices can affect the likelihood of introducing vulnerabilities to a code base. Lack of knowledge or training regarding secure software development, excessive pressure to deliver, or an excessively complex code base can all allow vulnerabilities to be introduced and left unnoticed. These factors can also be exacerbated if security is not prioritized by the <a href="Company_culture" class="mw-redirect" title="Company culture">company culture</a>. <sup id="cite_ref-FOOTNOTEStrout202317_15-0" class="reference"><a href="#cite_note-FOOTNOTEStrout202317-15"><span class="cite-bracket">[</span>15<span class="cite-bracket">]</span></a></sup> Inadequate <a href="Code_review" title="Code review">code reviews</a> can also lead to missed bugs, but there are also <a href="Static_application_security_testing" title="Static application security testing">static code analysis</a> tools that can be used during the code review process to help find some vulnerabilities.<sup id="cite_ref-FOOTNOTEHaberHibbert2018143_16-0" class="reference"><a href="#cite_note-FOOTNOTEHaberHibbert2018143-16"><span class="cite-bracket">[</span>16<span class="cite-bracket">]</span></a></sup>
</p><p><a href="DevOps" title="DevOps">DevOps</a>, a development workflow that emphasizes automated testing and deployment to speed up the deployment of new features, often requires that many developers be granted access to change configurations, which can lead to deliberate or inadvertent inclusion of vulnerabilities.<sup id="cite_ref-FOOTNOTEHaberHibbert2018141_17-0" class="reference"><a href="#cite_note-FOOTNOTEHaberHibbert2018141-17"><span class="cite-bracket">[</span>17<span class="cite-bracket">]</span></a></sup> Compartmentalizing dependencies, which is often part of DevOps workflows, can reduce the <a href="Attack_surface" title="Attack surface">attack surface</a> by paring down dependencies to only what is necessary.<sup id="cite_ref-FOOTNOTEHaberHibbert2018142_18-0" class="reference"><a href="#cite_note-FOOTNOTEHaberHibbert2018142-18"><span class="cite-bracket">[</span>18<span class="cite-bracket">]</span></a></sup> If <a href="Software_as_a_service" title="Software as a service">software as a service</a> is used, rather than the organization's own hardware and software, the organization is dependent on the cloud services provider to prevent vulnerabilities.<sup id="cite_ref-FOOTNOTEHaberHibbert2018135–137_19-0" class="reference"><a href="#cite_note-FOOTNOTEHaberHibbert2018135–137-19"><span class="cite-bracket">[</span>19<span class="cite-bracket">]</span></a></sup>
</p>
<div class="mw-heading mw-heading3"><h3 id="National_Vulnerability_Database_classification">National Vulnerability Database classification</h3></div>
<style data-mw-deduplicate="TemplateStyles:r1305433154">
/* start https://en.wikipedia.org/ */


.mw-parser-output .ambox{border:1px solid #a2a9b1;border-left:10px solid #36c;background-color:#fbfbfb;box-sizing:border-box}.mw-parser-output .ambox+link+.ambox,.mw-parser-output .ambox+link+style+.ambox,.mw-parser-output .ambox+link+link+.ambox,.mw-parser-output .ambox+.mw-empty-elt+link+.ambox,.mw-parser-output .ambox+.mw-empty-elt+link+style+.ambox,.mw-parser-output .ambox+.mw-empty-elt+link+link+.ambox{margin-top:-1px}html body.mediawiki .mw-parser-output .ambox.mbox-small-left{margin:4px 1em 4px 0;overflow:hidden;width:238px;border-collapse:collapse;font-size:88%;line-height:1.25em}.mw-parser-output .ambox-speedy{border-left:10px solid #b32424;background-color:#fee7e6}.mw-parser-output .ambox-delete{border-left:10px solid #b32424}.mw-parser-output .ambox-content{border-left:10px solid #f28500}.mw-parser-output .ambox-style{border-left:10px solid #fc3}.mw-parser-output .ambox-move{border-left:10px solid #9932cc}.mw-parser-output .ambox-protection{border-left:10px solid #a2a9b1}.mw-parser-output .ambox .mbox-text{border:none;padding:0.25em 0.5em;width:100%}.mw-parser-output .ambox .mbox-image{border:none;padding:2px 0 2px 0.5em;text-align:center}.mw-parser-output .ambox .mbox-imageright{border:none;padding:2px 0.5em 2px 0;text-align:center}.mw-parser-output .ambox .mbox-empty-cell{border:none;padding:0;width:1px}.mw-parser-output .ambox .mbox-image-div{width:52px}@media(min-width:720px){.mw-parser-output .ambox{margin:0 10%}}@media print{body.ns-0 .mw-parser-output .ambox{display:none!important}}


/* end https://en.wikipedia.org/ */
</style>
<p>The <a href="National_Vulnerability_Database" title="National Vulnerability Database">National Vulnerability Database</a> classifies vulnerabilities into eight root causes that may be overlapping, including:<sup id="cite_ref-FOOTNOTEGargBaliyan202317–18_20-0" class="reference"><a href="#cite_note-FOOTNOTEGargBaliyan202317–18-20"><span class="cite-bracket">[</span>20<span class="cite-bracket">]</span></a></sup>
</p>
<ol><li><a href="Improper_input_validation" title="Improper input validation">Input validation</a> vulnerabilities exist when <a href="Input_checking" class="mw-redirect" title="Input checking">input checking</a> is not sufficient to prevent the attacker from injecting malicious code. <a href="Buffer_overflow" title="Buffer overflow">Buffer overflow</a> exploits, <a href="Buffer_underflow" class="mw-redirect" title="Buffer underflow">buffer underflow</a> exploits, and <a href="Boundary_condition" class="mw-redirect" title="Boundary condition">boundary condition</a> exploits typically take advantage of this category.<sup id="cite_ref-FOOTNOTEGargBaliyan202317_21-0" class="reference"><a href="#cite_note-FOOTNOTEGargBaliyan202317-21"><span class="cite-bracket">[</span>21<span class="cite-bracket">]</span></a></sup></li>
<li><a href="Access_control" title="Access control">Access control</a> vulnerabilities enable an attacker to access a system that is supposed to be restricted to them, or engage in <a href="Privilege_escalation" title="Privilege escalation">privilege escalation</a>.<sup id="cite_ref-FOOTNOTEGargBaliyan202317_21-1" class="reference"><a href="#cite_note-FOOTNOTEGargBaliyan202317-21"><span class="cite-bracket">[</span>21<span class="cite-bracket">]</span></a></sup></li>
<li>When the system fails to handle and exceptional or unanticipated condition correctly, an attacker can exploit the situation to gain access.<sup id="cite_ref-FOOTNOTEGargBaliyan202318_22-0" class="reference"><a href="#cite_note-FOOTNOTEGargBaliyan202318-22"><span class="cite-bracket">[</span>22<span class="cite-bracket">]</span></a></sup></li>
<li>Configuration vulnerability come into existence when configuration settings cause risks to the system security, leading to such faults as unpatched software or file system permissions that do not sufficiently restrict access.<sup id="cite_ref-FOOTNOTEGargBaliyan202318_22-1" class="reference"><a href="#cite_note-FOOTNOTEGargBaliyan202318-22"><span class="cite-bracket">[</span>22<span class="cite-bracket">]</span></a></sup></li>
<li>A <a href="Race_condition" title="Race condition">race condition</a>—when timing or other external factors change the outcome and lead to inconsistent or unpredictable results—can cause a vulnerability.<sup id="cite_ref-FOOTNOTEGargBaliyan202318_22-2" class="reference"><a href="#cite_note-FOOTNOTEGargBaliyan202318-22"><span class="cite-bracket">[</span>22<span class="cite-bracket">]</span></a></sup></li></ol>
<div class="mw-heading mw-heading2"><h2 id="Vulnerabilities_by_component">Vulnerabilities by component</h2></div>
<div class="mw-heading mw-heading3"><h3 id="Hardware">Hardware</h3></div>
<style data-mw-deduplicate="TemplateStyles:r1236090951">
/* start https://en.wikipedia.org/ */


.mw-parser-output .hatnote{font-style:italic}.mw-parser-output div.hatnote{padding-left:1.6em;margin-bottom:0.5em}.mw-parser-output .hatnote i{font-style:normal}.mw-parser-output .hatnote+link+.hatnote{margin-top:-0.5em}@media print{body.ns-0 .mw-parser-output .hatnote{display:none!important}}


/* end https://en.wikipedia.org/ */
</style><div role="note" class="hatnote navigation-not-searchable">Main article: <a href="Hardware_security_bug" title="Hardware security bug">Hardware security bug</a></div>
<p>Deliberate security bugs can be introduced during or after manufacturing and cause the <a href="Integrated_circuit" title="Integrated circuit">integrated circuit</a> not to behave as expected under certain specific circumstances. Testing for security bugs in hardware is quite difficult due to limited time and the complexity of twenty-first century chips,<sup id="cite_ref-FOOTNOTESalmani20181_23-0" class="reference"><a href="#cite_note-FOOTNOTESalmani20181-23"><span class="cite-bracket">[</span>23<span class="cite-bracket">]</span></a></sup> while the globalization of design and manufacturing has increased the opportunity for these bugs to be introduced by malicious actors.<sup id="cite_ref-FOOTNOTESalmani201811_24-0" class="reference"><a href="#cite_note-FOOTNOTESalmani201811-24"><span class="cite-bracket">[</span>24<span class="cite-bracket">]</span></a></sup>
</p>
<div class="mw-heading mw-heading3"><h3 id="Operating_system">Operating system</h3></div>
<div role="note" class="hatnote navigation-not-searchable">See also: <a href="Operating_system#Security" title="Operating system">Operating system §&nbsp;Security</a></div>
<p>Although operating system vulnerabilities vary depending on the <a href="Operating_system" title="Operating system">operating system</a> in use, a common problem is <a href="Privilege_escalation" title="Privilege escalation">privilege escalation</a> bugs that enable the attacker to gain more access than they should be allowed. <a href="Open-source" class="mw-redirect" title="Open-source">Open-source</a> operating systems such as <a href="Linux" title="Linux">Linux</a> and <a href="Android_(operating_system)" title="Android (operating system)">Android</a> have a freely accessible <a href="Source_code" title="Source code">source code</a> and allow anyone to contribute, which could enable the introduction of vulnerabilities. However, the same vulnerabilities also occur in proprietary operating systems such as <a href="Microsoft_Windows" title="Microsoft Windows">Microsoft Windows</a> and <a href="List_of_Apple_operating_systems" title="List of Apple operating systems">Apple operating systems</a>.<sup id="cite_ref-FOOTNOTEGargBaliyan202320–25_25-0" class="reference"><a href="#cite_note-FOOTNOTEGargBaliyan202320–25-25"><span class="cite-bracket">[</span>25<span class="cite-bracket">]</span></a></sup> All reputable vendors of operating systems provide patches regularly.<sup id="cite_ref-FOOTNOTESharp2024271_26-0" class="reference"><a href="#cite_note-FOOTNOTESharp2024271-26"><span class="cite-bracket">[</span>26<span class="cite-bracket">]</span></a></sup>
</p>
<div class="mw-heading mw-heading3"><h3 id="Client–server_applications">Client–server applications</h3></div>
<p><a href="Client%E2%80%93server_model" title="Client–server model">Client–server applications</a> are downloaded onto the end user's computers and are typically updated less frequently than web applications. Unlike web applications, they interact directly with a user's <a href="Operating_system" title="Operating system">operating system</a>. Common vulnerabilities in these applications include:<sup id="cite_ref-FOOTNOTEStrout202315_27-0" class="reference"><a href="#cite_note-FOOTNOTEStrout202315-27"><span class="cite-bracket">[</span>27<span class="cite-bracket">]</span></a></sup>
</p>
<ul><li>Unencrypted data that is in permanent storage or sent over a network is relatively easy for attackers to steal.<sup id="cite_ref-FOOTNOTEStrout202315_27-1" class="reference"><a href="#cite_note-FOOTNOTEStrout202315-27"><span class="cite-bracket">[</span>27<span class="cite-bracket">]</span></a></sup></li>
<li>Process hijacking occurs when an attacker takes over an existing <a href="Computer_process" class="mw-redirect" title="Computer process">computer process</a>.<sup id="cite_ref-FOOTNOTEStrout202315_27-2" class="reference"><a href="#cite_note-FOOTNOTEStrout202315-27"><span class="cite-bracket">[</span>27<span class="cite-bracket">]</span></a></sup></li></ul>
<div class="mw-heading mw-heading3"><h3 id="Web_applications">Web applications</h3></div>
<p><a href="Web_applications" class="mw-redirect" title="Web applications">Web applications</a> run on many websites. Because they are inherently less secure than other applications, they are a leading source of <a href="Data_breach" title="Data breach">data breaches</a> and other security incidents.<sup id="cite_ref-FOOTNOTEStrout202313_28-0" class="reference"><a href="#cite_note-FOOTNOTEStrout202313-28"><span class="cite-bracket">[</span>28<span class="cite-bracket">]</span></a></sup><sup id="cite_ref-FOOTNOTEHaberHibbert2018129_29-0" class="reference"><a href="#cite_note-FOOTNOTEHaberHibbert2018129-29"><span class="cite-bracket">[</span>29<span class="cite-bracket">]</span></a></sup> They can include:
</p>
<ul><li><a href="Authentication" title="Authentication">Authentication</a> and <a href="Authorization" title="Authorization">authorization</a> failures enable attackers to access data that should be restricted to trusted users.<sup id="cite_ref-FOOTNOTEStrout202313_28-1" class="reference"><a href="#cite_note-FOOTNOTEStrout202313-28"><span class="cite-bracket">[</span>28<span class="cite-bracket">]</span></a></sup></li>
<li>Business logic vulnerability occurs when programmers do not consider unexpected cases arising in <a href="Business_logic" title="Business logic">business logic</a>.</li></ul>
<p>Attacks used against vulnerabilities in web applications include:
</p>
<ul><li><a href="Cross-site_scripting" title="Cross-site scripting">Cross-site scripting</a> (XSS) enables attackers to <a href="Code_injection" title="Code injection">inject</a> and run <a href="JavaScript" title="JavaScript">JavaScript</a>-based <a href="Malware" title="Malware">malware</a> when <a href="Input_checking" class="mw-redirect" title="Input checking">input checking</a> is insufficient to reject the injected code.<sup id="cite_ref-FOOTNOTEStrout202313_28-2" class="reference"><a href="#cite_note-FOOTNOTEStrout202313-28"><span class="cite-bracket">[</span>28<span class="cite-bracket">]</span></a></sup> XSS can be persistent, when attackers save the malware in a data field and run it when the data is loaded; it can also be loaded using a malicious <a href="URL" title="URL">URL</a> link (reflected XSS).<sup id="cite_ref-FOOTNOTEStrout202313_28-3" class="reference"><a href="#cite_note-FOOTNOTEStrout202313-28"><span class="cite-bracket">[</span>28<span class="cite-bracket">]</span></a></sup> Attackers can also insert malicious code into the <a href="Domain_object_model" class="mw-redirect" title="Domain object model">domain object model</a>.<sup id="cite_ref-FOOTNOTEStrout202314_30-0" class="reference"><a href="#cite_note-FOOTNOTEStrout202314-30"><span class="cite-bracket">[</span>30<span class="cite-bracket">]</span></a></sup></li>
<li><a href="SQL_injection" title="SQL injection">SQL injection</a> and similar attacks manipulate <a href="Database_queries" class="mw-redirect" title="Database queries">database queries</a> to gain unauthorized access to data.<sup id="cite_ref-FOOTNOTEStrout202314_30-1" class="reference"><a href="#cite_note-FOOTNOTEStrout202314-30"><span class="cite-bracket">[</span>30<span class="cite-bracket">]</span></a></sup></li>
<li><a href="Command_injection" class="mw-redirect" title="Command injection">Command injection</a> is a form of code injection where the attacker places the malware in data fields or <a href="Process" title="Process">processes</a>. The attacker might be able to take over the entire server.<sup id="cite_ref-FOOTNOTEStrout202314_30-2" class="reference"><a href="#cite_note-FOOTNOTEStrout202314-30"><span class="cite-bracket">[</span>30<span class="cite-bracket">]</span></a></sup></li>
<li><a href="Cross-site_request_forgery" title="Cross-site request forgery">Cross-site request forgery</a> (CSRF) is creating client requests that do malicious actions, such as an attacker changing a user's credentials.<sup id="cite_ref-FOOTNOTEStrout202314_30-3" class="reference"><a href="#cite_note-FOOTNOTEStrout202314-30"><span class="cite-bracket">[</span>30<span class="cite-bracket">]</span></a></sup></li>
<li><a href="Server-side_request_forgery" title="Server-side request forgery">Server-side request forgery</a> is similar to CSRF, but the request is forged from the server side and often exploits the enhanced privilege of the server.<sup id="cite_ref-FOOTNOTEStrout202314_30-4" class="reference"><a href="#cite_note-FOOTNOTEStrout202314-30"><span class="cite-bracket">[</span>30<span class="cite-bracket">]</span></a></sup></li>
<li>Business logic vulnerability occurs when programmers do not consider unexpected cases arising in <a href="Business_logic" title="Business logic">business logic</a>.<sup id="cite_ref-FOOTNOTEStrout202314–15_31-0" class="reference"><a href="#cite_note-FOOTNOTEStrout202314–15-31"><span class="cite-bracket">[</span>31<span class="cite-bracket">]</span></a></sup></li></ul>
<div class="mw-heading mw-heading2"><h2 id="Management">Management</h2></div>
<div role="note" class="hatnote navigation-not-searchable">Main article: <a href="Vulnerability_management" title="Vulnerability management">Vulnerability management</a></div>
<p>There is little evidence about the effectiveness and cost-effectiveness of different cyberattack prevention measures.<sup id="cite_ref-FOOTNOTEAgrafiotis_''et_al.''20182_32-0" class="reference"><a href="#cite_note-FOOTNOTEAgrafiotis_''et_al.''20182-32"><span class="cite-bracket">[</span>32<span class="cite-bracket">]</span></a></sup> Although estimating the risk of an attack is not straightforward, the mean time to breach and expected cost can be considered to determine the priority for remediating or mitigating an identified vulnerability and whether it is cost effective to do so.<sup id="cite_ref-FOOTNOTEHaberHibbert201897–98_33-0" class="reference"><a href="#cite_note-FOOTNOTEHaberHibbert201897–98-33"><span class="cite-bracket">[</span>33<span class="cite-bracket">]</span></a></sup> Although attention to security can reduce the risk of attack, achieving perfect security for a complex system is impossible, and many security measures have unacceptable cost or usability downsides.<sup id="cite_ref-FOOTNOTETjoa_''et_al.''202463_34-0" class="reference"><a href="#cite_note-FOOTNOTETjoa_''et_al.''202463-34"><span class="cite-bracket">[</span>34<span class="cite-bracket">]</span></a></sup> For example, reducing the complexity and functionality of the system is effective at reducing the <a href="Attack_surface" title="Attack surface">attack surface</a>.<sup id="cite_ref-FOOTNOTETjoa_''et_al.''202468,_70_35-0" class="reference"><a href="#cite_note-FOOTNOTETjoa_''et_al.''202468,_70-35"><span class="cite-bracket">[</span>35<span class="cite-bracket">]</span></a></sup>
</p><p>Successful vulnerability management usually involves a combination of remediation (closing a vulnerability), mitigation (increasing the difficulty, and reducing the consequences, of exploits), and accepting some residual risk. Often a <a href="Defense_in_depth" class="mw-redirect" title="Defense in depth">defense in depth</a> strategy is used for multiple barriers to attack.<sup id="cite_ref-FOOTNOTEMagnusson202034_36-0" class="reference"><a href="#cite_note-FOOTNOTEMagnusson202034-36"><span class="cite-bracket">[</span>36<span class="cite-bracket">]</span></a></sup> Some organizations scan for only the highest-risk vulnerabilities as this enables prioritization in the context of lacking the resources to fix every vulnerability.<sup id="cite_ref-FOOTNOTEHaberHibbert2018166–167_37-0" class="reference"><a href="#cite_note-FOOTNOTEHaberHibbert2018166–167-37"><span class="cite-bracket">[</span>37<span class="cite-bracket">]</span></a></sup> Increasing expenses is likely to have <a href="Diminishing_returns" title="Diminishing returns">diminishing returns</a>.<sup id="cite_ref-FOOTNOTEHaberHibbert201897–98_33-1" class="reference"><a href="#cite_note-FOOTNOTEHaberHibbert201897–98-33"><span class="cite-bracket">[</span>33<span class="cite-bracket">]</span></a></sup>
</p>
<div class="mw-heading mw-heading3"><h3 id="Remediation">Remediation</h3></div>
<p>Remediation fixes vulnerabilities, for example by downloading a <a href="Software_patch" class="mw-redirect" title="Software patch">software patch</a>.<sup id="cite_ref-FOOTNOTEHaberHibbert201811_38-0" class="reference"><a href="#cite_note-FOOTNOTEHaberHibbert201811-38"><span class="cite-bracket">[</span>38<span class="cite-bracket">]</span></a></sup> <a href="Vulnerability_scanner" title="Vulnerability scanner">Vulnerability scanners</a> are typically unable to detect zero-day vulnerabilities, but are more effective at finding known vulnerabilities based on a database. These systems can find some known vulnerabilities and advise fixes, such as a patch.<sup id="cite_ref-FOOTNOTEStrout20238_39-0" class="reference"><a href="#cite_note-FOOTNOTEStrout20238-39"><span class="cite-bracket">[</span>39<span class="cite-bracket">]</span></a></sup><sup id="cite_ref-FOOTNOTEHaberHibbert201812–13_40-0" class="reference"><a href="#cite_note-FOOTNOTEHaberHibbert201812–13-40"><span class="cite-bracket">[</span>40<span class="cite-bracket">]</span></a></sup> However, they have limitations including <a href="False_positive" class="mw-redirect" title="False positive">false positives</a>.<sup id="cite_ref-FOOTNOTEHaberHibbert201811_38-1" class="reference"><a href="#cite_note-FOOTNOTEHaberHibbert201811-38"><span class="cite-bracket">[</span>38<span class="cite-bracket">]</span></a></sup>
</p><p>Vulnerabilities can only be exploited when they are active-the software in which they are embedded is actively running on the system.<sup id="cite_ref-FOOTNOTEHaberHibbert201884_41-0" class="reference"><a href="#cite_note-FOOTNOTEHaberHibbert201884-41"><span class="cite-bracket">[</span>41<span class="cite-bracket">]</span></a></sup> Before the code containing the vulnerability is configured to run on the system, it is considered a carrier.<sup id="cite_ref-FOOTNOTEHaberHibbert201885_42-0" class="reference"><a href="#cite_note-FOOTNOTEHaberHibbert201885-42"><span class="cite-bracket">[</span>42<span class="cite-bracket">]</span></a></sup> Dormant vulnerabilities can run, but are not currently running. Software containing dormant and carrier vulnerabilities can sometimes be uninstalled or disabled, removing the risk.<sup id="cite_ref-FOOTNOTEHaberHibbert201884–85_43-0" class="reference"><a href="#cite_note-FOOTNOTEHaberHibbert201884–85-43"><span class="cite-bracket">[</span>43<span class="cite-bracket">]</span></a></sup> Active vulnerabilities, if distinguished from the other types, can be prioritized for patching.<sup id="cite_ref-FOOTNOTEHaberHibbert201884_41-1" class="reference"><a href="#cite_note-FOOTNOTEHaberHibbert201884-41"><span class="cite-bracket">[</span>41<span class="cite-bracket">]</span></a></sup>
</p><p>Vulnerability mitigation is measures that do not close the vulnerability, but make it more difficult to exploit or reduce the consequences of an attack.<sup id="cite_ref-FOOTNOTEMagnusson202032_44-0" class="reference"><a href="#cite_note-FOOTNOTEMagnusson202032-44"><span class="cite-bracket">[</span>44<span class="cite-bracket">]</span></a></sup> Reducing the <a href="Attack_surface" title="Attack surface">attack surface</a>, particularly for parts of the system with <a href="Superuser" title="Superuser">root</a> (administrator) access, and closing off opportunities for exploits to engage in privilege exploitation is a common strategy for reducing the harm that a cyberattack can cause.<sup id="cite_ref-FOOTNOTEHaberHibbert201811_38-2" class="reference"><a href="#cite_note-FOOTNOTEHaberHibbert201811-38"><span class="cite-bracket">[</span>38<span class="cite-bracket">]</span></a></sup> If a patch for third-party software is unavailable, it may be possible to temporarily disable the software.<sup id="cite_ref-FOOTNOTEMagnusson202033_45-0" class="reference"><a href="#cite_note-FOOTNOTEMagnusson202033-45"><span class="cite-bracket">[</span>45<span class="cite-bracket">]</span></a></sup>
</p>
<div class="mw-heading mw-heading3"><h3 id="Testing">Testing</h3></div>
<p>A <a href="Penetration_test" title="Penetration test">penetration test</a> attempts to enter the system via an exploit to see if the system is insecure.<sup id="cite_ref-FOOTNOTEHaberHibbert201893_46-0" class="reference"><a href="#cite_note-FOOTNOTEHaberHibbert201893-46"><span class="cite-bracket">[</span>46<span class="cite-bracket">]</span></a></sup> If a penetration test fails, it does not necessarily mean that the system is secure.<sup id="cite_ref-FOOTNOTEHaberHibbert201896_47-0" class="reference"><a href="#cite_note-FOOTNOTEHaberHibbert201896-47"><span class="cite-bracket">[</span>47<span class="cite-bracket">]</span></a></sup> Some penetration tests can be conducted with automated software that tests against existing exploits for known vulnerabilities.<sup id="cite_ref-FOOTNOTEHaberHibbert201894_48-0" class="reference"><a href="#cite_note-FOOTNOTEHaberHibbert201894-48"><span class="cite-bracket">[</span>48<span class="cite-bracket">]</span></a></sup> Other penetration tests are conducted by trained hackers. Many companies prefer to contract out this work as it simulates an outsider attack.<sup id="cite_ref-FOOTNOTEHaberHibbert201896_47-1" class="reference"><a href="#cite_note-FOOTNOTEHaberHibbert201896-47"><span class="cite-bracket">[</span>47<span class="cite-bracket">]</span></a></sup>
</p>
<div class="mw-heading mw-heading2"><h2 id="Vulnerability_lifecycle">Vulnerability lifecycle</h2></div>

<p>The vulnerability lifecycle begins when vulnerabilities are introduced into hardware or software.<sup id="cite_ref-FOOTNOTEStrout202316_49-0" class="reference"><a href="#cite_note-FOOTNOTEStrout202316-49"><span class="cite-bracket">[</span>49<span class="cite-bracket">]</span></a></sup> Detection of vulnerabilities can be by the software vendor, or by a third party. In the latter case, it is considered most ethical to immediately disclose the vulnerability to the vendor so it can be fixed.<sup id="cite_ref-FOOTNOTEStrout202318_50-0" class="reference"><a href="#cite_note-FOOTNOTEStrout202318-50"><span class="cite-bracket">[</span>50<span class="cite-bracket">]</span></a></sup> Government or intelligence agencies buy vulnerabilities that have not been publicly disclosed and may use them in an attack, stockpile them, or notify the vendor.<sup id="cite_ref-FOOTNOTELibickiAblonWebb201544_51-0" class="reference"><a href="#cite_note-FOOTNOTELibickiAblonWebb201544-51"><span class="cite-bracket">[</span>51<span class="cite-bracket">]</span></a></sup> As of 2013, the <a href="Five_Eyes" title="Five Eyes">Five Eyes</a> (United States, United Kingdom, Canada, Australia, and New Zealand) captured the plurality of the market and other significant purchasers included Russia, India, Brazil, Malaysia, Singapore, North Korea, and Iran.<sup id="cite_ref-FOOTNOTEPerlroth2021145_52-0" class="reference"><a href="#cite_note-FOOTNOTEPerlroth2021145-52"><span class="cite-bracket">[</span>52<span class="cite-bracket">]</span></a></sup> Organized criminal groups also buy vulnerabilities, although they typically prefer <a href="Exploit_kit" title="Exploit kit">exploit kits</a>.<sup id="cite_ref-FOOTNOTELibickiAblonWebb201544,_46_53-0" class="reference"><a href="#cite_note-FOOTNOTELibickiAblonWebb201544,_46-53"><span class="cite-bracket">[</span>53<span class="cite-bracket">]</span></a></sup>
</p><p>Even vulnerabilities that are publicly known or patched are often exploitable for an extended period.<sup id="cite_ref-FOOTNOTEAblonBogart20178_54-0" class="reference"><a href="#cite_note-FOOTNOTEAblonBogart20178-54"><span class="cite-bracket">[</span>54<span class="cite-bracket">]</span></a></sup><sup id="cite_ref-FOOTNOTESoodEnbody201442_55-0" class="reference"><a href="#cite_note-FOOTNOTESoodEnbody201442-55"><span class="cite-bracket">[</span>55<span class="cite-bracket">]</span></a></sup> Security patches can take months to develop,<sup id="cite_ref-FOOTNOTEStrout202326_56-0" class="reference"><a href="#cite_note-FOOTNOTEStrout202326-56"><span class="cite-bracket">[</span>56<span class="cite-bracket">]</span></a></sup> or may never be developed.<sup id="cite_ref-FOOTNOTESoodEnbody201442_55-1" class="reference"><a href="#cite_note-FOOTNOTESoodEnbody201442-55"><span class="cite-bracket">[</span>55<span class="cite-bracket">]</span></a></sup> A patch can have negative effects on the functionality of software<sup id="cite_ref-FOOTNOTESoodEnbody201442_55-2" class="reference"><a href="#cite_note-FOOTNOTESoodEnbody201442-55"><span class="cite-bracket">[</span>55<span class="cite-bracket">]</span></a></sup> and users may need to <a href="Software_testing" title="Software testing">test</a> the patch to confirm functionality and compatibility.<sup id="cite_ref-FOOTNOTELibickiAblonWebb201550_57-0" class="reference"><a href="#cite_note-FOOTNOTELibickiAblonWebb201550-57"><span class="cite-bracket">[</span>57<span class="cite-bracket">]</span></a></sup> Larger organizations may fail to identify and patch all dependencies, while smaller enterprises and personal users may not install patches.<sup id="cite_ref-FOOTNOTESoodEnbody201442_55-3" class="reference"><a href="#cite_note-FOOTNOTESoodEnbody201442-55"><span class="cite-bracket">[</span>55<span class="cite-bracket">]</span></a></sup> Research suggests that risk of cyberattack increases if the vulnerability is made publicly known or a patch is released.<sup id="cite_ref-FOOTNOTELibickiAblonWebb201549–50_58-0" class="reference"><a href="#cite_note-FOOTNOTELibickiAblonWebb201549–50-58"><span class="cite-bracket">[</span>58<span class="cite-bracket">]</span></a></sup> Cybercriminals can <a href="Reverse_engineer" class="mw-redirect" title="Reverse engineer">reverse engineer</a> the patch to find the underlying vulnerability and develop exploits,<sup id="cite_ref-FOOTNOTEStrout202328_59-0" class="reference"><a href="#cite_note-FOOTNOTEStrout202328-59"><span class="cite-bracket">[</span>59<span class="cite-bracket">]</span></a></sup> often faster than users install the patch.<sup id="cite_ref-FOOTNOTELibickiAblonWebb201549–50_58-1" class="reference"><a href="#cite_note-FOOTNOTELibickiAblonWebb201549–50-58"><span class="cite-bracket">[</span>58<span class="cite-bracket">]</span></a></sup>
</p><p>Vulnerabilities become deprecated when the software or vulnerable versions fall out of use.<sup id="cite_ref-FOOTNOTEStrout202318_50-1" class="reference"><a href="#cite_note-FOOTNOTEStrout202318-50"><span class="cite-bracket">[</span>50<span class="cite-bracket">]</span></a></sup> This can take an extended period of time; in particular, industrial software may not be feasible to replace even if the manufacturer stops supporting it.<sup id="cite_ref-FOOTNOTEStrout202319_60-0" class="reference"><a href="#cite_note-FOOTNOTEStrout202319-60"><span class="cite-bracket">[</span>60<span class="cite-bracket">]</span></a></sup>
</p>
<div class="mw-heading mw-heading2"><h2 id="Assessment,_disclosure,_and_inventory">Assessment, disclosure, and inventory</h2></div>
<div class="mw-heading mw-heading3"><h3 id="Assessment">Assessment</h3></div>
<p>A commonly used scale for assessing the severity of vulnerabilities is the open-source specification <a href="Common_Vulnerability_Scoring_System" title="Common Vulnerability Scoring System">Common Vulnerability Scoring System</a> (CVSS). CVSS evaluates the possibility to exploit the vulnerability and compromise data confidentiality, availability, and integrity. It also considers how the vulnerability could be used and how complex an exploit would need to be. The amount of access needed for exploitation and whether it could take place without user interaction are also factored in to the overall score.<sup id="cite_ref-FOOTNOTEStrout20235–6_61-0" class="reference"><a href="#cite_note-FOOTNOTEStrout20235–6-61"><span class="cite-bracket">[</span>61<span class="cite-bracket">]</span></a></sup><sup id="cite_ref-FOOTNOTEHaberHibbert201873–74_62-0" class="reference"><a href="#cite_note-FOOTNOTEHaberHibbert201873–74-62"><span class="cite-bracket">[</span>62<span class="cite-bracket">]</span></a></sup>
</p>
<div class="mw-heading mw-heading3"><h3 id="Disclosure">Disclosure</h3></div>
<p>Someone who discovers a vulnerability may disclose it immediately (<a href="Full_disclosure_(computer_security)" title="Full disclosure (computer security)">full disclosure</a>) or wait until a patch has been developed (<a href="Coordinated_vulnerability_disclosure" title="Coordinated vulnerability disclosure">responsible disclosure</a>, or coordinated disclosure). The former approach is praised for its transparency, but the drawback is that the risk of attack is likely to be increased after disclosure with no patch available.<sup id="cite_ref-63" class="reference"><a href="#cite_note-63"><span class="cite-bracket">[</span>63<span class="cite-bracket">]</span></a></sup> Some vendors pay <a href="Bug_bounty" class="mw-redirect" title="Bug bounty">bug bounties</a> to those who report vulnerabilities to them.<sup id="cite_ref-FOOTNOTEO'Harrow201318_64-0" class="reference"><a href="#cite_note-FOOTNOTEO'Harrow201318-64"><span class="cite-bracket">[</span>64<span class="cite-bracket">]</span></a></sup><sup id="cite_ref-FOOTNOTELibickiAblonWebb201545_65-0" class="reference"><a href="#cite_note-FOOTNOTELibickiAblonWebb201545-65"><span class="cite-bracket">[</span>65<span class="cite-bracket">]</span></a></sup> Not all companies respond positively to disclosures, as they can cause legal liability and operational overhead.<sup id="cite_ref-FOOTNOTEStrout202336_66-0" class="reference"><a href="#cite_note-FOOTNOTEStrout202336-66"><span class="cite-bracket">[</span>66<span class="cite-bracket">]</span></a></sup> There is no law requiring disclosure of vulnerabilities.<sup id="cite_ref-FOOTNOTEHaberHibbert2018110_67-0" class="reference"><a href="#cite_note-FOOTNOTEHaberHibbert2018110-67"><span class="cite-bracket">[</span>67<span class="cite-bracket">]</span></a></sup> If a vulnerability is discovered by a third party that does not disclose to the vendor or the public, it is called a <a href="Zero-day_vulnerability" title="Zero-day vulnerability">zero-day vulnerability</a>, often considered the most dangerous type because fewer defenses exist.<sup id="cite_ref-FOOTNOTEStrout202322_68-0" class="reference"><a href="#cite_note-FOOTNOTEStrout202322-68"><span class="cite-bracket">[</span>68<span class="cite-bracket">]</span></a></sup>
</p>
<div class="mw-heading mw-heading3"><h3 id="Vulnerability_inventory">Vulnerability inventory</h3></div>
<p>The most commonly used vulnerability dataset is <a href="Common_Vulnerabilities_and_Exposures" title="Common Vulnerabilities and Exposures">Common Vulnerabilities and Exposures</a> (CVE), maintained by <a href="Mitre_Corporation" title="Mitre Corporation">Mitre Corporation</a>.<sup id="cite_ref-FOOTNOTEStrout20236_69-0" class="reference"><a href="#cite_note-FOOTNOTEStrout20236-69"><span class="cite-bracket">[</span>69<span class="cite-bracket">]</span></a></sup> As of November 2024, it has over 240,000 entries<sup id="cite_ref-Metrics_1-1" class="reference"><a href="#cite_note-Metrics-1"><span class="cite-bracket">[</span>1<span class="cite-bracket">]</span></a></sup> This information is shared into other databases, including the United States' <a href="National_Vulnerability_Database" title="National Vulnerability Database">National Vulnerability Database</a>,<sup id="cite_ref-FOOTNOTEStrout20236_69-1" class="reference"><a href="#cite_note-FOOTNOTEStrout20236-69"><span class="cite-bracket">[</span>69<span class="cite-bracket">]</span></a></sup> where each vulnerability is given a risk score using <a href="Common_Vulnerability_Scoring_System" title="Common Vulnerability Scoring System">Common Vulnerability Scoring System</a> (CVSS), <a href="Common_Platform_Enumeration" title="Common Platform Enumeration">Common Platform Enumeration</a> (CPE) scheme, and <a href="Common_Weakness_Enumeration" title="Common Weakness Enumeration">Common Weakness Enumeration</a>. CVE and other databases typically do not track vulnerabilities in <a href="Software_as_a_service" title="Software as a service">software as a service</a> products.<sup id="cite_ref-FOOTNOTEStrout20238_39-1" class="reference"><a href="#cite_note-FOOTNOTEStrout20238-39"><span class="cite-bracket">[</span>39<span class="cite-bracket">]</span></a></sup> Submitting a CVE is voluntary for companies that discovered a vulnerability.<sup id="cite_ref-FOOTNOTEHaberHibbert2018110_67-1" class="reference"><a href="#cite_note-FOOTNOTEHaberHibbert2018110-67"><span class="cite-bracket">[</span>67<span class="cite-bracket">]</span></a></sup>
</p>
<div class="mw-heading mw-heading2"><h2 id="Liability">Liability</h2></div>
<p>The software vendor is usually not legally liable for the cost if a vulnerability is used in an attack, which creates an incentive to make cheaper but less secure software.<sup id="cite_ref-FOOTNOTESloanWarner2019104–105_70-0" class="reference"><a href="#cite_note-FOOTNOTESloanWarner2019104–105-70"><span class="cite-bracket">[</span>70<span class="cite-bracket">]</span></a></sup> Some companies are covered by laws, such as <a href="Payment_Card_Industry_Security_Standards_Council" title="Payment Card Industry Security Standards Council">PCI</a>, <a href="HIPAA" class="mw-redirect" title="HIPAA">HIPAA</a>, and <a href="Sarbanes-Oxley" class="mw-redirect" title="Sarbanes-Oxley">Sarbanes-Oxley</a>, that place legal requirements on vulnerability management.<sup id="cite_ref-FOOTNOTEHaberHibbert2018111_71-0" class="reference"><a href="#cite_note-FOOTNOTEHaberHibbert2018111-71"><span class="cite-bracket">[</span>71<span class="cite-bracket">]</span></a></sup>
</p>
<div class="mw-heading mw-heading2"><h2 id="References">References</h2></div>
<style data-mw-deduplicate="TemplateStyles:r1239543626">
/* start https://en.wikipedia.org/ */


.mw-parser-output .reflist{margin-bottom:0.5em;list-style-type:decimal}@media screen{.mw-parser-output .reflist{font-size:90%}}.mw-parser-output .reflist .references{font-size:100%;margin-bottom:0;list-style-type:inherit}.mw-parser-output .reflist-columns-2{column-width:30em}.mw-parser-output .reflist-columns-3{column-width:25em}.mw-parser-output .reflist-columns{margin-top:0.3em}.mw-parser-output .reflist-columns ol{margin-top:0}.mw-parser-output .reflist-columns li{page-break-inside:avoid;break-inside:avoid-column}.mw-parser-output .reflist-upper-alpha{list-style-type:upper-alpha}.mw-parser-output .reflist-upper-roman{list-style-type:upper-roman}.mw-parser-output .reflist-lower-alpha{list-style-type:lower-alpha}.mw-parser-output .reflist-lower-greek{list-style-type:lower-greek}.mw-parser-output .reflist-lower-roman{list-style-type:lower-roman}


/* end https://en.wikipedia.org/ */
</style><div class="reflist reflist-columns references-column-width" style="column-width: 30em;">
<ol class="references">
<li id="cite_note-Metrics-1"><span class="mw-cite-backlink">^ <a href="#cite_ref-Metrics_1-0"><sup><i><b>a</b></i></sup></a> <a href="#cite_ref-Metrics_1-1"><sup><i><b>b</b></i></sup></a></span> <span class="reference-text"><style data-mw-deduplicate="TemplateStyles:r1238218222">
/* start https://en.wikipedia.org/ */


.mw-parser-output cite.citation{font-style:inherit;word-wrap:break-word}.mw-parser-output .citation q{quotes:"\"""\"""'""'"}.mw-parser-output .citation:target{background-color:rgba(0,127,255,0.133)}.mw-parser-output .id-lock-free.id-lock-free a{background:url("./mw/Lock-green.svg")right 0.1em center/9px no-repeat}.mw-parser-output .id-lock-limited.id-lock-limited a,.mw-parser-output .id-lock-registration.id-lock-registration a{background:url("./mw/Lock-gray-alt-2.svg")right 0.1em center/9px no-repeat}.mw-parser-output .id-lock-subscription.id-lock-subscription a{background:url("./mw/Lock-red-alt-2.svg")right 0.1em center/9px no-repeat}.mw-parser-output .cs1-ws-icon a{background:url("./mw/Wikisource-logo.svg")right 0.1em center/12px no-repeat}body:not(.skin-timeless):not(.skin-minerva) .mw-parser-output .id-lock-free a,body:not(.skin-timeless):not(.skin-minerva) .mw-parser-output .id-lock-limited a,body:not(.skin-timeless):not(.skin-minerva) .mw-parser-output .id-lock-registration a,body:not(.skin-timeless):not(.skin-minerva) .mw-parser-output .id-lock-subscription a,body:not(.skin-timeless):not(.skin-minerva) .mw-parser-output .cs1-ws-icon a{background-size:contain;padding:0 1em 0 0}.mw-parser-output .cs1-code{color:inherit;background:inherit;border:none;padding:inherit}.mw-parser-output .cs1-hidden-error{display:none;color:var(--color-error,#d33)}.mw-parser-output .cs1-visible-error{color:var(--color-error,#d33)}.mw-parser-output .cs1-maint{display:none;color:#085;margin-left:0.3em}.mw-parser-output .cs1-kern-left{padding-left:0.2em}.mw-parser-output .cs1-kern-right{padding-right:0.2em}.mw-parser-output .citation .mw-selflink{font-weight:inherit}@media screen{.mw-parser-output .cs1-format{font-size:95%}html.skin-theme-clientpref-night .mw-parser-output .cs1-maint{color:#18911f}}@media screen and (prefers-color-scheme:dark){html.skin-theme-clientpref-os .mw-parser-output .cs1-maint{color:#18911f}}


/* end https://en.wikipedia.org/ */
</style><cite class="citation web cs1"><a rel="nofollow" class="external text" href="https://www.cve.org/About/Metrics">"CVE - Program Metrics"</a>. 15 November 2024.</cite></span>
</li>
<li id="cite_note-FOOTNOTEAblonBogart20171-2"><span class="mw-cite-backlink"><b><a href="#cite_ref-FOOTNOTEAblonBogart20171_2-0">^</a></b></span> <span class="reference-text"><a href="#CITEREFAblonBogart2017">Ablon &amp; Bogart 2017</a>, p.&nbsp;1.</span>
</li>
<li id="cite_note-FOOTNOTEAblonBogart20172-3"><span class="mw-cite-backlink">^ <a href="#cite_ref-FOOTNOTEAblonBogart20172_3-0"><sup><i><b>a</b></i></sup></a> <a href="#cite_ref-FOOTNOTEAblonBogart20172_3-1"><sup><i><b>b</b></i></sup></a></span> <span class="reference-text"><a href="#CITEREFAblonBogart2017">Ablon &amp; Bogart 2017</a>, p.&nbsp;2.</span>
</li>
<li id="cite_note-FOOTNOTEDaswaniElbayadi202125-4"><span class="mw-cite-backlink"><b><a href="#cite_ref-FOOTNOTEDaswaniElbayadi202125_4-0">^</a></b></span> <span class="reference-text"><a href="#CITEREFDaswaniElbayadi2021">Daswani &amp; Elbayadi 2021</a>, p.&nbsp;25.</span>
</li>
<li id="cite_note-FOOTNOTESeaman202047–48-5"><span class="mw-cite-backlink"><b><a href="#cite_ref-FOOTNOTESeaman202047–48_5-0">^</a></b></span> <span class="reference-text"><a href="#CITEREFSeaman2020">Seaman 2020</a>, pp.&nbsp;47–48.</span>
</li>
<li id="cite_note-FOOTNOTEDaswaniElbayadi202126–27-6"><span class="mw-cite-backlink"><b><a href="#cite_ref-FOOTNOTEDaswaniElbayadi202126–27_6-0">^</a></b></span> <span class="reference-text"><a href="#CITEREFDaswaniElbayadi2021">Daswani &amp; Elbayadi 2021</a>, pp.&nbsp;26–27.</span>
</li>
<li id="cite_note-FOOTNOTEHaberHibbert20185–6-7"><span class="mw-cite-backlink"><b><a href="#cite_ref-FOOTNOTEHaberHibbert20185–6_7-0">^</a></b></span> <span class="reference-text"><a href="#CITEREFHaberHibbert2018">Haber &amp; Hibbert 2018</a>, pp.&nbsp;5–6.</span>
</li>
<li id="cite_note-FOOTNOTEHaberHibbert20186-8"><span class="mw-cite-backlink"><b><a href="#cite_ref-FOOTNOTEHaberHibbert20186_8-0">^</a></b></span> <span class="reference-text"><a href="#CITEREFHaberHibbert2018">Haber &amp; Hibbert 2018</a>, p.&nbsp;6.</span>
</li>
<li id="cite_note-FOOTNOTEHaberHibbert201810-9"><span class="mw-cite-backlink"><b><a href="#cite_ref-FOOTNOTEHaberHibbert201810_9-0">^</a></b></span> <span class="reference-text"><a href="#CITEREFHaberHibbert2018">Haber &amp; Hibbert 2018</a>, p.&nbsp;10.</span>
</li>
<li id="cite_note-FOOTNOTEHaberHibbert201813–14-10"><span class="mw-cite-backlink"><b><a href="#cite_ref-FOOTNOTEHaberHibbert201813–14_10-0">^</a></b></span> <span class="reference-text"><a href="#CITEREFHaberHibbert2018">Haber &amp; Hibbert 2018</a>, pp.&nbsp;13–14.</span>
</li>
<li id="cite_note-Vacca23-11"><span class="mw-cite-backlink"><b><a href="#cite_ref-Vacca23_11-0">^</a></b></span> <span class="reference-text"><cite id="CITEREFKakareka2009" class="citation book cs1">Kakareka, Almantas (2009). "23". In Vacca, John (ed.). <i>Computer and Information Security Handbook</i>. Morgan Kaufmann Publications. Elsevier Inc. p.&nbsp;393. <a href="ISBN_(identifier)" class="mw-redirect" title="ISBN (identifier)">ISBN</a>&nbsp;<bdi>978-0-12-374354-1</bdi>.</cite></span>
</li>
<li id="cite_note-12"><span class="mw-cite-backlink"><b><a href="#cite_ref-12">^</a></b></span> <span class="reference-text"><cite id="CITEREFKrsul1997" class="citation book cs1">Krsul, Ivan (April 15, 1997). <i>Technical Report CSD-TR-97-026</i>. The COAST Laboratory Department of Computer Sciences, Purdue University. <a href="CiteSeerX_(identifier)" class="mw-redirect" title="CiteSeerX (identifier)">CiteSeerX</a>&nbsp;<span class="id-lock-free" title="Freely accessible"><a rel="nofollow" class="external text" href="https://citeseerx.ist.psu.edu/viewdoc/summary?doi=10.1.1.26.5435">10.1.1.26.5435</a></span>.</cite></span>
</li>
<li id="cite_note-FOOTNOTELinkovKott20192-13"><span class="mw-cite-backlink"><b><a href="#cite_ref-FOOTNOTELinkovKott20192_13-0">^</a></b></span> <span class="reference-text"><a href="#CITEREFLinkovKott2019">Linkov &amp; Kott 2019</a>, p.&nbsp;2.</span>
</li>
<li id="cite_note-FOOTNOTEHaberHibbert2018155-14"><span class="mw-cite-backlink"><b><a href="#cite_ref-FOOTNOTEHaberHibbert2018155_14-0">^</a></b></span> <span class="reference-text"><a href="#CITEREFHaberHibbert2018">Haber &amp; Hibbert 2018</a>, p.&nbsp;155.</span>
</li>
<li id="cite_note-FOOTNOTEStrout202317-15"><span class="mw-cite-backlink"><b><a href="#cite_ref-FOOTNOTEStrout202317_15-0">^</a></b></span> <span class="reference-text"><a href="#CITEREFStrout2023">Strout 2023</a>, p.&nbsp;17.</span>
</li>
<li id="cite_note-FOOTNOTEHaberHibbert2018143-16"><span class="mw-cite-backlink"><b><a href="#cite_ref-FOOTNOTEHaberHibbert2018143_16-0">^</a></b></span> <span class="reference-text"><a href="#CITEREFHaberHibbert2018">Haber &amp; Hibbert 2018</a>, p.&nbsp;143.</span>
</li>
<li id="cite_note-FOOTNOTEHaberHibbert2018141-17"><span class="mw-cite-backlink"><b><a href="#cite_ref-FOOTNOTEHaberHibbert2018141_17-0">^</a></b></span> <span class="reference-text"><a href="#CITEREFHaberHibbert2018">Haber &amp; Hibbert 2018</a>, p.&nbsp;141.</span>
</li>
<li id="cite_note-FOOTNOTEHaberHibbert2018142-18"><span class="mw-cite-backlink"><b><a href="#cite_ref-FOOTNOTEHaberHibbert2018142_18-0">^</a></b></span> <span class="reference-text"><a href="#CITEREFHaberHibbert2018">Haber &amp; Hibbert 2018</a>, p.&nbsp;142.</span>
</li>
<li id="cite_note-FOOTNOTEHaberHibbert2018135–137-19"><span class="mw-cite-backlink"><b><a href="#cite_ref-FOOTNOTEHaberHibbert2018135–137_19-0">^</a></b></span> <span class="reference-text"><a href="#CITEREFHaberHibbert2018">Haber &amp; Hibbert 2018</a>, pp.&nbsp;135–137.</span>
</li>
<li id="cite_note-FOOTNOTEGargBaliyan202317–18-20"><span class="mw-cite-backlink"><b><a href="#cite_ref-FOOTNOTEGargBaliyan202317–18_20-0">^</a></b></span> <span class="reference-text"><a href="#CITEREFGargBaliyan2023">Garg &amp; Baliyan 2023</a>, pp.&nbsp;17–18.</span>
</li>
<li id="cite_note-FOOTNOTEGargBaliyan202317-21"><span class="mw-cite-backlink">^ <a href="#cite_ref-FOOTNOTEGargBaliyan202317_21-0"><sup><i><b>a</b></i></sup></a> <a href="#cite_ref-FOOTNOTEGargBaliyan202317_21-1"><sup><i><b>b</b></i></sup></a></span> <span class="reference-text"><a href="#CITEREFGargBaliyan2023">Garg &amp; Baliyan 2023</a>, p.&nbsp;17.</span>
</li>
<li id="cite_note-FOOTNOTEGargBaliyan202318-22"><span class="mw-cite-backlink">^ <a href="#cite_ref-FOOTNOTEGargBaliyan202318_22-0"><sup><i><b>a</b></i></sup></a> <a href="#cite_ref-FOOTNOTEGargBaliyan202318_22-1"><sup><i><b>b</b></i></sup></a> <a href="#cite_ref-FOOTNOTEGargBaliyan202318_22-2"><sup><i><b>c</b></i></sup></a></span> <span class="reference-text"><a href="#CITEREFGargBaliyan2023">Garg &amp; Baliyan 2023</a>, p.&nbsp;18.</span>
</li>
<li id="cite_note-FOOTNOTESalmani20181-23"><span class="mw-cite-backlink"><b><a href="#cite_ref-FOOTNOTESalmani20181_23-0">^</a></b></span> <span class="reference-text"><a href="#CITEREFSalmani2018">Salmani 2018</a>, p.&nbsp;1.</span>
</li>
<li id="cite_note-FOOTNOTESalmani201811-24"><span class="mw-cite-backlink"><b><a href="#cite_ref-FOOTNOTESalmani201811_24-0">^</a></b></span> <span class="reference-text"><a href="#CITEREFSalmani2018">Salmani 2018</a>, p.&nbsp;11.</span>
</li>
<li id="cite_note-FOOTNOTEGargBaliyan202320–25-25"><span class="mw-cite-backlink"><b><a href="#cite_ref-FOOTNOTEGargBaliyan202320–25_25-0">^</a></b></span> <span class="reference-text"><a href="#CITEREFGargBaliyan2023">Garg &amp; Baliyan 2023</a>, pp.&nbsp;20–25.</span>
</li>
<li id="cite_note-FOOTNOTESharp2024271-26"><span class="mw-cite-backlink"><b><a href="#cite_ref-FOOTNOTESharp2024271_26-0">^</a></b></span> <span class="reference-text"><a href="#CITEREFSharp2024">Sharp 2024</a>, p.&nbsp;271.</span>
</li>
<li id="cite_note-FOOTNOTEStrout202315-27"><span class="mw-cite-backlink">^ <a href="#cite_ref-FOOTNOTEStrout202315_27-0"><sup><i><b>a</b></i></sup></a> <a href="#cite_ref-FOOTNOTEStrout202315_27-1"><sup><i><b>b</b></i></sup></a> <a href="#cite_ref-FOOTNOTEStrout202315_27-2"><sup><i><b>c</b></i></sup></a></span> <span class="reference-text"><a href="#CITEREFStrout2023">Strout 2023</a>, p.&nbsp;15.</span>
</li>
<li id="cite_note-FOOTNOTEStrout202313-28"><span class="mw-cite-backlink">^ <a href="#cite_ref-FOOTNOTEStrout202313_28-0"><sup><i><b>a</b></i></sup></a> <a href="#cite_ref-FOOTNOTEStrout202313_28-1"><sup><i><b>b</b></i></sup></a> <a href="#cite_ref-FOOTNOTEStrout202313_28-2"><sup><i><b>c</b></i></sup></a> <a href="#cite_ref-FOOTNOTEStrout202313_28-3"><sup><i><b>d</b></i></sup></a></span> <span class="reference-text"><a href="#CITEREFStrout2023">Strout 2023</a>, p.&nbsp;13.</span>
</li>
<li id="cite_note-FOOTNOTEHaberHibbert2018129-29"><span class="mw-cite-backlink"><b><a href="#cite_ref-FOOTNOTEHaberHibbert2018129_29-0">^</a></b></span> <span class="reference-text"><a href="#CITEREFHaberHibbert2018">Haber &amp; Hibbert 2018</a>, p.&nbsp;129.</span>
</li>
<li id="cite_note-FOOTNOTEStrout202314-30"><span class="mw-cite-backlink">^ <a href="#cite_ref-FOOTNOTEStrout202314_30-0"><sup><i><b>a</b></i></sup></a> <a href="#cite_ref-FOOTNOTEStrout202314_30-1"><sup><i><b>b</b></i></sup></a> <a href="#cite_ref-FOOTNOTEStrout202314_30-2"><sup><i><b>c</b></i></sup></a> <a href="#cite_ref-FOOTNOTEStrout202314_30-3"><sup><i><b>d</b></i></sup></a> <a href="#cite_ref-FOOTNOTEStrout202314_30-4"><sup><i><b>e</b></i></sup></a></span> <span class="reference-text"><a href="#CITEREFStrout2023">Strout 2023</a>, p.&nbsp;14.</span>
</li>
<li id="cite_note-FOOTNOTEStrout202314–15-31"><span class="mw-cite-backlink"><b><a href="#cite_ref-FOOTNOTEStrout202314–15_31-0">^</a></b></span> <span class="reference-text"><a href="#CITEREFStrout2023">Strout 2023</a>, pp.&nbsp;14–15.</span>
</li>
<li id="cite_note-FOOTNOTEAgrafiotis_''et_al.''20182-32"><span class="mw-cite-backlink"><b><a href="#cite_ref-FOOTNOTEAgrafiotis_''et_al.''20182_32-0">^</a></b></span> <span class="reference-text"><a href="#CITEREFAgrafiotis_et_al.2018">Agrafiotis <i>et al.</i> 2018</a>, p.&nbsp;2.</span>
</li>
<li id="cite_note-FOOTNOTEHaberHibbert201897–98-33"><span class="mw-cite-backlink">^ <a href="#cite_ref-FOOTNOTEHaberHibbert201897–98_33-0"><sup><i><b>a</b></i></sup></a> <a href="#cite_ref-FOOTNOTEHaberHibbert201897–98_33-1"><sup><i><b>b</b></i></sup></a></span> <span class="reference-text"><a href="#CITEREFHaberHibbert2018">Haber &amp; Hibbert 2018</a>, pp.&nbsp;97–98.</span>
</li>
<li id="cite_note-FOOTNOTETjoa_''et_al.''202463-34"><span class="mw-cite-backlink"><b><a href="#cite_ref-FOOTNOTETjoa_''et_al.''202463_34-0">^</a></b></span> <span class="reference-text"><a href="#CITEREFTjoa_et_al.2024">Tjoa <i>et al.</i> 2024</a>, p.&nbsp;63.</span>
</li>
<li id="cite_note-FOOTNOTETjoa_''et_al.''202468,_70-35"><span class="mw-cite-backlink"><b><a href="#cite_ref-FOOTNOTETjoa_''et_al.''202468,_70_35-0">^</a></b></span> <span class="reference-text"><a href="#CITEREFTjoa_et_al.2024">Tjoa <i>et al.</i> 2024</a>, pp.&nbsp;68, 70.</span>
</li>
<li id="cite_note-FOOTNOTEMagnusson202034-36"><span class="mw-cite-backlink"><b><a href="#cite_ref-FOOTNOTEMagnusson202034_36-0">^</a></b></span> <span class="reference-text"><a href="#CITEREFMagnusson2020">Magnusson 2020</a>, p.&nbsp;34.</span>
</li>
<li id="cite_note-FOOTNOTEHaberHibbert2018166–167-37"><span class="mw-cite-backlink"><b><a href="#cite_ref-FOOTNOTEHaberHibbert2018166–167_37-0">^</a></b></span> <span class="reference-text"><a href="#CITEREFHaberHibbert2018">Haber &amp; Hibbert 2018</a>, pp.&nbsp;166–167.</span>
</li>
<li id="cite_note-FOOTNOTEHaberHibbert201811-38"><span class="mw-cite-backlink">^ <a href="#cite_ref-FOOTNOTEHaberHibbert201811_38-0"><sup><i><b>a</b></i></sup></a> <a href="#cite_ref-FOOTNOTEHaberHibbert201811_38-1"><sup><i><b>b</b></i></sup></a> <a href="#cite_ref-FOOTNOTEHaberHibbert201811_38-2"><sup><i><b>c</b></i></sup></a></span> <span class="reference-text"><a href="#CITEREFHaberHibbert2018">Haber &amp; Hibbert 2018</a>, p.&nbsp;11.</span>
</li>
<li id="cite_note-FOOTNOTEStrout20238-39"><span class="mw-cite-backlink">^ <a href="#cite_ref-FOOTNOTEStrout20238_39-0"><sup><i><b>a</b></i></sup></a> <a href="#cite_ref-FOOTNOTEStrout20238_39-1"><sup><i><b>b</b></i></sup></a></span> <span class="reference-text"><a href="#CITEREFStrout2023">Strout 2023</a>, p.&nbsp;8.</span>
</li>
<li id="cite_note-FOOTNOTEHaberHibbert201812–13-40"><span class="mw-cite-backlink"><b><a href="#cite_ref-FOOTNOTEHaberHibbert201812–13_40-0">^</a></b></span> <span class="reference-text"><a href="#CITEREFHaberHibbert2018">Haber &amp; Hibbert 2018</a>, pp.&nbsp;12–13.</span>
</li>
<li id="cite_note-FOOTNOTEHaberHibbert201884-41"><span class="mw-cite-backlink">^ <a href="#cite_ref-FOOTNOTEHaberHibbert201884_41-0"><sup><i><b>a</b></i></sup></a> <a href="#cite_ref-FOOTNOTEHaberHibbert201884_41-1"><sup><i><b>b</b></i></sup></a></span> <span class="reference-text"><a href="#CITEREFHaberHibbert2018">Haber &amp; Hibbert 2018</a>, p.&nbsp;84.</span>
</li>
<li id="cite_note-FOOTNOTEHaberHibbert201885-42"><span class="mw-cite-backlink"><b><a href="#cite_ref-FOOTNOTEHaberHibbert201885_42-0">^</a></b></span> <span class="reference-text"><a href="#CITEREFHaberHibbert2018">Haber &amp; Hibbert 2018</a>, p.&nbsp;85.</span>
</li>
<li id="cite_note-FOOTNOTEHaberHibbert201884–85-43"><span class="mw-cite-backlink"><b><a href="#cite_ref-FOOTNOTEHaberHibbert201884–85_43-0">^</a></b></span> <span class="reference-text"><a href="#CITEREFHaberHibbert2018">Haber &amp; Hibbert 2018</a>, pp.&nbsp;84–85.</span>
</li>
<li id="cite_note-FOOTNOTEMagnusson202032-44"><span class="mw-cite-backlink"><b><a href="#cite_ref-FOOTNOTEMagnusson202032_44-0">^</a></b></span> <span class="reference-text"><a href="#CITEREFMagnusson2020">Magnusson 2020</a>, p.&nbsp;32.</span>
</li>
<li id="cite_note-FOOTNOTEMagnusson202033-45"><span class="mw-cite-backlink"><b><a href="#cite_ref-FOOTNOTEMagnusson202033_45-0">^</a></b></span> <span class="reference-text"><a href="#CITEREFMagnusson2020">Magnusson 2020</a>, p.&nbsp;33.</span>
</li>
<li id="cite_note-FOOTNOTEHaberHibbert201893-46"><span class="mw-cite-backlink"><b><a href="#cite_ref-FOOTNOTEHaberHibbert201893_46-0">^</a></b></span> <span class="reference-text"><a href="#CITEREFHaberHibbert2018">Haber &amp; Hibbert 2018</a>, p.&nbsp;93.</span>
</li>
<li id="cite_note-FOOTNOTEHaberHibbert201896-47"><span class="mw-cite-backlink">^ <a href="#cite_ref-FOOTNOTEHaberHibbert201896_47-0"><sup><i><b>a</b></i></sup></a> <a href="#cite_ref-FOOTNOTEHaberHibbert201896_47-1"><sup><i><b>b</b></i></sup></a></span> <span class="reference-text"><a href="#CITEREFHaberHibbert2018">Haber &amp; Hibbert 2018</a>, p.&nbsp;96.</span>
</li>
<li id="cite_note-FOOTNOTEHaberHibbert201894-48"><span class="mw-cite-backlink"><b><a href="#cite_ref-FOOTNOTEHaberHibbert201894_48-0">^</a></b></span> <span class="reference-text"><a href="#CITEREFHaberHibbert2018">Haber &amp; Hibbert 2018</a>, p.&nbsp;94.</span>
</li>
<li id="cite_note-FOOTNOTEStrout202316-49"><span class="mw-cite-backlink"><b><a href="#cite_ref-FOOTNOTEStrout202316_49-0">^</a></b></span> <span class="reference-text"><a href="#CITEREFStrout2023">Strout 2023</a>, p.&nbsp;16.</span>
</li>
<li id="cite_note-FOOTNOTEStrout202318-50"><span class="mw-cite-backlink">^ <a href="#cite_ref-FOOTNOTEStrout202318_50-0"><sup><i><b>a</b></i></sup></a> <a href="#cite_ref-FOOTNOTEStrout202318_50-1"><sup><i><b>b</b></i></sup></a></span> <span class="reference-text"><a href="#CITEREFStrout2023">Strout 2023</a>, p.&nbsp;18.</span>
</li>
<li id="cite_note-FOOTNOTELibickiAblonWebb201544-51"><span class="mw-cite-backlink"><b><a href="#cite_ref-FOOTNOTELibickiAblonWebb201544_51-0">^</a></b></span> <span class="reference-text"><a href="#CITEREFLibickiAblonWebb2015">Libicki, Ablon &amp; Webb 2015</a>, p.&nbsp;44.</span>
</li>
<li id="cite_note-FOOTNOTEPerlroth2021145-52"><span class="mw-cite-backlink"><b><a href="#cite_ref-FOOTNOTEPerlroth2021145_52-0">^</a></b></span> <span class="reference-text"><a href="#CITEREFPerlroth2021">Perlroth 2021</a>, p.&nbsp;145.</span>
</li>
<li id="cite_note-FOOTNOTELibickiAblonWebb201544,_46-53"><span class="mw-cite-backlink"><b><a href="#cite_ref-FOOTNOTELibickiAblonWebb201544,_46_53-0">^</a></b></span> <span class="reference-text"><a href="#CITEREFLibickiAblonWebb2015">Libicki, Ablon &amp; Webb 2015</a>, pp.&nbsp;44, 46.</span>
</li>
<li id="cite_note-FOOTNOTEAblonBogart20178-54"><span class="mw-cite-backlink"><b><a href="#cite_ref-FOOTNOTEAblonBogart20178_54-0">^</a></b></span> <span class="reference-text"><a href="#CITEREFAblonBogart2017">Ablon &amp; Bogart 2017</a>, p.&nbsp;8.</span>
</li>
<li id="cite_note-FOOTNOTESoodEnbody201442-55"><span class="mw-cite-backlink">^ <a href="#cite_ref-FOOTNOTESoodEnbody201442_55-0"><sup><i><b>a</b></i></sup></a> <a href="#cite_ref-FOOTNOTESoodEnbody201442_55-1"><sup><i><b>b</b></i></sup></a> <a href="#cite_ref-FOOTNOTESoodEnbody201442_55-2"><sup><i><b>c</b></i></sup></a> <a href="#cite_ref-FOOTNOTESoodEnbody201442_55-3"><sup><i><b>d</b></i></sup></a></span> <span class="reference-text"><a href="#CITEREFSoodEnbody2014">Sood &amp; Enbody 2014</a>, p.&nbsp;42.</span>
</li>
<li id="cite_note-FOOTNOTEStrout202326-56"><span class="mw-cite-backlink"><b><a href="#cite_ref-FOOTNOTEStrout202326_56-0">^</a></b></span> <span class="reference-text"><a href="#CITEREFStrout2023">Strout 2023</a>, p.&nbsp;26.</span>
</li>
<li id="cite_note-FOOTNOTELibickiAblonWebb201550-57"><span class="mw-cite-backlink"><b><a href="#cite_ref-FOOTNOTELibickiAblonWebb201550_57-0">^</a></b></span> <span class="reference-text"><a href="#CITEREFLibickiAblonWebb2015">Libicki, Ablon &amp; Webb 2015</a>, p.&nbsp;50.</span>
</li>
<li id="cite_note-FOOTNOTELibickiAblonWebb201549–50-58"><span class="mw-cite-backlink">^ <a href="#cite_ref-FOOTNOTELibickiAblonWebb201549–50_58-0"><sup><i><b>a</b></i></sup></a> <a href="#cite_ref-FOOTNOTELibickiAblonWebb201549–50_58-1"><sup><i><b>b</b></i></sup></a></span> <span class="reference-text"><a href="#CITEREFLibickiAblonWebb2015">Libicki, Ablon &amp; Webb 2015</a>, pp.&nbsp;49–50.</span>
</li>
<li id="cite_note-FOOTNOTEStrout202328-59"><span class="mw-cite-backlink"><b><a href="#cite_ref-FOOTNOTEStrout202328_59-0">^</a></b></span> <span class="reference-text"><a href="#CITEREFStrout2023">Strout 2023</a>, p.&nbsp;28.</span>
</li>
<li id="cite_note-FOOTNOTEStrout202319-60"><span class="mw-cite-backlink"><b><a href="#cite_ref-FOOTNOTEStrout202319_60-0">^</a></b></span> <span class="reference-text"><a href="#CITEREFStrout2023">Strout 2023</a>, p.&nbsp;19.</span>
</li>
<li id="cite_note-FOOTNOTEStrout20235–6-61"><span class="mw-cite-backlink"><b><a href="#cite_ref-FOOTNOTEStrout20235–6_61-0">^</a></b></span> <span class="reference-text"><a href="#CITEREFStrout2023">Strout 2023</a>, pp.&nbsp;5–6.</span>
</li>
<li id="cite_note-FOOTNOTEHaberHibbert201873–74-62"><span class="mw-cite-backlink"><b><a href="#cite_ref-FOOTNOTEHaberHibbert201873–74_62-0">^</a></b></span> <span class="reference-text"><a href="#CITEREFHaberHibbert2018">Haber &amp; Hibbert 2018</a>, pp.&nbsp;73–74.</span>
</li>
<li id="cite_note-63"><span class="mw-cite-backlink"><b><a href="#cite_ref-63">^</a></b></span> <span class="reference-text"><cite class="citation web cs1"><a rel="nofollow" class="external text" href="https://ethics.acm.org/integrity-project/ask-an-ethicist/ask-an-ethicist-vulnerability-disclosure/">"Ask an Ethicist: Vulnerability Disclosure"</a>. <i><a href="Association_for_Computing_Machinery" title="Association for Computing Machinery">Association for Computing Machinery</a>'s Committee on Professional Ethics</i>. 17 July 2018<span class="reference-accessdate">. Retrieved <span class="nowrap">3 May</span> 2024</span>.</cite></span>
</li>
<li id="cite_note-FOOTNOTEO'Harrow201318-64"><span class="mw-cite-backlink"><b><a href="#cite_ref-FOOTNOTEO'Harrow201318_64-0">^</a></b></span> <span class="reference-text"><a href="#CITEREFO'Harrow2013">O'Harrow 2013</a>, p.&nbsp;18.</span>
</li>
<li id="cite_note-FOOTNOTELibickiAblonWebb201545-65"><span class="mw-cite-backlink"><b><a href="#cite_ref-FOOTNOTELibickiAblonWebb201545_65-0">^</a></b></span> <span class="reference-text"><a href="#CITEREFLibickiAblonWebb2015">Libicki, Ablon &amp; Webb 2015</a>, p.&nbsp;45.</span>
</li>
<li id="cite_note-FOOTNOTEStrout202336-66"><span class="mw-cite-backlink"><b><a href="#cite_ref-FOOTNOTEStrout202336_66-0">^</a></b></span> <span class="reference-text"><a href="#CITEREFStrout2023">Strout 2023</a>, p.&nbsp;36.</span>
</li>
<li id="cite_note-FOOTNOTEHaberHibbert2018110-67"><span class="mw-cite-backlink">^ <a href="#cite_ref-FOOTNOTEHaberHibbert2018110_67-0"><sup><i><b>a</b></i></sup></a> <a href="#cite_ref-FOOTNOTEHaberHibbert2018110_67-1"><sup><i><b>b</b></i></sup></a></span> <span class="reference-text"><a href="#CITEREFHaberHibbert2018">Haber &amp; Hibbert 2018</a>, p.&nbsp;110.</span>
</li>
<li id="cite_note-FOOTNOTEStrout202322-68"><span class="mw-cite-backlink"><b><a href="#cite_ref-FOOTNOTEStrout202322_68-0">^</a></b></span> <span class="reference-text"><a href="#CITEREFStrout2023">Strout 2023</a>, p.&nbsp;22.</span>
</li>
<li id="cite_note-FOOTNOTEStrout20236-69"><span class="mw-cite-backlink">^ <a href="#cite_ref-FOOTNOTEStrout20236_69-0"><sup><i><b>a</b></i></sup></a> <a href="#cite_ref-FOOTNOTEStrout20236_69-1"><sup><i><b>b</b></i></sup></a></span> <span class="reference-text"><a href="#CITEREFStrout2023">Strout 2023</a>, p.&nbsp;6.</span>
</li>
<li id="cite_note-FOOTNOTESloanWarner2019104–105-70"><span class="mw-cite-backlink"><b><a href="#cite_ref-FOOTNOTESloanWarner2019104–105_70-0">^</a></b></span> <span class="reference-text"><a href="#CITEREFSloanWarner2019">Sloan &amp; Warner 2019</a>, pp.&nbsp;104–105.</span>
</li>
<li id="cite_note-FOOTNOTEHaberHibbert2018111-71"><span class="mw-cite-backlink"><b><a href="#cite_ref-FOOTNOTEHaberHibbert2018111_71-0">^</a></b></span> <span class="reference-text"><a href="#CITEREFHaberHibbert2018">Haber &amp; Hibbert 2018</a>, p.&nbsp;111.</span>
</li>
</ol></div>
<div class="mw-heading mw-heading2"><h2 id="Sources">Sources</h2></div>
<style data-mw-deduplicate="TemplateStyles:r1239549316">
/* start https://en.wikipedia.org/ */


.mw-parser-output .refbegin{margin-bottom:0.5em}.mw-parser-output .refbegin-hanging-indents>ul{margin-left:0}.mw-parser-output .refbegin-hanging-indents>ul>li{margin-left:0;padding-left:3.2em;text-indent:-3.2em}.mw-parser-output .refbegin-hanging-indents ul,.mw-parser-output .refbegin-hanging-indents ul li{list-style:none}@media(max-width:720px){.mw-parser-output .refbegin-hanging-indents>ul>li{padding-left:1.6em;text-indent:-1.6em}}.mw-parser-output .refbegin-columns{margin-top:0.3em}.mw-parser-output .refbegin-columns ul{margin-top:0}.mw-parser-output .refbegin-columns li{page-break-inside:avoid;break-inside:avoid-column}@media screen{.mw-parser-output .refbegin{font-size:90%}}


/* end https://en.wikipedia.org/ */
</style><div class="refbegin refbegin-hanging-indents" style="">
<ul><li><cite id="CITEREFAblonBogart2017" class="citation book cs1">Ablon, Lillian; Bogart, Andy (2017). <a rel="nofollow" class="external text" href="https://www.rand.org/content/dam/rand/pubs/research_reports/RR1700/RR1751/RAND_RR1751.pdf"><i>Zero Days, Thousands of Nights: The Life and Times of Zero-Day Vulnerabilities and Their Exploits</i></a> <span class="cs1-format">(PDF)</span>. Rand Corporation. <a href="ISBN_(identifier)" class="mw-redirect" title="ISBN (identifier)">ISBN</a>&nbsp;<bdi>978-0-8330-9761-3</bdi>.</cite></li>
<li><cite id="CITEREFAgrafiotis_et_al.2018" class="citation journal cs1">Agrafiotis, Ioannis; Nurse, Jason R C; Goldsmith, Michael; Creese, Sadie; Upton, David (2018). <a rel="nofollow" class="external text" href="https://doi.org/10.1093%2Fcybsec%2Ftyy006">"A taxonomy of cyber-harms: Defining the impacts of cyber-attacks and understanding how they propagate"</a>. <i>Journal of Cybersecurity</i>. <b>4</b> (1). <a href="Doi_(identifier)" class="mw-redirect" title="Doi (identifier)">doi</a>:<span class="id-lock-free" title="Freely accessible"><a rel="nofollow" class="external text" href="https://doi.org/10.1093%2Fcybsec%2Ftyy006">10.1093/cybsec/tyy006</a></span>. <a href="ISSN_(identifier)" class="mw-redirect" title="ISSN (identifier)">ISSN</a>&nbsp;<a rel="nofollow" class="external text" href="https://search.worldcat.org/issn/2057-2085">2057-2085</a>.</cite></li>
<li><cite id="CITEREFDaswaniElbayadi2021" class="citation book cs1"><a href="Neil_Daswani" title="Neil Daswani">Daswani, Neil</a>; Elbayadi, Moudy (2021). <i>Big Breaches: Cybersecurity Lessons for Everyone</i>. Apress. <a href="ISBN_(identifier)" class="mw-redirect" title="ISBN (identifier)">ISBN</a>&nbsp;<bdi>978-1-4842-6654-0</bdi>.</cite></li>
<li><cite id="CITEREFGargBaliyan2023" class="citation book cs1">Garg, Shivi; Baliyan, Niyati (2023). <i>Mobile OS Vulnerabilities: Quantitative and Qualitative Analysis</i>. CRC Press. <a href="ISBN_(identifier)" class="mw-redirect" title="ISBN (identifier)">ISBN</a>&nbsp;<bdi>978-1-000-92451-0</bdi>.</cite></li>
<li><cite id="CITEREFHaberHibbert2018" class="citation book cs1">Haber, Morey J.; Hibbert, Brad (2018). <i>Asset Attack Vectors: Building Effective Vulnerability Management Strategies to Protect Organizations</i>. Apress. <a href="ISBN_(identifier)" class="mw-redirect" title="ISBN (identifier)">ISBN</a>&nbsp;<bdi>978-1-4842-3627-7</bdi>.</cite></li>
<li><cite id="CITEREFLibickiAblonWebb2015" class="citation book cs1">Libicki, Martin C.; Ablon, Lillian; Webb, Tim (2015). <a rel="nofollow" class="external text" href="https://www.rand.org/content/dam/rand/pubs/research_reports/RR1000/RR1024/RAND_RR1024.pdf"><i>The Defender's Dilemma: Charting a Course Toward Cybersecurity</i></a> <span class="cs1-format">(PDF)</span>. Rand Corporation. <a href="ISBN_(identifier)" class="mw-redirect" title="ISBN (identifier)">ISBN</a>&nbsp;<bdi>978-0-8330-8911-3</bdi>.</cite></li>
<li><cite id="CITEREFLinkovKott2019" class="citation book cs1">Linkov, Igor; Kott, Alexander (2019). "Fundamental Concepts of Cyber Resilience: Introduction and Overview". <i>Cyber Resilience of Systems and Networks</i>. Springer International Publishing. pp.&nbsp;<span class="nowrap">1–</span>25. <a href="ISBN_(identifier)" class="mw-redirect" title="ISBN (identifier)">ISBN</a>&nbsp;<bdi>978-3-319-77492-3</bdi>.</cite></li>
<li><cite id="CITEREFMagnusson2020" class="citation book cs1">Magnusson, Andrew (2020). <i>Practical Vulnerability Management: A Strategic Approach to Managing Cyber Risk</i>. No Starch Press. <a href="ISBN_(identifier)" class="mw-redirect" title="ISBN (identifier)">ISBN</a>&nbsp;<bdi>978-1-59327-989-9</bdi>.</cite></li>
<li><cite id="CITEREFO'Harrow2013" class="citation book cs1">O'Harrow, Robert (2013). <i>Zero Day: The Threat In Cyberspace</i>. Diversion Books. <a href="ISBN_(identifier)" class="mw-redirect" title="ISBN (identifier)">ISBN</a>&nbsp;<bdi>978-1-938120-76-3</bdi>.</cite></li>
<li><cite id="CITEREFPerlroth2021" class="citation book cs1">Perlroth, Nicole (2021). <i>This Is How They Tell Me the World Ends: Winner of the FT &amp; McKinsey Business Book of the Year Award 2021</i>. Bloomsbury Publishing. <a href="ISBN_(identifier)" class="mw-redirect" title="ISBN (identifier)">ISBN</a>&nbsp;<bdi>978-1-5266-2983-8</bdi>.</cite></li>
<li><cite id="CITEREFSalmani2018" class="citation book cs1">Salmani, Hassan (2018). <i>Trusted Digital Circuits: Hardware Trojan Vulnerabilities, Prevention and Detection</i>. Springer. <a href="ISBN_(identifier)" class="mw-redirect" title="ISBN (identifier)">ISBN</a>&nbsp;<bdi>978-3-319-79081-7</bdi>.</cite></li>
<li><cite id="CITEREFSeaman2020" class="citation book cs1">Seaman, Jim (2020). <i>PCI DSS: An Integrated Data Security Standard Guide</i>. Apress. <a href="ISBN_(identifier)" class="mw-redirect" title="ISBN (identifier)">ISBN</a>&nbsp;<bdi>978-1-4842-5808-8</bdi>.</cite></li>
<li><cite id="CITEREFSharp2024" class="citation book cs1">Sharp, Robin (2024). <i>Introduction to Cybersecurity: A Multidisciplinary Challenge</i>. Springer Nature. <a href="ISBN_(identifier)" class="mw-redirect" title="ISBN (identifier)">ISBN</a>&nbsp;<bdi>978-3-031-41463-3</bdi>.</cite></li>
<li><cite id="CITEREFSloanWarner2019" class="citation book cs1">Sloan, Robert H.; Warner, Richard (2019). <i>Why Don't We Defend Better?: Data Breaches, Risk Management, and Public Policy</i>. CRC Press. <a href="ISBN_(identifier)" class="mw-redirect" title="ISBN (identifier)">ISBN</a>&nbsp;<bdi>978-1-351-12729-5</bdi>.</cite></li>
<li><cite id="CITEREFSoodEnbody2014" class="citation book cs1">Sood, Aditya; Enbody, Richard (2014). <i>Targeted Cyber Attacks: Multi-staged Attacks Driven by Exploits and Malware</i>. Syngress. <a href="ISBN_(identifier)" class="mw-redirect" title="ISBN (identifier)">ISBN</a>&nbsp;<bdi>978-0-12-800619-1</bdi>.</cite></li>
<li><cite id="CITEREFStrout2023" class="citation book cs1">Strout, Benjamin (2023). <i>The Vulnerability Researcher's Handbook: A comprehensive guide to discovering, reporting, and publishing security vulnerabilities</i>. Packt Publishing. <a href="ISBN_(identifier)" class="mw-redirect" title="ISBN (identifier)">ISBN</a>&nbsp;<bdi>978-1-80324-356-6</bdi>.</cite></li>
<li><cite id="CITEREFTjoa_et_al.2024" class="citation book cs1">Tjoa, Simon; Gafić, Melisa; Kieseberg, Peter (2024). <i>Cyber Resilience Fundamentals</i>. Springer Nature. <a href="ISBN_(identifier)" class="mw-redirect" title="ISBN (identifier)">ISBN</a>&nbsp;<bdi>978-3-031-52064-8</bdi>.</cite></li></ul>
</div>
<div class="mw-heading mw-heading2"><h2 id="External_links">External links</h2></div>
<ul><li><span class="noviewer" typeof="mw:File"></span> Media related to <a href="https://commons.wikimedia.org/wiki/Category:Vulnerability_(computing)" class="extiw external" title="commons:Category:Vulnerability (computing)">Vulnerability (computing)</a> at Wikimedia Commons</li></ul>
<div class="navbox-styles"><style data-mw-deduplicate="TemplateStyles:r1236075235">
/* start https://en.wikipedia.org/ */


.mw-parser-output .navbox{box-sizing:border-box;border:1px solid #a2a9b1;width:100%;clear:both;font-size:88%;text-align:center;padding:1px;margin:1em auto 0}.mw-parser-output .navbox .navbox{margin-top:0}.mw-parser-output .navbox+.navbox,.mw-parser-output .navbox+.navbox-styles+.navbox{margin-top:-1px}.mw-parser-output .navbox-inner,.mw-parser-output .navbox-subgroup{width:100%}.mw-parser-output .navbox-group,.mw-parser-output .navbox-title,.mw-parser-output .navbox-abovebelow{padding:0.25em 1em;line-height:1.5em;text-align:center}.mw-parser-output .navbox-group{white-space:nowrap;text-align:right}.mw-parser-output .navbox,.mw-parser-output .navbox-subgroup{background-color:#fdfdfd}.mw-parser-output .navbox-list{line-height:1.5em;border-color:#fdfdfd}.mw-parser-output .navbox-list-with-group{text-align:left;border-left-width:2px;border-left-style:solid}.mw-parser-output tr+tr>.navbox-abovebelow,.mw-parser-output tr+tr>.navbox-group,.mw-parser-output tr+tr>.navbox-image,.mw-parser-output tr+tr>.navbox-list{border-top:2px solid #fdfdfd}.mw-parser-output .navbox-title{background-color:#ccf}.mw-parser-output .navbox-abovebelow,.mw-parser-output .navbox-group,.mw-parser-output .navbox-subgroup .navbox-title{background-color:#ddf}.mw-parser-output .navbox-subgroup .navbox-group,.mw-parser-output .navbox-subgroup .navbox-abovebelow{background-color:#e6e6ff}.mw-parser-output .navbox-even{background-color:#f7f7f7}.mw-parser-output .navbox-odd{background-color:transparent}.mw-parser-output .navbox .hlist td dl,.mw-parser-output .navbox .hlist td ol,.mw-parser-output .navbox .hlist td ul,.mw-parser-output .navbox td.hlist dl,.mw-parser-output .navbox td.hlist ol,.mw-parser-output .navbox td.hlist ul{padding:0.125em 0}.mw-parser-output .navbox .navbar{display:block;font-size:100%}.mw-parser-output .navbox-title .navbar{float:left;text-align:left;margin-right:0.5em}body.skin--responsive .mw-parser-output .navbox-image img{max-width:none!important}@media print{body.ns-0 .mw-parser-output .navbox{display:none!important}}


/* end https://en.wikipedia.org/ */
</style></div><div role="navigation" class="navbox" aria-labelledby="Information_security92" style="padding:3px"><table class="nowraplinks mw-collapsible autocollapse navbox-inner" style="border-spacing:0;background:transparent;color:inherit"><tbody><tr><th scope="col" class="navbox-title" colspan="3"><div id="Information_security92" style="font-size:114%;margin:0 4em"><a href="Information_security" title="Information security">Information security</a></div></th></tr><tr><th scope="row" class="navbox-group" style="width:1%"><a href="Threat_(computer)" class="mw-redirect" title="Threat (computer)">Threats</a></th><td class="navbox-list-with-group navbox-list navbox-odd hlist" style="width:100%;padding:0"><div style="padding:0 0.25em">
<ul><li><a href="Adware" title="Adware">Adware</a></li>
<li><a href="Advanced_persistent_threat" title="Advanced persistent threat">Advanced persistent threat</a></li>
<li><a href="Arbitrary_code_execution" title="Arbitrary code execution">Arbitrary code execution</a></li>
<li><a href="Backdoor_(computing)" title="Backdoor (computing)">Backdoors</a></li>
<li>Bombs
<ul><li><a href="Fork_bomb" title="Fork bomb">Fork</a></li>
<li><a href="Logic_bomb" title="Logic bomb">Logic</a></li>
<li><a href="Time_bomb_(software)" title="Time bomb (software)">Time</a></li>
<li><a href="Zip_bomb" title="Zip bomb">Zip</a></li></ul></li>
<li><a href="Hardware_backdoor" title="Hardware backdoor">Hardware backdoors</a></li>
<li><a href="Code_injection" title="Code injection">Code injection</a></li>
<li><a href="Crimeware" title="Crimeware">Crimeware</a></li>
<li><a href="Cross-site_scripting" title="Cross-site scripting">Cross-site scripting</a></li>
<li><a href="Cross-site_leaks" title="Cross-site leaks">Cross-site leaks</a></li>
<li><a href="DOM_clobbering" title="DOM clobbering">DOM clobbering</a></li>
<li><a href="History_sniffing" title="History sniffing">History sniffing</a></li>
<li><a href="Cryptojacking" title="Cryptojacking">Cryptojacking</a></li>
<li><a href="Botnet" title="Botnet">Botnets</a></li>
<li><a href="Data_breach" title="Data breach">Data breach</a></li>
<li><a href="Drive-by_download" title="Drive-by download">Drive-by download</a></li>
<li><a href="Browser_Helper_Object" title="Browser Helper Object">Browser Helper Objects</a></li>
<li><a href="Computer_virus" title="Computer virus">Viruses</a></li>
<li><a href="Data_scraping" title="Data scraping">Data scraping</a></li>
<li><a href="Denial-of-service_attack" title="Denial-of-service attack">Denial-of-service attack</a></li>
<li><a href="Eavesdropping" title="Eavesdropping">Eavesdropping</a></li>
<li><a href="Email_fraud" title="Email fraud">Email fraud</a></li>
<li><a href="Email_spoofing" title="Email spoofing">Email spoofing</a></li>
<li><a href="Exploit_(computer_security)" title="Exploit (computer security)">Exploits</a></li>
<li><a href="Dialer#Fraudulent_dialer" title="Dialer">Fraudulent dialers</a></li>
<li><a href="Hacktivism" title="Hacktivism">Hacktivism</a></li>
<li><a href="Infostealer" title="Infostealer">Infostealer</a></li>
<li><a href="Insecure_direct_object_reference" title="Insecure direct object reference">Insecure direct object reference</a></li>
<li><a href="Keystroke_logging" title="Keystroke logging">Keystroke loggers</a></li>
<li><a href="Malware" title="Malware">Malware</a></li>
<li><a href="Payload_(computing)" title="Payload (computing)">Payload</a></li>
<li><a href="Phishing" title="Phishing">Phishing</a>
<ul><li><a href="Voice_phishing" title="Voice phishing">Voice</a></li></ul></li>
<li><a href="Polymorphic_engine" title="Polymorphic engine">Polymorphic engine</a></li>
<li><a href="Privilege_escalation" title="Privilege escalation">Privilege escalation</a></li>
<li><a href="Ransomware" title="Ransomware">Ransomware</a></li>
<li><a href="Rootkit" title="Rootkit">Rootkits</a></li>
<li><a href="Scareware" title="Scareware">Scareware</a></li>
<li><a href="Shellcode" title="Shellcode">Shellcode</a></li>
<li><a href="Spamming" title="Spamming">Spamming</a></li>
<li><a href="Social_engineering_(security)" title="Social engineering (security)">Social engineering</a></li>
<li><a href="Spyware" title="Spyware">Spyware</a></li>
<li><a href="Software_bug" title="Software bug">Software bugs</a></li>
<li><a href="Trojan_horse_(computing)" title="Trojan horse (computing)">Trojan horses</a></li>
<li><a href="Hardware_Trojan" title="Hardware Trojan">Hardware Trojans</a></li>
<li><a href="Remote_access_trojan" class="mw-redirect" title="Remote access trojan">Remote access trojans</a></li>

<li><a href="Web_shell" title="Web shell">Web shells</a></li>
<li><a href="Wiper_(malware)" title="Wiper (malware)">Wiper</a></li>
<li><a href="Computer_worm" title="Computer worm">Worms</a></li>
<li><a href="SQL_injection" title="SQL injection">SQL injection</a></li>
<li><a href="Rogue_security_software" title="Rogue security software">Rogue security software</a></li>
<li><a href="Zombie_(computing)" title="Zombie (computing)">Zombie</a></li></ul>
</div></td><td class="noviewer navbox-image" rowspan="3" style="width:1px;padding:0 0 0 2px"><div></div></td></tr><tr><th scope="row" class="navbox-group" style="width:1%">Defenses</th><td class="navbox-list-with-group navbox-list navbox-even hlist" style="width:100%;padding:0"><div style="padding:0 0.25em">
<ul><li><a href="Application_security" title="Application security">Application security</a>
<ul><li><a href="Secure_coding" title="Secure coding">Secure coding</a></li>
<li>Secure by default</li>
<li><a href="Secure_by_design" title="Secure by design">Secure by design</a>
<ul><li><a href="Misuse_case" title="Misuse case">Misuse case</a></li></ul></li></ul></li>
<li><a href="Computer_access_control" title="Computer access control">Computer access control</a>
<ul><li><a href="Authentication" title="Authentication">Authentication</a>
<ul><li><a href="Multi-factor_authentication" title="Multi-factor authentication">Multi-factor authentication</a></li></ul></li>
<li><a href="Authorization" title="Authorization">Authorization</a></li></ul></li>
<li><a href="Computer_security_software" title="Computer security software">Computer security software</a>
<ul><li><a href="Antivirus_software" title="Antivirus software">Antivirus software</a></li>
<li><a href="Security-focused_operating_system" title="Security-focused operating system">Security-focused operating system</a></li></ul></li>
<li><a href="Data-centric_security" title="Data-centric security">Data-centric security</a></li>
<li><a href="Obfuscation_(software)" title="Obfuscation (software)">Software obfuscation</a></li>
<li><a href="Data_masking" title="Data masking">Data masking</a></li>
<li><a href="Encryption" title="Encryption">Encryption</a></li>
<li><a href="Firewall_(computing)" title="Firewall (computing)">Firewall</a></li>
<li><a href="Intrusion_detection_system" title="Intrusion detection system">Intrusion detection system</a>
<ul><li><a href="Host-based_intrusion_detection_system" title="Host-based intrusion detection system">Host-based intrusion detection system</a> (HIDS)</li>
<li><a href="Anomaly_detection" title="Anomaly detection">Anomaly detection</a></li></ul></li>
<li><a href="Information_security_management" title="Information security management">Information security management</a>
<ul><li><a href="Information_risk_management" class="mw-redirect" title="Information risk management">Information risk management</a></li>
<li><a href="Security_information_and_event_management" title="Security information and event management">Security information and event management</a> (SIEM)</li></ul></li>
<li><a href="Runtime_application_self-protection" title="Runtime application self-protection">Runtime application self-protection</a></li>
<li><a href="Site_isolation" title="Site isolation">Site isolation</a></li></ul>
</div></td></tr><tr><th scope="row" class="navbox-group" style="width:1%">Related<br>security<br>topics</th><td class="navbox-list-with-group navbox-list navbox-odd hlist" style="width:100%;padding:0"><div style="padding:0 0.25em">
<ul><li><a href="Computer_security" title="Computer security">Computer security</a></li>
<li><a href="Automotive_security" title="Automotive security">Automotive security</a></li>
<li><a href="Cybercrime" title="Cybercrime">Cybercrime</a>
<ul><li><a href="Cybersex_trafficking" title="Cybersex trafficking">Cybersex trafficking</a></li>
<li><a href="Computer_fraud" title="Computer fraud">Computer fraud</a></li></ul></li>
<li><a href="Cybergeddon" title="Cybergeddon">Cybergeddon</a></li>
<li><a href="Cyberterrorism" title="Cyberterrorism">Cyberterrorism</a></li>
<li><a href="Cyberwarfare" title="Cyberwarfare">Cyberwarfare</a></li>
<li><a href="Electronic_warfare" title="Electronic warfare">Electronic warfare</a></li>
<li><a href="Information_warfare" title="Information warfare">Information warfare</a></li>
<li><a href="Internet_security" title="Internet security">Internet security</a></li>
<li><a href="Mobile_security" title="Mobile security">Mobile security</a></li>
<li><a href="Network_security" title="Network security">Network security</a></li>
<li><a href="Copy_protection" title="Copy protection">Copy protection</a></li>
<li><a href="Digital_rights_management" title="Digital rights management">Digital rights management</a></li></ul>
</div></td></tr></tbody></table></div></div><!--htdig_noindex--><div><div class="zim-footer">
This article is issued from <a class="external text" title="Last edited on 2025-08-04" href="https://en.wikipedia.org/wiki/?title=Vulnerability_(computer_security)&amp;oldid=1304246215">Wikipedia</a>. The text is available under <a class="external text" href="https://creativecommons.org/licenses/by-sa/4.0/deed.en">Creative Commons Attribution-Share Alike 4.0</a> unless otherwise noted. Additional terms may apply for the media files.
</div>
</div><!--/htdig_noindex--></div>
</div>
</main>
</div>
</div>
</div>

</body></html>