Main article: Vulnerability (computing)
Security bugs, like all other software bugs, stem from root causes that can generally be traced to either absent or inadequate:3
Security bugs generally fall into a fairly small number of broad categories that include:4
See software security assurance.
"CWE/SANS TOP 25 Most Dangerous Software Errors". SANS. Retrieved 13 July 2012. http://cwe.mitre.org/top25/index.html#CWE-306 ↩
"Software Quality and Software Security". 2008-11-02. Retrieved 2017-04-28. http://swreflections.blogspot.com/2008/11/software-quality-and-software-security.html ↩
Alhazmi, Omar H.; Woo, Sung-Whan; Malaiya, Yashwant K. (Jan 2006). "Security vulnerability categories in major software systems". Proceedings of the Third IASTED International Conference on Communication, Network, and Information Security. https://www.researchgate.net/publication/220885085 ↩