对象已移动

可在此处找到该文档 The top 25 weaknesses in software in 2024 – New Self New Life
New Self New Life
No Result
View All Result
  • Home
  • Entertainment
  • Celebrity
  • Cinema
  • Music
  • Digital Lifestyle
  • Social Media
  • Softwares
  • Devices
  • Home
  • Entertainment
  • Celebrity
  • Cinema
  • Music
  • Digital Lifestyle
  • Social Media
  • Softwares
  • Devices
New Self New Life
No Result
View All Result
Home Softwares

The top 25 weaknesses in software in 2024

by admin
8 months ago
in Softwares
The top 25 weaknesses in software in 2024
Share on FacebookShare on Twitter


MITRE just lately launched its yearly checklist of the 2024 CWE Prime 25 Most Harmful Software program Weaknesses. 

This checklist differs from lists that comprise the most typical vulnerabilities, as it’s not an inventory of vulnerabilities, however relatively weaknesses in system design that may be exploited to leverage vulnerabilities. 

“By definition, code injection is an assault, and after we take into consideration the Prime 25 it’s figuring out the weaknesses beneath,” stated Alec Summers, challenge chief for the CVE and CWE packages at MITRE. 

These weaknesses can doubtlessly pave the best way for vulnerabilities and assaults, so it’s vital to pay attention to them and mitigate them as a lot as attainable.

In line with Summers, one development on this yr’s checklist is that whereas some weaknesses moved up or down the checklist, a number of the weaknesses on the checklist are basic weaknesses which were round for years, reminiscent of those who allow SQL injection and cross-site scripting.

“The extra you perceive these weaknesses, and also you draw connections between this stuff, you possibly can truly begin to get rid of entire lessons of issues that we see so many occasions,” he stated.

Addressing these weaknesses not solely improves product safety, but in addition has the potential to avoid wasting corporations cash as a result of “the extra weaknesses we keep away from in product growth, the much less vulnerabilities to handle after deployment,” he defined.

This yr’s checklist contains the next weaknesses:

  1. Improper Neutralization of Enter Throughout Net Web page Technology (‘Cross-site Scripting’)
  2. Out-of-bounds Write
  3. Improper Neutralization of Particular Parts utilized in an SQL Command (‘SQL Injection’)
  4. Cross-Web site Request Forgery (CSRF)
  5. Improper Limitation of a Pathname to a Restricted Listing (‘Path Traversal’)
  6. Out-of-bounds Learn
  7. Improper Neutralization of Particular Parts utilized in an OS Command (‘OS Command Injection’)
  8. Use After Free
  9. Lacking Authorization
  10. Unrestricted Add of File with Harmful Kind
  11. Improper Management of Technology of Code (‘Code Injection’)
  12. Improper Enter Validation
  13. Improper Neutralization of Particular Parts utilized in a Command (‘Command Injection’)
  14. Improper Authentication
  15. Improper Privilege Administration
  16. Deserialization of Untrusted Knowledge
  17. Publicity of Delicate Data to an Unauthorized Actor
  18. Incorrect Authorization
  19. Server-Aspect Request Forgery (SSRF)
  20. Improper Restriction of Operations throughout the Bounds of a Reminiscence Buffer
  21. NULL Pointer Dereference
  22. Use of Onerous-coded Credentials
  23. Integer Overflow or Wraparound
  24. Uncontrolled Useful resource Consumption
  25. Lacking Authentication for Vital Operate

The dataset the checklist relies on contains data for 31,779 Widespread Vulnerabilities and Exposures (CVEs) revealed between June 1, 2023 and June 1, 2024. 

In line with Summers, this yr, the technique through which the checklist was created was completely different than in previous years as a result of MITRE and CISA concerned the broader safety group to research the dataset, whereas in earlier years MITRE’s Widespread Weak point Enumeration (CWE) crew labored alone. 

This may increasingly have resulted in lots of modifications from earlier years, and this yr’s checklist solely featured three weaknesses that retained the identical rating as final yr: #3 Improper Neutralization of Particular Parts utilized in an SQL Command (‘SQL Injection’), #10 Unrestricted Add of File with Harmful Kind, and #19 Server-Aspect Request Forgery (SSRF).

The weaknesses that had the most important upward transfer from final yr’s checklist are #4 Cross-Web site Request Forgery, which moved up 5 ranks; #11 Improper Management of Technology of Code (‘Code Injection’), which moved up 12 ranks; #15 Improper Privilege Administration, which moved up seven ranks; and #18 Incorrect Authorization, which moved up six ranks. 

Weaknesses that moved down in rank considerably embody #12 Improper Enter Validation, which moved down six ranks; #21 NULL Pointer Dereference, which moved down 9 ranks; #23 Integer Overflow or Wraparound, which moved down 9 ranks; and #25 Lacking Authentication for Vital Operate, which moved down 5 ranks. 

This yr additionally noticed two new entries to the checklist and two entries that left the Prime 25. New entries embody #17 Publicity of Delicate Data to an Unauthorized Actor and #24 Uncontrolled Useful resource Consumption. Earlier entries now not within the Prime 25 are Concurrent Execution utilizing Shared Useful resource with Improper Synchronization (‘Race Situation’) and Incorrect Default Permissions.

In line with MITRE, one attainable reason behind the modifications is that they didn’t obtain CWE mappings from the U.S. Nationwide Vulnerability Database analysts for the CVE data from the primary half of 2024. 

“It’s not clear whether or not these gaps have an effect on the relative rankings, for the reason that distribution of unmapped CVEs appears prone to align roughly with the CWE distribution of the complete information set,” MITRE wrote. 



Source link

Tags: SoftwareTopWeaknesses
Previous Post

Wendy Williams ‘permanently incapacitated’ by dementia, guardian claims – National

Next Post

Tech Changes! – Corporette.com

Related Posts

Best AI Agents Development Companies in 2025
Softwares

Best AI Agents Development Companies in 2025

by admin
July 28, 2025
Minor update(3) for Vivaldi Android Browser 7.5
Softwares

Minor update(3) for Vivaldi Android Browser 7.5

by admin
July 27, 2025
User Guide For 360 Degree Product Image For Wix
Softwares

User Guide For 360 Degree Product Image For Wix

by admin
July 24, 2025
New open-source tool makes complex data understandable
Softwares

New open-source tool makes complex data understandable

by admin
July 25, 2025
BrowserStack launches Figma plugin for detecting accessibility issues in design phase
Softwares

BrowserStack launches Figma plugin for detecting accessibility issues in design phase

by admin
July 22, 2025
Next Post
Tech Changes! – Corporette.com

Tech Changes! - Corporette.com

Wendy Williams’s guardian claims in lawsuit that Lifetime doc filmmakers sought to ‘exploit’ her ‘cognitive and physical decline’

Wendy Williams’s guardian claims in lawsuit that Lifetime doc filmmakers sought to ‘exploit’ her ‘cognitive and physical decline'

  • Trending
  • Comments
  • Latest
Critics And Fans Disagree On Netflix’s Controversial Fantasy Show With Near-Perfect RT Score

Critics And Fans Disagree On Netflix’s Controversial Fantasy Show With Near-Perfect RT Score

July 5, 2025
10 Best Netflix Original Thriller Shows, Ranked

10 Best Netflix Original Thriller Shows, Ranked

June 22, 2025
How well did you know Ozzy? Take this quiz – National

How well did you know Ozzy? Take this quiz – National

July 28, 2025
Why unFTP, how to run, embed or extend with Rust

Why unFTP, how to run, embed or extend with Rust

June 22, 2021
I Tried Calocurb For 90 Days. Here’s My Review.

I Tried Calocurb For 90 Days. Here’s My Review.

January 8, 2025
In-N-Out heiress’ dizzying wealth could grow by millions as chain leaves California behind

In-N-Out heiress’ dizzying wealth could grow by millions as chain leaves California behind

July 24, 2025
Us TikTok Ban To Be Upheld if a Deal Isn’t Finalized by Current Deadline

Us TikTok Ban To Be Upheld if a Deal Isn’t Finalized by Current Deadline

July 25, 2025
Mustard Releases His Own Condiments Line

Mustard Releases His Own Condiments Line

July 27, 2025
Family, Friends & Fans Gather for Ozzy Osbourne’s Cortege Travels

Family, Friends & Fans Gather for Ozzy Osbourne’s Cortege Travels

July 30, 2025
10 Hulu Miniseries That Are Absolutely Flawless (#1 Is The Best You’ve Never Seen)

10 Hulu Miniseries That Are Absolutely Flawless (#1 Is The Best You’ve Never Seen)

July 30, 2025
Love Island USA’s JaNa Craig and Kenny Rodriguez Split: What We Know

Love Island USA’s JaNa Craig and Kenny Rodriguez Split: What We Know

July 30, 2025
What to post on LinkedIn: 30 ideas plus examples

What to post on LinkedIn: 30 ideas plus examples

July 30, 2025
Hardwell Reveals Avicii Asked Him to Collaborate On "Bromance"

Hardwell Reveals Avicii Asked Him to Collaborate On "Bromance"

July 29, 2025
Flowtica Scribe AI Pen : An AI Assistant in Your Pocket

Flowtica Scribe AI Pen : An AI Assistant in Your Pocket

July 29, 2025
Spotify Stock Dips On Q2 Earnings Miss, Focus On Ads Business

Spotify Stock Dips On Q2 Earnings Miss, Focus On Ads Business

July 29, 2025
Robin Williams’s Daughter On AI, Matthew Lawrence Backlash

Robin Williams’s Daughter On AI, Matthew Lawrence Backlash

July 29, 2025
New Self New Life

Your source for entertainment news, celebrities, celebrity news, and Music, Cinema, Digital Lifestyle and Social Media and More !

Categories

  • Celebrity
  • Cinema
  • Devices
  • Digital Lifestyle
  • Entertainment
  • Music
  • Social Media
  • Softwares
  • Uncategorized

Recent Posts

  • Family, Friends & Fans Gather for Ozzy Osbourne’s Cortege Travels
  • 10 Hulu Miniseries That Are Absolutely Flawless (#1 Is The Best You’ve Never Seen)
  • Love Island USA’s JaNa Craig and Kenny Rodriguez Split: What We Know
  • Home
  • Disclaimer
  • DMCA
  • Privacy Policy
  • Cookie Privacy Policy
  • Terms and Conditions
  • Contact us

Copyright © 2021 New Self New Life.
New Self New Life is not responsible for the content of external sites. slotsfree  creator solana token

No Result
View All Result
  • Home
  • Entertainment
  • Celebrity
  • Cinema
  • Music
  • Digital Lifestyle
  • Social Media
  • Softwares
  • Devices

Copyright © 2021 New Self New Life.
New Self New Life is not responsible for the content of external sites.

New Self New Life