digibusiness.fi | livingbusiness.fi | swbusiness.fi
13.1.2009
2009 CWE/SANS Top 25 Most Dangerous Programming Errors

Top 25 Most Dangerous Programming Errors is a list of the most significant programming errors that can lead to serious software vulnerabilities. They occur frequently, are often easy to find, and easy to exploit. They are dangerous because they will frequently allow attackers to completely take over the software, steal data, or prevent the software from working at all.

The list is the result of collaboration between the SANS Institute, MITRE, and many top software security experts in the US and Europe. It leverages experiences in the development of the SANS Top 20 attack vectors and MITRE's Common Weakness Enumeration (CWE).

The Top 25 is organized into three high-level categories that contain multiple CWE entries. Categories are: Insecure interaction between components, risky resource management and Porous defences.


Further information and complete list:
cwe.mitre.org/top25/