CWE Glossary Definition |
👁 x
|
Podcast
“Out-Of-Bounds Read” is the CWE Program’s free podcast about common weaknesses in software and hardware, the vulnerabilities they cause, how to reduce them, and how using CWE can help make products more secure by design. Listen now on the CWE Program Channel on YouTube.
👁 Out of Bounds Read podcast - CWE Top 25 Most Dangerous Software Weaknesses
|
CWE Top 25 Most Dangerous Software Weaknesses YouTube
MITRE’s CWE™ and CVE™ Project Lead Alec Summers talks with CWE Technical Lead Steve Christey and CWE Top 25 Lead Connor Mullaly about the CWE Top 25 Most Dangerous Software Weaknesses list (CWE Top 25).
Topics include what the CWE Top 25 is and why it matters for software security; how the list is calculated using prevalence and average severity; how the quality of mappings in CVE Records affects the accuracy and usefulness of the list; how CVE Numbering Authorities (CNAs) help build the list; common mapping problems, especially choosing overly broad or discouraged entries instead of more specific ones; changes in methodology for the 2025 list, especially moving away from normalizing everything into a smaller subset and instead reflecting what actually mapped in the full corpus; and practical advice for better root cause mapping, including using mapping notes, avoiding discouraged entries, and focusing on the underlying weakness rather than just the impact.
|
👁 Out of Bounds Read podcast - Why Cisco uses CWE while looking at fixing vulnerabilities
|
Why Cisco Uses CWE While Looking at Fixing Vulnerabilities YouTube
In this episode, we talk with Cisco’s Tim Wadhwa-Brown, Security Research and Offensive Security for Professional Services in Europe and Jared Pendleton, Advanced Security Initiatives Group about how Cisco uses CWE for finding and fixing vulnerabilities. They find it useful to help categorize the types of vulnerabilities to help determine the root cause of possible future vulnerabilities.
|
👁 Out of Bounds Read podcast - What Is CWE, Why Is It Important, and How Can It Help Me?
|
What Is CWE, Why Is It Important, and How Can It Help Me? YouTube | MP3
Welcome to the inaugural episode of Out-of-Bounds Read, the CWE/CAPEC Program podcast!
In our first-ever episode, Steve Battista of the CWE/CAPEC Program interviews Steve Christey Coley, the CWE/CAPEC Program Technical Lead, about what Common Weakness Enumeration (CWE™) is and the problem it aims to solve, who can benefit from CWE and how to leverage it, the role of the community, how CWE has evolved over time, and possibilities for the future.
Resources mentioned in this episode:
CWE/CAPEC on Twitter
CWE Submissions Form & Guidelines
Common Vulnerability Scoring System (CVSS)
U.S. National Vulnerability Database’s (NVD) CVSS calculator
|
Archived Episodes
👁 Out of Bounds Read podcast - What is CAPEC, Why is It important, and How Can it Help Me?
|
What is CAPEC, Why is It important, and How Can it Help Me? (ARCHIVED) YouTube
NOTE: This episode has been ARCHIVED.
Steve Battista of the CWE/CAPEC Program interviews Rich Piazza, the CAPEC Task Lead, about what Common Attack Pattern Enumeration and Classification (CAPEC™) and the problem it aims to solve, who can benefit from CAPEC and how to leverage it, the role of the community, how CAPEC has evolved over time, and possibilities for the future.
Resources mentioned in this episode:
CWE on Twitter
Common Attack Pattern Enumeration and Classification (CAPEC™)
|
More information is available — Please edit the custom filter or select a different filter.
|