Hacker News new | past | comments | ask | show | jobs | submit login

> What CVEs aren't due to programming mistakes?

Shellshock would be a good candidate: Bash is designed to be able to pass around some amount of shell scripting in environment variables, which obviously leads to some pretty severe security issues if attackers can control environment variables (say, CGI scripts). So you can argue that the problem here is a design mistake rather than a programming mistake.




Also, spectre meltdown, all the hw cves, there are a bunch of bluetooth protocol flaws.. the list goes on.




Join us for AI Startup School this June 16-17 in San Francisco!

Guidelines | FAQ | Lists | API | Security | Legal | Apply to YC | Contact

Search: