A security bug or security defect is a software bug that can be exploited to gain unauthorized access or privileges on a computer system. Security bugs introduce security vulnerabilities by compromising one or more of:
Security bugs need not be identified nor exploited to qualify as such.
Security bugs, like all other software bugs, stem from root causes that can generally be traced to either absent or inadequate:
Security bugs generally fall into a fairly small number of broad categories that include:
See software security assurance.