CWE

Common Weakness Enumeration

A Community-Developed List of Software & Hardware Weakness Types

CWE Top 25 Most Dangerous Weaknesses
Home > News > Podcast  
ID

Podcast

“Out-Of-Bounds Read” is the CWE/CAPEC Program’s free podcast devoted to helping the community that protects systems by understanding weaknesses and attack patterns in software and hardware. Listen now on the CWE/CAPEC Program Channel on YouTube, the Out-of-Bounds Read page on Buzzsprout, or on podcast platforms.


Out of Bounds Read podcast episode 4 - The CWE 15th Anniversary Special
The CWE 15th Anniversary Special - Episode 4   
YouTube | Buzzsprout

This episode is a special cybersecurity awareness month podcast where we discuss the 15-year history and future of the CWE/CAPEC program.

Interviewees include:

Bob Martin, Senior Principal Software and Supply Chain Assurance Engineer at MITRE
Joe Jarzombek, Director of Government and Critical Infrastructure Programs at Synopsis
Chris Eng, Chief Research Officer at Veracode
Chris Levendis, CWE/CAPEC Program Leader at MITRE
Drew Buttner, Software Assurance Capability Area Lead at MITRE

Resources mentioned in this episode:

Common Weakness Enumeration (CWE™)
Common Attack Pattern Enumeration and Classification (CAPEC™)
IS0/IEC 5055:2021 - Information technology; Software measurement; Software quality measurement; Automated source code quality measures
CWE-1340
Software Bill of Materials (SBOM)

Out of Bounds Read podcast episode 3 - All About the 2021 Top 25 Most Dangerous Software Weaknesses
All About the 2021 Top 25 Most Dangerous Software Weaknesses - Episode 3   
YouTube | Buzzsprout

Steve Battista of the CWE/CAPEC Program interviews Rushi Purohit, who has helped lead the efforts behind the last few years’ Top 25 most dangerous software weaknesses publications. We talk about the new 2021 release of this list.

Resources mentioned in this episode:

2021 CWE Top 25
Methodology
Analysis
U.S. National Vulnerability Database (NVD)

Out of Bounds Read podcast episode 2 - What is CAPEC, Why is It important, and How Can it Help Me?
What is CAPEC, Why is It important, and How Can it Help Me? - Episode 2   
YouTube | Buzzsprout

Steve Battista of the CWE/CAPEC Program interviews Rich Piazza, the CAPEC Task Lead, about what Common Attack Pattern Enumeration and Classification (CAPEC™) and the problem it aims to solve, who can benefit from CAPEC and how to leverage it, the role of the community, how CAPEC has evolved over time, and possibilities for the future.

Resources mentioned in this episode:

CWE/CAPEC on Twitter
Common Attack Pattern Enumeration and Classification (CAPEC™)

Out of Bounds Read podcast episode 1 - What Is CWE, Why Is It Important, and How Can It Help Me?
What Is CWE, Why Is It Important, and How Can It Help Me? - Episode 1   
YouTube | Buzzsprout | MP3

Welcome to the inaugural episode of Out-of-Bounds Read, the CWE/CAPEC Program podcast!

In our first-ever episode, Steve Battista of the CWE/CAPEC Program interviews Steve Christey Coley, the CWE/CAPEC Program Technical Lead, about what Common Weakness Enumeration (CWE™) is and the problem it aims to solve, who can benefit from CWE and how to leverage it, the role of the community, how CWE has evolved over time, and possibilities for the future.

Resources mentioned in this episode:

CWE/CAPEC on Twitter
CWE Submissions Form & Guidelines
Common Vulnerability Scoring System (CVSS)
U.S. National Vulnerability Database’s (NVD) CVSS calculator

More information is available — Please select a different filter.
Page Last Updated: October 14, 2021