Why do traditional scanning tools detect less than 3% of memory safety vulnerabilities in C and C++, and how can we improve software security?

In this week’s RunSafe Security Minute, we explore why scanning tools detect less than 3% of memory safety vulnerabilities in C/C++ and what you can do to address this gap. Salim breaks down the challenges of detecting subtle bugs in C/C++ code and shares practical solutions like using SBOMs and hardening techniques to protect your software from both known and unknown threats.

Memory Safety in C/C++

Why Memory Safety Vulnerabilities in C/C++ Are Hard to Detect with Scanning Tools

Scanning tools fail to detect over 97% of memory safety vulnerabilities in C/C++—but why? The challenge lies in the complexity of analyzing C/C++ code and the subtlety of memory vulnerabilities, which traditional tools aren’t designed to catch. Instead, they focus on matching known vulnerabilities rather than deeply analyzing the code itself for potential exploits.

In this RunSafe Security Minute, Salim explains why memory safety in C/C++ is such a persistent issue and how organizations can take proactive steps to close this security gap. From using SBOMs to stay informed about new vulnerabilities to hardening your software against unknown threats, this video provides actionable insights to enhance your software’s security posture.

If you’re developing or securing software in C/C++, understanding these risks and solutions is critical. Watch now to learn how to protect your systems from vulnerabilities hiding in plain sight.

CRA Readiness: Build an SBOM You Can Act On

CRA Readiness: Build an SBOM You Can Act On

Under the Cyber Resilience Act, having an SBOM is only the beginning. Manufacturers need to know exactly what software is in each product release and be able to quickly determine which products are affected when a new vulnerability emerges. For embedded software, that...

read more
Operational Software Assurance

Operational Software Assurance

Security Cannot Stop When Software Ships Critical software can remain deployed for years or even decades. During that time, new vulnerabilities emerge, threats evolve, and AI is accelerating both vulnerability discovery and exploit development. But patching, testing,...

read more
6 Steps to CRA Readiness

6 Steps to CRA Readiness

The EU Cyber Resilience Act (CRA) is reshaping how connected and embedded products must be secured, maintained, and supported. Is your organization ready? Watch this short video to learn six practical steps that can help product manufacturers prepare: Test your...

read more