The 2009 Pwnie Winner For Lamest Vendor Response

Linux

Continually assuming that all kernel memory corruption bugs are only Denial-of-Service

The Linux kernel development team was nominated several times over for their ongoing lack of handling of bugs of “unknown impact” and generally assuming that all kernel memory corruption issues are only Denial-of-Service issues. Here’s a hint: Just because you can only get a DoS from a bug, doesn’t mean that skilled hackers can’t get a root shell out of it.