Rants of a deranged squirrel.

OSVDB – Classification: Exploit Status Overhaul

[This was originally published on the OSVDB blog.]

OSVDB’s classification system is designed to categorize certain attributes of a vulnerability. This facilitates custom searches by a specific attribute, helps researchers develop metrics and gives a better picture of the vulnerability landscape. Until now, we’ve tracked if an exploit is ‘available’, ‘unavailable’, ‘rumored / private’ or ‘unknown’. While this was a good start for exploit status, it has quickly outgrown usefulness. Today, OSVDB overhauled the exploit classification to use the following:

In addition, we are moving one existing classification to the ‘exploit’ column since it is relevant to this category:

As always, if you have suggestions or questions about the classification system, please mail moderators[at]osvdb.org!

Exit mobile version