Tag: NVD

  • Case Study: Third-Party Plugins

    Case Study: Third-Party Plugins

    [This was originally published on RiskBasedSecurity.com in the 2018 Q3 Vulnerability QuickView Report.] Many people are familiar with content management systems (CMS), which are used in a variety of roles. Millions of people use them via hosted software such as WordPress.com and companies use them for blogging and knowledgebase systems. Historically, despite their wide deployment,…

  • Our Reports Clickbait? No. Click Here To Find Out Why…

    Our Reports Clickbait? No. Click Here To Find Out Why…

    [This was originally posted to the Risk Based Security blog (now 404 and no IA copy), with contributions from Jake Kouns.] Last week, we published our 2018 mid-year report that included an overview of the vulnerabilities that we have tracked and included in VulnDB. We highlighted a key takeaway from the report in the title:…

  • Thoughts about CNNVD vs. US NVD

    Thoughts about CNNVD vs. US NVD

    [This was originally published on RiskBasedSecurity.com in the 2017 Q3 Vulnerability QuickView report.] In October, Bill Ladd of Recorded Future released a study comparing CVE and the U.S. NationalVulnerability Database (NVD) with China’s National Vulnerability Database (CNNVD). This report, titled“The Dragon Is Winning: U.S. Lags Behind Chinese Vulnerability Reporting” was covered by John Leyden inThe…

  • Rebuttal: Dark Reading’s “9” Sources for Tracking New Vulnerabilities

    Rebuttal: Dark Reading’s “9” Sources for Tracking New Vulnerabilities

    [This was originally published on the OSVDB blog.] Earlier today, Sean Martin published an article on Dark Reading titled “9 Sources For Tracking New Vulnerabilities“. Spanning 10 pages, likely for extra ad revenue, the sub-title reads: Keeping up with the latest vulnerabilities — especially in the context of the latest threats — can be a…

  • Our New Year Vulnerability “Trends” Prediction!

    Our New Year Vulnerability “Trends” Prediction!

    [This was originally published on RiskBasedSecurity.com.] Shortly after a year closes out, the industry is treated to dozens of security companies that want to tell you all about vulnerability totals and trends from the previous year. In many cases, the companies offering the predictions are armchair experts of a sorts, who do not aggregate vulnerability…

  • CVE/NVD: The High Price of ‘Free’

    CVE/NVD: The High Price of ‘Free’

    [This was originally published for RiskBasedSecurity.com. I can’t find the original on archive.org and this was written too long ago to have access to the original Google Doc.] Vulnerability Intelligence (VI) is not a new offering by any stretch of the imagination. However, in the past few years VI has gained more attention and become…

  • SQLi Disclosures and the Last Five Years (Transparent Statistics)

    SQLi Disclosures and the Last Five Years (Transparent Statistics)

    [This was originally published on the OSVDB blog.] Nothing like waking up to a new article purporting to show vulnerability statistics and having someone ask us for comment. But hey, we love giving additional perspective on such statistics since they are often without proper context and disclaimers. This morning, the new article comes from Help…

  • CVE Vulnerabilities: How Your Dataset Influences Statistics

    [This was originally published on the OSVDB blog.] Readers may recall that I blogged about a similar topic just over a month ago, in an article titled Advisories != Vulnerabilities, and How It Affects Statistics. In this installment, instead of “advisories”, we have “CVEs” and the inherent problems when using CVE identifiers in the place…

  • Adobe, Qualys, CVE, and Math

    [This was originally published on the OSVDB blog.] Elinor Mills wrote an article titled Firefox, Adobe top buggiest-software list. In it, she quotes Qualys as providing vulnerability statistics for Mozilla, Adobe and others. Qualys states: The number of vulnerabilities in Adobe programs rose from 14 last year to 45 this year, while those in Microsoft…

  • OSVDB Now Supports CVSSv2 Scoring

    [This was originally published on the OSVDB blog.] OSVDB now displays CVSSv2 scores, mostly as calculated by the National Vulnerability Database (NVD): Along with the score, we display the date that NVD generated it and give users a method for recommending updates if they feel the score is inaccurate. While this is long overdue, this…