Tag: Vulnerability Databases

  • Ferreting Out Unique Vulnerability Data in OSVDB

    [This was originally published on the OSVDB blog.] In previous blog posts and on Twitter, I have shown and mentioned various methods for searching OSVDB to find interesting data. However, there is no written guide to the ins-and-outs of the data. The search interface is simple enough, but it can be used in a manner…

  • iDefense VCP as seen through OSVDB

    [This was originally published on the OSVDB blog.] In 2002, iDefense started their Vulnerability Contributor Program. The VCP was created to solicit vulnerability information from the security community and pay researchers for the information. Paying up to US$15,000 for a vulnerability or exploit, iDefense proved there was a significant market for such information after years…

  • Adobe, Qualys, CVE, and Math

    [This was originally published on the OSVDB blog.] Elinor Mills wrote an article titled Firefox, Adobe top buggiest-software list. In it, she quotes Qualys as providing vulnerability statistics for Mozilla, Adobe and others. Qualys states: The number of vulnerabilities in Adobe programs rose from 14 last year to 45 this year, while those in Microsoft…

  • OSVDB – Creditee System Overhauled

    [This was originally published on the OSVDB blog.] Thanks to Dave, we now have a completely re-written creditee system. For years, we operated off a four field system (name, email, company, url) for tracking vulnerability researchers. While we tracked that information, it was not flexible and led to serious problems with data integrity. Even worse,…

  • OSVDB – Search Filters & Custom Exports

    [This was originally published on the OSVDB blog.] Last week, OSVDB enhanced the search results capability by adding a considerable amount of filter capability, a simple “results by year” graph and export capability. Rather than draft a huge walkthrough, open a search in a new tab and title search for “microsoft windows”. As always, the…

  • What I Learned From Early CVE Entries!

    [This was originally published on the OSVDB blog.] This post is the farthest thing from picking on or insulting CVE. They were running a VDB some four years before OSVDB entered the picture. More impressive, they operated with a level of transparency that no other VDB offered at the time. Early OSVDB entries suffered just…

  • Vendors & researchers, no more decade old embargo!

    [This was originally published on the OSVDB blog.] Vulnerabilities reported ten years ago, they have no impact on your customers. If they do, then you are woefully behind and your customers are desperately hanging on to legacy products, scared to upgrade. For vendors who have kept up on security and adopted a responsible and timely…

  • Malware to Vulnerability Mappings.. Anyone?

    [This was originally published on the OSVDB blog.] Unbeknownst to many of us, MITRE’s Common Malware Enumeration (CME) project was declared dead, and apparently has been for a while. What is CME? From their site: CME was created to provide single, common identifiers to new virus threats and to the most prevalent virus threats in…

  • What features are sorely lacking from VDBs?

    [This was originally published on the OSVDB blog.] For over ten years, most Vulnerability Databases (VDBs) have done little to evolve. In some cases, they appear to be devolving. OSVDB recognized this many long ago but has struggled for years with a lack of resources, particularly developers. Now that we have saved up enough money,…

  • OSVDB – Search Enhance: by CVSS Score or Attribute

    [This was originally published on the OSVDB blog.] Using the ‘Advanced Search‘, you can now search the database by entering a CVSSv2 score range (e.g., 8 to 10) or by a specific CVSSv2 attribute (e.g., Confidentiality : Partial). To search for entries with only a 10 score, use the search range 10 to 10. Using…