Tag: Vulnerability Statistics

  • Numb3rs

    [This was originally published on the OSVDB blog.] I’ve been with the OSVDB project for 1000 days. I am responsible for creating 20,667 entries, moderating 7,791 mangler submissions, and mangling 3,480 vulnerabilities myself. The database contains vulnerabilities dating back to 1965, spanning over 40 years. The database contains over 3,800 cross-site scripting, 2,500 SQL injection…

  • Depending on how you count flaws..

    [This was originally published on the OSVDB blog.] After flap, Symantec adjusts browser bug countDepending on how you count flaws, either IE or Firefox could be considered less secureNews Story by Robert McMillan MARCH 07, 2006 (IDG NEWS SERVICE) – A report issued today by Symantec Corp. seeks to satisfy users of both Mozilla Corp.’s…

  • Mac vs Windows – More “Statistics”

    [This was originally published by the OSVDB blog.] Yet another article comparing Mac vs Windows, and using statistics to back it up. Since this is getting to be a common occurrence, I won’t go into the usual lecture about statistics, how they can easily be manipulated to back any argument (including how VAX/VMS is the…

  • A Time to Patch

    [This was originally published on the OSVDB blog.] http://blogs.washingtonpost.com/securityfix/2006/01/a_timeline_of_m.html Brian Krebs has a fantastic post on his blog covering the time it takes for Microsoft to release a patch, and if they are getting any better at it. Here are a few relevant paragraphs from it, but I encourage you to read the entire article.…

  • An Open Letter on the Interpretation of “Vulnerability Statistics”

    [This was originally published on the OSVDB blog.] Steve Christey (CVE Editor) wrote an open letter to several mailing lists regarding the nature of vulnerability statistics. What he said is spot on, and most of what I would have pointed out had my previous rant been more broad, and not a direct attack on a…

  • US-CERT: A Disgrace to Vulnerability Statistics

    [This was originally published on the OSVDB blog.] Several people have asked OSVDB about their thoughts on the recent US-CERT Cyber Security Bulletin 2005 Summary. Producing vulnerability statistics is trivial to do. All it takes is your favorite data set, a few queries, and off you go. Producing meaningful and useful vulnerability statistics is a…

  • SANS Top 20 Report Value

    [This was originally published on the OSVDB blog.] SANS has released their Top 20 Internet Security Vulnerabilities for 2005. Started in June 2000, “the SANS Institute and the National Infrastructure Protection Center (NIPC) at the FBI released a document summarizing the Ten Most Critical Internet Security Vulnerabilities”. The list was designed to help administrators tackle…

  • “OSS means slower patches” – huh?!

    [This was originally posted on the OSVDB blog.] http://australianit.news.com.au/articles/0,7204[..].htmlOSS means slower patchesChris JenkinsSEPTEMBER 19, 2005 This was posted to Full-Disclosure where I first replied, and ISN picked up. Articles like this do nothing positive for our industry. Jenkins should not waste his time writing fluff pieces like this, and he should do some digging or…

  • 600 Security Vulnerabilities in Q1 2005

    [This was originally published on the OSVDB blog.] http://www.betanews.com/article/600_Security_Vulnerabilities_in_Q1_2005/1115067858 600 Security Vulnerabilities in Q1 2005By Nate Mook, BetaNewsMay 2, 2005, 5:04 PM According to a study published Monday by the SANS Institute, more than 600 new security vulnerabilities cropped up in the first three months of 2005. Although Microsoft leads the top 20 most critical…

  • Random Comments on the Symantec Internet Threat Report 2005

    [Originally posted to the ISN Mail List. Shortly after, modified for attrition.org. This was republished at The Age (AU) and the Sydney Morning Herald.] Some interesting stuff in the Symantec report that is being talked about in various news articles:http://www.zdnet.com.au/news/security/0,2000061744,39185387,00.htmhttp://uk.news.yahoo.com/050322/152/ferr7.htmlhttp://continuitycentral.com/news01804.htmhttp://www.macobserver.com/article/2005/03/23.4.shtml[..] The original Symantec release for this report:http://enterprisesecurity.symantec.com/content.cfm?articleid=1539 Symantec Internet Security Threat ReportTrends for July 04…