TE
TechEcho
Home24h TopNewestBestAskShowJobs
GitHubTwitter
Home

TechEcho

A tech news platform built with Next.js, providing global tech news and discussions.

GitHubTwitter

Home

HomeNewestBestAskShowJobs

Resources

HackerNews APIOriginal HackerNewsNext.js

© 2025 TechEcho. All rights reserved.

NVD Makes Up Vulnerability Severity Levels

12 pointsby ghuntleyabout 2 years ago

1 comment

ericpauleyabout 2 years ago
Interesting! I do think NVD’s approach makes sense in some ways. NVD is useful for long-term and longitudinal studies of CVE trends. To achieve this, the scores should be as consistent as possible. Curl is probably an outlier in their intellectually honest treatment of vulnerabilities, with commercial software vendors potentially downplaying severity.<p>I’m not sure I agree with the specific CVE example, though. Admittedly without any context, isn’t the short window not material if the adversary can reproduce the vulnerability locally and find an input to exploit it? Processing by curl server side would usually be non-interactive to the client.
评论 #35042069 未加载