What is a CVE? (2024)

In 1999, MITRE Corporation, a US Government-funded research and development company, developed a uniform standard for reporting and tracking software security bugs named CVE, for Common Vulnerabilities and Exposures. Software bug reporting has come a long way since 1999, and today an organization named CVE.org oversees the CVE program.

CVE entries are brief. They don’t include technical data, or information about risks, impacts, and fixes. Those details appear in other databases, including the U.S. National Vulnerability Database (NVD), the CERT/CC Vulnerability Notes Database, and various lists maintained by vendors and other organizations.

Across these different systems, CVE IDs give users a reliable way to recognize unique vulnerabilities and coordinate the development of security tools and solutions. The MITRE corporation maintains the CVE List, but a security flaw that becomes a CVE entry is often submitted by organizations and members of the open source community.

About CVE identifiers

CVE identifiers areassigned by a CVE Numbering Authority (CNA). There areabout 100 CNAs, representing major IT vendors—such as Red Hat, IBM, Cisco, Oracle, and Microsoft—as well as security companies and research organizations.MITRE can also issue CVEs directly.

CNAs are issued blocks of CVEs, which are held in reserve to attach to new issues asthey are discovered. Thousands of CVE IDs are issued every year. A single complex product, such as an operating system, can accumulate hundreds of CVEs.

CVE reports can come from anywhere. A vendor, a researcher, or just an astute user can discover a flaw and bring it to someone’s attention. Many vendors offerbug bounties to encourage responsible disclosure of security issues. If you find a vulnerability in open source software you should submit it to the community.

One way or another, information about the flaw makes its way to a CNA. The CNA assigns the information a CVE ID, and writes a brief description and includes references. Then the new CVE is posted on the CVE website.

Often, a CVE ID is assigned before a security advisoryis made public. It’s common for vendors to keep security flaws secret until a fix has been developed and tested. That reduces opportunities for attackers toexploitunpatched flaws.

Once made public, a CVE entry includes the CVE ID (in the format "CVE-2019-1234567"), a brief description of the security vulnerability or exposure, and references, which can include links to vulnerability reports and advisories.

What is a CVE? (2024)
Top Articles
Optimal Number of Credit Cards: How Many Should You Have?
The Health Benefits of IV Drip Treatments
Jail Inquiry | Polk County Sheriff's Office
Cintas Pay Bill
Booknet.com Contract Marriage 2
50 Meowbahh Fun Facts: Net Worth, Age, Birthday, Face Reveal, YouTube Earnings, Girlfriend, Doxxed, Discord, Fanart, TikTok, Instagram, Etc
Mustangps.instructure
Achivr Visb Verizon
Optum Medicare Support
Devourer Of Gods Resprite
Catsweb Tx State
Los Angeles Craigs List
Craigslist Pets Athens Ohio
Erskine Plus Portal
Mile Split Fl
Rachel Griffin Bikini
De beste uitvaartdiensten die goede rituele diensten aanbieden voor de laatste rituelen
bode - Bode frequency response of dynamic system
Hyvee Workday
Fsga Golf
Busted Mcpherson Newspaper
Anotherdeadfairy
Costco Gas Hours St Cloud Mn
Inbanithi Age
Обзор Joxi: Что это такое? Отзывы, аналоги, сайт и инструкции | APS
Cal State Fullerton Titan Online
Times Narcos Lied To You About What Really Happened - Grunge
WOODSTOCK CELEBRATES 50 YEARS WITH COMPREHENSIVE 38-CD DELUXE BOXED SET | Rhino
Boneyard Barbers
Autozone Locations Near Me
RALEY MEDICAL | Oklahoma Department of Rehabilitation Services
Cal Poly 2027 College Confidential
How much does Painttool SAI costs?
Gateway Bible Passage Lookup
Devon Lannigan Obituary
Walmart Car Service Near Me
Mudfin Village Wow
How I Passed the AZ-900 Microsoft Azure Fundamentals Exam
Bmp 202 Blue Round Pill
Tropical Smoothie Address
25 Hotels TRULY CLOSEST to Woollett Aquatics Center, Irvine, CA
Scott Surratt Salary
Quest Diagnostics Mt Morris Appointment
Craigslist Sarasota Free Stuff
Solving Quadratics All Methods Worksheet Answers
Diamond Spikes Worth Aj
sin city jili
Southwind Village, Southend Village, Southwood Village, Supervision Of Alcohol Sales In Church And Village Halls
2121 Gateway Point
Att Corporate Store Location
Latest Posts
Article information

Author: Mrs. Angelic Larkin

Last Updated:

Views: 5770

Rating: 4.7 / 5 (67 voted)

Reviews: 90% of readers found this page helpful

Author information

Name: Mrs. Angelic Larkin

Birthday: 1992-06-28

Address: Apt. 413 8275 Mueller Overpass, South Magnolia, IA 99527-6023

Phone: +6824704719725

Job: District Real-Estate Facilitator

Hobby: Letterboxing, Vacation, Poi, Homebrewing, Mountain biking, Slacklining, Cabaret

Introduction: My name is Mrs. Angelic Larkin, I am a cute, charming, funny, determined, inexpensive, joyous, cheerful person who loves writing and wants to share my knowledge and understanding with you.