The Common Vulnerabilities and Exposures (CVE) Initiative

Abstract

Common Vulnerabilities and Exposures (CVE) is an international, community-based effort, including industry, government, and academia, that is working to create an organizing mechanism to make identifying, finding, and fixing software product vulnerabilities more rapid and efficient. A few years ago, each of us was faced with a cacophony of naming methods for defining individual security problems in software. This made it difficult to assess, manage, and fix vulnerabilities and exposures when using the various vulnerability services, tools, and databases along with the software suppliers' update announcements and alerts. For example, Table 1 shows how in 1998 each of a dozen leading organizations used different names to refer to the same well-known vulnerability in the phf phonebook CGI program. Such confusion made it hard to understand which vulnerabilities an organization faced and which ones each tool was looking for (or not looking for). Then, to get the fix to the identified vulnerability, users still had to figure out what name the vulnerability or exposure was assigned by their software supplier.

Open PDF

Document Details

Document Type
Technical Report
Publication Date
Jun 01, 2002
Accession Number
AD1125343

Entities

People

  • David Baker
  • Robert Martin
  • Steven Christey

Organizations

  • MITRE Corporation

Tags

Communities of Interest

  • Human Systems

DTIC Thesaurus Topics

  • Commerce
  • Communities
  • Computer Network Security
  • Computer Program Documentation
  • Computer Programs
  • Computers
  • Databases
  • Detection
  • Education
  • Electronic Commerce
  • Feedback
  • Governments
  • Information Exchange
  • Information Retrieval
  • Information Security
  • Information Systems
  • Intrusion Detection
  • Intrusion Detection Systems
  • Intrusion Detectors
  • Malware
  • Network Computing
  • Networks
  • Operating Systems
  • Security
  • Systems Engineering
  • Test Methods
  • Training
  • Vulnerability
  • Websites

Readers

  • Cybersecurity.
  • Database Systems and Applications
  • Educational Psychology