· @postmodern
901 followers · 685 posts · Server infosec.exchange

It appears you can request CVEs incrementally using startIndex and resultsPerPage, however I suspect this is much slower than downloading the per-year NVD JSON Feeds.

There is also the experimental/pilot cvelist git repo which puts the entire NVD data-set into a git repo as JSON files (Ruby client code: cvelist.rb).

#nvd #cvelist

Last updated 2 years ago

· @postmodern
901 followers · 683 posts · Server infosec.exchange

TIL on September 2023 NVD will shutdown their JSON Feeds in favor of their own REST API. While I generally prefer REST, I kind of like the idea of being able to import all of their data into whatever database or schema I want to use and query it as much as I like. Although, I bet this gets abused by companies and NIST is looking to monetize the commercial demand for their data.
nvd.nist.gov/General/News/chan

#nvd

Last updated 2 years ago

· @postmodern
901 followers · 678 posts · Server infosec.exchange

When will the NVD offer .xz compressed feeds?

#nvd #xz

Last updated 2 years ago

Gustav H Meyer · @inetpro
109 followers · 520 posts · Server infosec.exchange

Another unambiguous write up by Daniel Stenberg and very nice to learn some more about the subjective nature of the CVSS scores and how it all fits together.

How do we get the NVD to stop the insanity?

[...] In the curl project we decided to abandon CVSS years ago because of its inherent problems. Instead we use only the four severity names: Low, Medium, High, and Critical [...] I have talked to humans on the GitHub database team and I push for them to ignore or filter out the severity levels as set by NVD, if possible. But me being just a single complaining maintainer I do not expect this to have much of an effect. I would urge NVD to stop this insanity if I had any way to. [...]

daniel.haxx.se/blog/2023/03/06

#cvss #nvd #cve #mitre #vulnerabilitymanagement

Last updated 2 years ago

VulDB :verified: · @vuldb
119 followers · 224 posts · Server infosec.exchange

[Hint] You want to publish a new vulnerability? Just submit and we will handle your CVE assignment in no time. vuldb.com/?id.add

#vuldb #CNA #cve #mitre #nvd

Last updated 2 years ago

surendra · @surendra
1 followers · 8 posts · Server mastodon.world
VulnCheck · @vulncheck
13 followers · 8 posts · Server infosec.exchange

Dark Reading details our latest research revealing how the differences in the National Vulnerability Database () and vendors score bugs can make patch prioritization more challenging. Read the full article below to learn more: darkreading.com/application-se

#nvd #vulnerabilitymanagement

Last updated 2 years ago

VulDB :verified: · @vuldb
56 followers · 30 posts · Server infosec.exchange

[Hint] You have discovered a new vulnerability? Submit it here and we will assign a CVE in no time. vuldb.com/?id.add

#vuldb #CNA #cve #mitre #nvd

Last updated 2 years ago

Tod Beardsley 🏴‍☠️ · @todb
1036 followers · 821 posts · Server infosec.exchange

@DarkOperator minor point of fact, FTA:

the National Vulnerability Database assigned Common Vulnerabilities and Exposures (CVE) identifiers to over 12,000 vulnerabilities

I assure you, the did not assign 12,000 CVEs. Most CVEs are assigned by the Program, and the rest are assigned by CVE partners (CNAs), which is not part of NVD.

NVD merely provides commentary on, and republishes, CVEs.

#nvd #cve

Last updated 2 years ago

Being sick at home means that you have a lot of time and can devote yourself to things that you would otherwise like to put off.

And so, while analyzing some failures in our CI pipeline, I found out that apparently will no longer make the database available offline, but only via a new version of their API.

nvd.nist.gov/General/News/chan

This will make it much harder to include NVD data because this approach doesn't scale, let alone builds that lack access to external resources.

#devops #nvd #nist

Last updated 2 years ago

Ólavur Ellefsen · @olavur
210 followers · 196 posts · Server e.fo

Fríggjadagin 18. november klokkan 14:30 verður alment tiltak og móttøka í Kongshøll á Vestaru bryggju í Havn í sambandi við, at Náttúruvísindadeildin á Fróðskaparsetri Føroya fyllir 50 ár
setur.fo/fo/setrid/tiltok/alme

#setrið #tiltøk #nvd

Last updated 2 years ago