Hacker Newsnew | past | comments | ask | show | jobs | submitlogin

Thanks for volunteering to manage the "300-600 CVEs each month"!

The world needs more volunteers like you.



Make that 3,000-4,000 on average per month, according to NISTs stats on CVEs for last year. ~40,000 for 2024.


I imagine most of those CVEs not being anything meaningful and just script kiddies trying to put something on their portfolio

all the meaningful ones will show up on HN


You manage the system and not the CVEs themselves. The simplist thing would be a list of numbers that correspond to Google docs. The owner of the Google doc can share it with the needed parties and eventually set it as public.


You truly believe that the CVE database (and others like CWE) are only about assigning serial numbers to random reports, don't you? I see people underestimating and understanding the work of others in matters like this. Is that a trend now?


I saw this same behavior quite a while back. While I'm out of the CVE game these days, it seems that there is a forever rotating new group of people who simply don't and can never see the complexities on the process.

I think it's a testament to the previous stewardship that it appears so simple.


No I don't believe that, but it might as well operate like that. The extra stuff isn't truly needed and was being outsourced to the companies that own the products since it wasn't providing much value. Take a look at Daniel's blog posts about CVEs for curl for what happens when you let them handle it.




Guidelines | FAQ | Lists | API | Security | Legal | Apply to YC | Contact

Search: