<?xml version="1.0"?>
<feed xmlns="http://www.w3.org/2005/Atom" xml:lang="en">
	<id>http://debianws.lexgopc.com/wiki143/index.php?action=history&amp;feed=atom&amp;title=National_Vulnerability_Database</id>
	<title>National Vulnerability Database - Revision history</title>
	<link rel="self" type="application/atom+xml" href="http://debianws.lexgopc.com/wiki143/index.php?action=history&amp;feed=atom&amp;title=National_Vulnerability_Database"/>
	<link rel="alternate" type="text/html" href="http://debianws.lexgopc.com/wiki143/index.php?title=National_Vulnerability_Database&amp;action=history"/>
	<updated>2026-06-10T01:13:59Z</updated>
	<subtitle>Revision history for this page on the wiki</subtitle>
	<generator>MediaWiki 1.43.1</generator>
	<entry>
		<id>http://debianws.lexgopc.com/wiki143/index.php?title=National_Vulnerability_Database&amp;diff=5643388&amp;oldid=prev</id>
		<title>imported&gt;WikiCleanerBot: v2.05b - Bot T20 CW#61 - Fix errors for CW project (Reference before punctuation)</title>
		<link rel="alternate" type="text/html" href="http://debianws.lexgopc.com/wiki143/index.php?title=National_Vulnerability_Database&amp;diff=5643388&amp;oldid=prev"/>
		<updated>2025-06-28T07:24:37Z</updated>

		<summary type="html">&lt;p&gt;v2.05b - &lt;a href=&quot;/wiki143/index.php?title=User:WikiCleanerBot&amp;amp;action=edit&amp;amp;redlink=1&quot; class=&quot;new&quot; title=&quot;User:WikiCleanerBot (page does not exist)&quot;&gt;Bot T20 CW#61&lt;/a&gt; - Fix errors for &lt;a href=&quot;/wiki143/index.php?title=WP:WCW&amp;amp;action=edit&amp;amp;redlink=1&quot; class=&quot;new&quot; title=&quot;WP:WCW (page does not exist)&quot;&gt;CW project&lt;/a&gt; (Reference before punctuation)&lt;/p&gt;
&lt;p&gt;&lt;b&gt;New page&lt;/b&gt;&lt;/p&gt;&lt;div&gt;{{Short description|American government data repository}}&lt;br /&gt;
The &amp;#039;&amp;#039;&amp;#039;National Vulnerability Database&amp;#039;&amp;#039;&amp;#039; (&amp;#039;&amp;#039;&amp;#039;NVD&amp;#039;&amp;#039;&amp;#039;) is the U.S. government repository of standards-based vulnerability management data represented using the [[Security Content Automation Protocol]] (SCAP). This data enables automation of vulnerability management, security measurement, and compliance. NVD includes databases of security checklists, security related software flaws, misconfigurations, product names, and impact metrics. NVD supports the [[Information Security Automation Program]] (ISAP). NVD is managed by the U.S. government agency the [[National Institute of Standards and Technology]] (NIST).&lt;br /&gt;
&lt;br /&gt;
On Friday March 8, 2013, the database was taken offline after it was discovered that the system used to run multiple government sites had been compromised by a software vulnerability of [[Adobe ColdFusion]].&amp;lt;ref&amp;gt;{{Cite web|url=https://www.theregister.co.uk/2013/03/14/adobe_coldfusion_vulns_compromise_us_malware_catalog/|title=Downed US vuln catalog infected for at least TWO MONTHS|last=at 17:55|first=Jack Clark in San Francisco 14 Mar 2013|website=www.theregister.co.uk|language=en|access-date=2019-10-29}}&amp;lt;/ref&amp;gt;&amp;lt;ref&amp;gt;[https://www.theregister.co.uk/2013/03/14/us_malware_catalogue_hacked/ &amp;quot;US national vulnerability database hacked.&amp;quot;]&amp;lt;/ref&amp;gt;&lt;br /&gt;
&lt;br /&gt;
The vulnerabilities in the NVD originate from the [[Common Vulnerabilities and Exposures]] (CVE) list, maintained by [[MITRE]]. New vulnerabilities are assigned by MITRE and CVE Numbering Authorities and subsequently added to the NVD.&amp;lt;ref&amp;gt;{{cite web |author1=NIST |author1-link=National Institute of Standards and Technology |title=CVEs and the NVD Process |url=https://nvd.nist.gov/general/cve-process |website=nvd.nist.gov}}&amp;lt;/ref&amp;gt;&lt;br /&gt;
&lt;br /&gt;
==CVE Enrichment==&lt;br /&gt;
When vulnerabilities are added to the list of [[Common Vulnerabilities and Exposures]] (CVEs), the NVD assigns them a score using the [[Common Vulnerability Scoring System|Common Vulnerability Scoring System (CVSS)]].&amp;lt;ref name=&amp;quot;:1&amp;quot;&amp;gt;{{cite news |last1=Townsend |first1=Kevin |title=CVE and NVD – A Weak and Fractured Source of Vulnerability Truth |url=https://www.securityweek.com/cve-and-nvd-a-weak-and-fractured-source-of-vulnerability-truth/ |access-date=28 May 2025 |work=SecurityWeek |date=3 April 2024}}&amp;lt;/ref&amp;gt;&amp;lt;ref&amp;gt;{{Cite journal |last1=Zhang |first1=Su |last2=Ou |first2=Xinming |last3=Caragea |first3=Doina |date=2015-12-31 |title=Predicting Cyber Risks through National Vulnerability Database |url=http://www.tandfonline.com/doi/full/10.1080/19393555.2015.1111961 |journal=Information Security Journal: A Global Perspective |language=en |volume=24 |issue=4–6 |pages=194–206 |doi=10.1080/19393555.2015.1111961 |s2cid=30587194 |issn=1939-3555|url-access=subscription }}&amp;lt;/ref&amp;gt; This score is based on metrics such as access complexity and potential impact,&amp;lt;ref&amp;gt;{{cite web |url=http://nvd.nist.gov/cvsseq2.htm |title=NVD - CVSS v2 Equations |website=nvd.nist.gov |archive-url=https://web.archive.org/web/20131221044001/http://nvd.nist.gov/cvsseq2.htm |archive-date=2013-12-21 |url-status=dead }}&amp;lt;/ref&amp;gt; allowing organizations to prioritize remediation efforts depending on the severity.&amp;lt;ref name=&amp;quot;:1&amp;quot; /&amp;gt;&lt;br /&gt;
&lt;br /&gt;
In June 2017, threat intel firm [[Recorded Future]] revealed that the median lag between a CVE being revealed to ultimately being published to the NVD is 7 days and that 75% of vulnerabilities are published unofficially before making it to the NVD, giving attackers time to exploit the vulnerability.&amp;lt;ref&amp;gt;{{Cite web|url=https://www.darkreading.com/vulnerabilities---threats/75--of-vulns-shared-online-before-nvd-publication/d/d-id/1329066|title=75% of Vulns Shared Online Before NVD Publication|website=Dark Reading|date=7 June 2017 |language=en|access-date=2019-10-29}}&amp;lt;/ref&amp;gt;&lt;br /&gt;
&lt;br /&gt;
In August 2023, the NVD initially marked an integer overflow bug in old versions of [[cURL]] as a 9.8 out of 10 critical vulnerability. cURL lead developer [[Daniel Stenberg]] responded by saying this was not a security problem, the bug had been patched nearly 4 years prior, requested the CVE be rejected, and accused NVD of &amp;quot;scaremongering&amp;quot; and &amp;quot;grossly inflating the severity level of issues&amp;quot;.&amp;lt;ref&amp;gt;{{cite web|last=Stenberg|first=Daniel|title=CVE-2020-19909 is everything that is wrong with CVEs|url=https://daniel.haxx.se/blog/2023/08/26/cve-2020-19909-is-everything-that-is-wrong-with-cves/|date=26 August 2023|website=Daniel Stenberg&amp;#039;s Blog|access-date=2023-08-26}}&amp;lt;/ref&amp;gt; MITRE disagreed with Stenberg and denied his request to reject the CVE, noting that &amp;quot;there is a valid weakness ... which can lead to a valid security impact.&amp;quot;&amp;lt;ref&amp;gt;{{Cite web |title=curl - Bogus report filed by anonymous - CVE-2020-19909 |url=https://curl.se/docs/CVE-2020-19909.html |access-date=2023-08-31 |website=curl.se}}&amp;lt;/ref&amp;gt;&lt;br /&gt;
In September 2023, the issue was rescored by the NVD as a 3.3 &amp;quot;low&amp;quot; vulnerability, stating that &amp;quot;it may (in theory) cause a denial of service&amp;quot; for attacked systems, but that this attack vector &amp;quot;is not especially plausible&amp;quot;.&amp;lt;ref&amp;gt;{{Cite web |title=NVD - CVE-2020-19909 |url=https://nvd.nist.gov/vuln/detail/CVE-2020-19909 |access-date=2023-09-07 |website=nvd.nist.gov|archive-url=https://web.archive.org/web/20230905213507/https://nvd.nist.gov/vuln/detail/CVE-2020-19909|archive-date=2023-09-05}}&amp;lt;/ref&amp;gt;&lt;br /&gt;
&lt;br /&gt;
==See also==&lt;br /&gt;
*[[Common Vulnerabilities and Exposures]]&lt;br /&gt;
*[[Common Weakness Enumeration]]&lt;br /&gt;
*[[European Union Vulnerability Database]]&lt;br /&gt;
*[[Software composition analysis]]&lt;br /&gt;
&lt;br /&gt;
== References ==&lt;br /&gt;
{{reflist|30em}}&lt;br /&gt;
&lt;br /&gt;
==External links==&lt;br /&gt;
* {{Official website|https://nvd.nist.gov/}}&lt;br /&gt;
*[https://csrc.nist.gov/projects/security-content-automation-protocol/ Security Content Automation Protocol (SCAP)]&lt;br /&gt;
*[https://packetstormsecurity.com/ Packet Storm]&lt;br /&gt;
*[https://www.exploit-db.com/ Exploit Database]&lt;br /&gt;
* [https://vulners.com/ Security Content Database]&lt;br /&gt;
&lt;br /&gt;
[[Category:Government databases in the United States]]&lt;br /&gt;
[[Category:Security vulnerability databases]]&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
{{US-gov-stub}}&lt;/div&gt;</summary>
		<author><name>imported&gt;WikiCleanerBot</name></author>
	</entry>
</feed>