| ▲ | embedding-shape 2 hours ago | |||||||
"Several" feels a bit of an understatement, there are 1313 CVEs listed on that page! Wonder how many of these NSA and others been sitting on, for how long and how many are still there? I guess the silver lining with the aixplosion of CVEs is that software eventually will get more secure. | ||||||||
| ▲ | SchemaLoad 2 hours ago | parent | next [-] | |||||||
Something to keep in mind is the Linux project registered as an authority to create their own CVE numbers in 2024. Previously the majority of bugs would just be fixed without note unless there was a demonstration that it could be exploited. Now they just give almost every bug a CVE number. | ||||||||
| ▲ | crispr245 an hour ago | parent | prev | next [-] | |||||||
NSA allegedly used to have a "black budget" of around a couple dozen million dollars for software sabotaging. I wonder what percentage of those CVEs could be related to it... | ||||||||
| ||||||||
| ▲ | vdfs 2 hours ago | parent | prev [-] | |||||||
Any kernel bug gets a CVE even if it's not really a vulnerability or can be exploited | ||||||||