| ▲ | SAI_Peregrinus 2 hours ago | ||||||||||||||||
Tautologically every bug can legitimately be assigned a CVE, since every bug prevents some feature from working as intended. It's therefore a denial of service, which by the definition of the CVE system using CVSS means every bug is at least a 1/Low level vulnerability to CVSS v4.0. If you're willing to stretch, missing but planned features also deny the use of said features since they haven't been added yet, and so are CVSS 1/Low vulnerabilities. Resume-driven development for security researchers has never been easier! | |||||||||||||||||
| ▲ | viraptor an hour ago | parent [-] | ||||||||||||||||
> It's therefore a denial of service That doesn't follow. In the extremely simple example, an adding service returning 1+1=3 has a bug, but it's not a possible DoS situation at all. > missing but planned features also deny the use of said features That's not what DoS is. This whole situation with CVE assigning comes from the whole process being far from ideal. But it doesn't mean it's completely useless and doesn't follow any rules at all. | |||||||||||||||||
| |||||||||||||||||