[a / b / c / d / e / f / g / gif / h / hr / k / m / o / p / s / t / u / v / vg / vm / vmg / vr / vrpg / vst / w / wg] [i / ic] [r9k / s4s / vip] [cm / hm / lgbt / y] [3 / aco / adv / an / bant / biz / cgl / ck / co / diy / fa / fit / gd / hc / his / int / jp / lit / mlp / mu / n / news / out / po / pol / pw / qst / sci / soc / sp / tg / toy / trv / tv / vp / vt / wsg / wsr / x / xs] [Settings] [Search] [Mobile] [Home]
Board
Settings Mobile Home
/g/ - Technology

Name
Options
Comment
Verification
4chan Pass users can bypass this verification. [Learn More] [Login]
File
  • Please read the Rules and FAQ before posting.
  • You may highlight syntax and preserve whitespace by using [code] tags.

08/21/20New boards added: /vrpg/, /vmg/, /vst/ and /vm/
05/04/17New trial board added: /bant/ - International/Random
10/04/16New board for 4chan Pass users: /vip/ - Very Important Posts
[Hide] [Show All]


Janitor acceptance emails will be sent out over the coming weeks. Make sure to check your spam folder!


[Advertise on 4chan]


File: graph.png (26 KB, 947x437)
26 KB PNG
"CopyFail" root access bug (CVE-2026-31431) had a severity score of 7.8 and they made a big deal out of it.

So I downloaded all the CVEs, dropped all except 2025-2026, put them in severity score version bins, dropped ones below median from both, and put them in weekly stacks.

Median ended up being near 7.0 in both so these are all more serious than level 7.


There is no peak around Mythos and Project Glasswing, just slow and steady rising from 300-400 weeklies of 2025 to current 800-900 weeklies over the course of 6 months.

Is this like Richter scale so that there's a huge difference between 7.0 and 7.8 or have they actually started making software safe and cozy like for real, in 2026?
>>
So basically CVE just means it's a flaw in software. It doesn't even have to be security related.

There's no standard with this shit and it's all muddied, but .gov is generally what you want
>>
people report cves to pad their cvs or to get paid. meaning, it's either famous free/open source software (ffmpeg, sqlite, firefox etc) or stuff that pays "well" (microsoft products, google etc). a software having 0 cves doesn't mean it's secure, it just means there's no reward to reporting vulnerabilities in it

cves got attention mostly because it's a way for it department to say "you can't use x software" or to try to get developers (and sometimes ops) to update their shit



[Advertise on 4chan]

Delete Post: [File Only] Style:
[Disable Mobile View / Use Desktop Site]

[Enable Mobile View / Use Mobile Site]

All trademarks and copyrights on this page are owned by their respective parties. Images uploaded are the responsibility of the Poster. Comments are owned by the Poster.