CVE Home

NOTICE: You are viewing an ARCHIVE of the old CVE website. This is available for historical purposes ONLY. All the content is obsolete. The current website is CVE.ORG .

Get CVE
CVE Home
About CVE
News and Events
Compatible Products
Editorial Board
Advisory Council
Press View
Free Newsletters
contact us
Alphabetical Index

CVE in Use

As the international industry standard for information security vulnerability and exposure names, CVE Identifiers are included in numerous products and services and are the foundation of others. CVE also helps in Making Security Measurable .

corner corner
corner corner

CVE-COMPATIBLE PRODUCTS

Use of CVE-IDs enhances these areas of enterprise security:

Sponsor : NSCD

National Vulnerability Database

National Vulnerability Database (NVD) provides:

Sponsor : NSCD

corner corner corner corner
corner corner

GOVERNMENT

US-CERT Bulletins

Uses CVE-IDs to uniquely identify the vulnerabilities they report.

Sponsor : NSCD

U.S. Government Agencies

National Institute of Standards and Technology (NIST) recommends use of CVE by U.S. agencies in two 2002 Special Publications: " 800-51: Use of the Common Vulnerabilities and Exposures (CVE) Vulnerability Naming Scheme" & "800-40: Procedures for Handling Security Patches. "

Sponsor : NSCD

DoD Contracts

U.S. Defense Information Systems Agency (DISA) issued a task order in June 2004 for information assurance applications for the Department of Defense (DoD) that requires the use of products that use CVE-IDs.

corner corner
corner corner

COMMUNITY

SANS Top 20 Most Critical Internet Security Vulnerabilities

Uses CVE-IDs to uniquely identify the vulnerabilities it describes.

OWASP Top 10 Web Application Security Issues

Derived from CVE vulnerability trends, the 2007 edition also includes CVE-IDs to identify examples of the vulnerabilities described.

Common Weakness Enumeration (CWE™)

A formal dictionary of software weaknesses types, CWE is based in part on the CVE List.

Sponsor : NSCD

Open Vulnerability and Assessment Language (OVAL®)

A standard for determining vulnerability and configuration issues on computer systems, CVE-IDs are the primary references for "OVAL Vulnerability Definitions," which test systems for the presence of CVEs.

Sponsor : NSCD

corner corner