|
|||||||||||||
|
NVD contains:
| 33101 | CVE Vulnerabilities |
| 132 | Checklists |
| 151 | US-CERT Alerts |
| 2271 | US-CERT Vuln Notes |
| 2097 | OVAL Queries |
Last updated: 10/10/08
CVE Publication rate:
18 vulnerabilities / dayNVD provides four mailing lists to the public. For information and subscription instructions please visit NVD Mailing Lists
NVD is a product of the NIST Computer Security Division and is sponsored by the Department of Homeland Security’s National Cyber Security Division. It supports the U.S. government multi-agency (OSD, DHS, NSA, DISA, and NIST) Information Security Automation Program. It is the U.S. government content repository for the Security Content Automation Protocol (SCAP).
| Element Name | Element Description | Attributes (required?) | Child Elements (# of occurences) |
| nvd | Root element. |
|
|
| entry | Root element for each CVE entry. |
|
|
| desc | Wrapper tag for all documented descriptions of this vulnerability. | None |
|
| descript | Contains a description of this vulnerability as published by the source indicated in the "source" attribute. Currently, the only description sources in NVD are CVE and NVD. |
|
|
| impacts | Wrapper tag for all documented impact explanations of this vulnerability. | None |
|
| impact | Contains an impact explanation of this vulnerability as published by the source indicated in the "source" attribute. Currently, the only impact explanation source in NVD is NVD. |
|
|
| sols | Wrapper tag for all documented solution explanations of this vulnerability. | None |
|
| sol | Contains a solution explanation of this vulnerability as published by the sourc indicated in the "source" attribute. Currently, the only solution explanation source in NVD is NVD. |
|
|
| loss_types | Wrapper tag for the types of loss that exploitation of this vulnerability can cause. Each child of this element represents a loss type that is specific to this vulnerability. | None | |
| avail | Indicates exploitation of this vulnerability can result in a loss of availability of the target (e.g. denial of service). | None | None |
| conf | Indicates exploitation of this vulnerability can result in compromised confidentiality on the target machine (e.g. information, data, or memory can be read from the target without appropriate credentials). | None | None |
| int | Indicates exploitation of this vulnerability can result in a loss of integrity on the target machine (e.g. information, data, or memory can be altered on the target machine without the proper credentials). | None | None |
| sec_prot | Indicates exploitation of this vulnerability can result in a loss of security protection on the target machine. This element's attributes describe the level of security protection that is lost. |
|
None |
| vuln_types | Wrapper tag for type descriptors that apply to this vulnerability | None | |
| access | Indicates that this vulnerability takes advantage of an access validation error. | None | None |
| input | Indicates that this vulnerability takes advantage of an input validation error. |
|
None |
| design | Indicates that this vulnerability takes advantage of a design error. | None | None |
| exception | Indicates that this vulnerability takes advantage of an exceptional condition error. | None | None |
| env | Indicates that this vulnerability takes advantage of an environmental error. | None | None |
| config | Indicates that this vulnerability takes advantage of a configuration error. | None | None |
| race | Indicates that this vulnerability takes advantage of a race condition error. | None | None |
| other | Indicates that this vulnerability takes advantage of some other error. | None | None |
| range | Wrapper tag for tags describing the attack range of this vulnerability. | None |
|
| local | Indicates that this vulnerability can be exploited by an attacker with local access to the machine. This includes remote terminal access through telnet, SSH, etc. | None | None |
| local_network | Indicates that this vulnerability can be exploited by an attacker with remote access within the local area network of the machine and the user is specifically not authenticated on the target machine. | None | None |
| network | Indicates that this vulnerability can be exploited by an attacker with remote access to the machine and is specifically not authenticated on the target machine. | None | None |
| user_init | Indicates that this vulnerability requires a user on the target computer to access the attacker (i.e. through clicking a malicious hyperlink). | None | None |
| refs | Wrapper tag for all documented references to this vulnerability. | None |
|
| ref | Contains information about a single reference to this vulnerability. |
|
|
| vuln_soft | Wrapper tag for a list of software products that are susceptible to this vulnerability. | None |
|
| prod | Names a product that is susceptible to this vulnerability and serves as a wrapper tag for the versions of this product that are specifically affected. |
|
|
| vers | Gives a version number of this product that is susceptible to this vulnerability. |
|
None |
Disclaimer Notice & Privacy Statement / Security Notice
Send comments or suggestions to nvd@nist.gov
NIST Computer Security Resource Center (CSRC)
NIST is an Agency of the U.S. Commerce Department
Full vulnerability listing