4 ms·
Depends on the situation, which is why CVE also have a CVSS score explaining the context and potential for abuse, e.g. : https://msrc.microsoft.com/update-guide
by luch 5y ago
Depends on the situation, which is why CVE also have a CVSS score explaining the context and potential for abuse, e.g. : https://msrc.microsoft.com/update-guide/vulnerability/CVE-2021-26855 https://msrc.microsoft.com/update-guide/vulnerability/CVE-20...
For example an arbitrary computation is useless for browser exploits (unless you think arb. bitcoin mining is a problem) since Javascript already gives you it for free but it is highly problematic for smart contracts since it breaks the economy based on it.
Another example would be data leak vulnerabilities which on some cases be only a stepping stone towards a RCE, but on others scenarios like for Heartbleed basically breaks the Internet's overall security.