4 ms·
Comparing CVE counts is a bit nonsensical. For instance, Chrome and Firefox don't individually assign CVEs for internally reported vulnerabilities. For instanc
by mccr8 4y ago
Comparing CVE counts is a bit nonsensical. For instance, Chrome and Firefox don't individually assign CVEs for internally reported vulnerabilities.
For instance, in these patch notes Chrome lists "Various fixes from internal audits, fuzzing and other initiatives" and doesn't even look to have a CVE:
https://chromereleases.googleblog.com/2022/05/stable-channel-update-for-desktop_24.html https://chromereleases.googleblog.com/2022/05/stable-channel...
Or for Firefox, there's a dozen or so bundled together in a single CVE under "Memory safety bugs fixed in Firefox 101":
https://www.mozilla.org/en-US/security/advisories/mfsa2022-20/ https://www.mozilla.org/en-US/security/advisories/mfsa2022-2...
- capableweb 4y agoI agree, measuring "security" by counting CVE counts is a bit like measuring developer productivity by counting git commits, it simply doesn't make sense. But in the grand schema of things, who cares how many CVEs a project has, when it can take almost 2 months for the project to ship updates fixing exploits that happen in the wild already? That's just out of control and unbelievable.
- LMYahooTFY 4y agoI seem to remember the CVE database search utility on Mitre's web site stating something along the lines of "comparing the number of CVEs by platform shouldn't be used to draw conclusions". Possibly a CYA-esque liability statement, but the principle seemed sound.
- coryfklein 4y agoAnd do we have reason to believe the vulnerability/CVE process for Safari is different from Chrome or Firefox?