Common Vulnerabilities and Exposures (CVE) System

owasp jsec cve details n.w
1 / 8
Embed
Share

Learn about the CVE system, which provides a method for documenting publicly known information security vulnerabilities and exposures. Explore examples and discover a cool tool for accessing the latest CVE details. Project timeline and future plans are also discussed.

  • Security
  • Vulnerabilities
  • Exposures
  • OWASP
  • Developer

Uploaded on | 0 Views


Download Presentation

Please find below an Image/Link to download the presentation.

The content on the website is provided AS IS for your information and personal use only. It may not be sold, licensed, or shared on other websites without obtaining consent from the author. If you encounter any issues during the download, it is possible that the publisher has removed the file from their server.

You are allowed to download the files provided on this website for personal or commercial use, subject to the condition that they are used lawfully. All files are the property of their respective owners.

The content on the website is provided AS IS for your information and personal use only. It may not be sold, licensed, or shared on other websites without obtaining consent from the author.

E N D

Presentation Transcript


  1. OWASP JSEC CVE DETAILS Dibyendu Sikdar (@dibsyhex) OSWAP Kolkata Chapter , Sillycon

  2. >>whoami Dibyendu Sikdar OpenSource Developer & Security Researcher Project Leader of OWASP JSEC DETAILS Acknowledged and listed in various Hall of Fame - AT&T , Microsoft, Oracle ,Adobe ,etc

  3. What is CVE ? CVE or The Common Vulnerabilities and Exposures system provides a reference method for publicly known information security vulnerabilities and exposures

  4. Example CVE-2014-5250 Details - Unspecified vulnerability in the AJAX autocompletion callback in the Biblio Autocomplete module 6.x-1.x before 6.x-1.1 and 7.x-1.x before 7.x-1.5 for Drupal allows remote attackers to access data via unspecified vectors.

  5. So what makes this tool cool? This desktop application can be used to fetch the latest CVEs directly from the CVE details online service cvedetails.com. Since this application is developed in Java it can be used to run on multiple platform.

  6. Screenshot

  7. Project Timeline 13 June 2014 - Released the project as open source 17 August 2014 - Requested for OWASP project approval 20 August 2014 - Project Proposal Accepted 21 August 2014 - To be released under OWASP Kolkata Chapter ,SillyCon

  8. Future Plans Fetch CVEs POCs from various websites Android Version Improved UI

More Related Content