The Secret Life of CVEs

Fuente: arXiv
Gespeichert in:
Bibliographische Detailangaben
Hauptverfasser: Przymus, Piotr, Fejzer, Mikołaj, Narębski, Jakub, Stencel, Krzysztof
Format: Preprint
Veröffentlicht: 2025
Schlagworte:
Online-Zugang:
Tags: Tag hinzufügen
Keine Tags, Fügen Sie den ersten Tag hinzu!
_version_ 1866912310737502208
author Przymus, Piotr
Fejzer, Mikołaj
Narębski, Jakub
Stencel, Krzysztof
author_facet Przymus, Piotr
Fejzer, Mikołaj
Narębski, Jakub
Stencel, Krzysztof
contents The Common Vulnerabilities and Exposures (CVEs) system is a reference method for documenting publicly known information security weaknesses and exposures. This paper presents a study of the lifetime of CVEs in software projects and the risk factors affecting their existence. The study uses survival analysis to examine how features of programming languages, projects, and CVEs themselves impact the lifetime of CVEs. We suggest avenues for future research to investigate the effect of various factors on the resolution of vulnerabilities.
format Preprint
id arxiv_https___arxiv_org_abs_2504_03863
institution arXiv
publishDate 2025
record_format arxiv
spellingShingle The Secret Life of CVEs
Przymus, Piotr
Fejzer, Mikołaj
Narębski, Jakub
Stencel, Krzysztof
Cryptography and Security
Software Engineering
The Common Vulnerabilities and Exposures (CVEs) system is a reference method for documenting publicly known information security weaknesses and exposures. This paper presents a study of the lifetime of CVEs in software projects and the risk factors affecting their existence. The study uses survival analysis to examine how features of programming languages, projects, and CVEs themselves impact the lifetime of CVEs. We suggest avenues for future research to investigate the effect of various factors on the resolution of vulnerabilities.
title The Secret Life of CVEs
topic Cryptography and Security
Software Engineering
url https://arxiv.org/abs/2504.03863