Hacker News new | ask | show | jobs
by viraptor 3537 days ago
You could probably pull that data out of the CVE reports. Just need to map versions and patch releases to specific dates for calculations.
2 comments

You could, and you'd add your name to the long list of people creating bad statistics about CVEs.

See this talk: https://www.youtube.com/watch?v=3Sx0uJGRQ4s

I don't think it would be possible; one of the interesting parts of the article's graph is the 'creation time' of the vulnerability, but there's no corresponding public data for Windows vulnerabilities.
Yes, the granularity of the start date would be closer to 2y periods. (Major windows versions affected)