Hacker News new | ask | show | jobs
by netsec_burn 2160 days ago
What about CVE+CPE? The NIST NVD provides a CVE+CPE API for your machine readable format, and CVE's are collected by MITRE.
1 comments

Yes, but which open source project publishes CPEs for their vulnerability information? :-) Plus, an important part of every security advisory is specifying which versions are affected by a particular vulnerability versus which contain the fix and are thus no longer affected.