Score: 0

The Secret Life of CVEs

Published: April 4, 2025 | arXiv ID: 2504.03863v1

By: Piotr Przymus , Mikołaj Fejzer , Jakub Narębski and more

Potential Business Impact:

Finds ways to fix computer security problems faster.

Business Areas:
Penetration Testing Information Technology, Privacy and Security

The Common Vulnerabilities and Exposures (CVEs) system is a reference method for documenting publicly known information security weaknesses and exposures. This paper presents a study of the lifetime of CVEs in software projects and the risk factors affecting their existence. The study uses survival analysis to examine how features of programming languages, projects, and CVEs themselves impact the lifetime of CVEs. We suggest avenues for future research to investigate the effect of various factors on the resolution of vulnerabilities.

Page Count
5 pages

Category
Computer Science:
Cryptography and Security