vix.ing · top · new · best · stats · spec

The (Un)Reliability of NVD Vulnerable Versions Data: an Empirical Experiment on Google Chrome Vulnerabilities

2013/02/17 by Viet Hung Nguyen, Nguyen, Viet Hung, Fabio Massacci +2 · 2 citations
Computer Science · #Cryptography and Security (cs.CR) #FOS: Computer and information sciences #Software Reliability and Analysis Research #Spam and Phishing Detection #Web Application Security Vulnerabilities #cs.CR

paper · pdf · doi:10.48550/arxiv.1302.4133

arxiv created 2013/02/17 · openalex publication_date 2013/02/17 · arxiv updated 2013/02/19 · openalex created_date 2025/10/10 · openalex updated_date 2026/07/28

Abstract

NVD is one of the most popular databases used by researchers to conduct empirical research on data sets of vulnerabilities. Our recent analysis on Chrome vulnerability data reported by NVD has revealed an abnormally phenomenon in the data where almost vulnerabilities were originated from the first versions. This inspires our experiment to validate the reliability of the NVD vulnerable version data. In this experiment, we verify for each version of Chrome that NVD claims vulnerable is actually vulnerable. The experiment revealed several errors in the vulnerability data of Chrome. Furthermore, we have also analyzed how these errors might impact the conclusions of an empirical study on foundational vulnerability. Our results show that different conclusions could be obtained due to the data errors.

Cited by

Related