Re: Vulnebrability level definition

From: raymond (ip_raymondat_private)
Date: Fri Feb 14 2003 - 07:27:01 PST

  • Next message: David Julião Santos: "Re: MS Office Files"

    Hi,
    
    I think that we should not be mixing the vulnerability
    and risk together. Vulnerability is the weakness of a
    design or system to be exploited. The risk is loss in
    case it happens...
    
    Therefore, CVE is all refering to Vulnerability. If
    you put up a MSQL Server in a standalone machine
    without any LAN connection. Is this a risk ?
    
    
    __________________________________________________
    Do you Yahoo!?
    Yahoo! Shopping - Send Flowers for Valentine's Day
    http://shopping.yahoo.com
    
    ----------------------------------------------------------------------------
    This list is provided by the SecurityFocus Security Intelligence Alert (SIA)
    Service. For more information on SecurityFocus' SIA service which
    automatically alerts you to the latest security vulnerabilities please see:
    https://alerts.securityfocus.com/
    



    This archive was generated by hypermail 2b30 : Fri Feb 14 2003 - 08:53:15 PST