Get desktop application:
View/edit binary Protocol Buffers messages
Details of a vulnerability occurrence.
Used in:
The type of package; whether native or non native(ruby gems, node.js packages etc)
Output only. The note provider assigned Severity of the vulnerability.
Output only. The CVSS score of this vulnerability. CVSS score is on a scale of 0-10 where 0 indicates low severity and 10 indicates high severity.
The set of affected locations and their fixes (if available) within the associated resource.
Output only. A one sentence description of this vulnerability.
Output only. A detailed description of this vulnerability.
Output only. URLs related to this vulnerability.
This message wraps a location affected by a vulnerability and its associated fix (if one is available).
Used in:
The location of the vulnerability.
The location of the available fix for vulnerability.
The severity (e.g., distro assigned severity) for this vulnerability.
Note provider-assigned severity/impact ranking.
Used in:
, ,Unknown.
Minimal severity.
Low severity.
Medium severity.
High severity.
Critical severity.
Vulnerability provides metadata about a security vulnerability.
Used in:
The CVSS score for this vulnerability.
Note provider assigned impact of the vulnerability.
All information about the package to specifically identify this vulnerability. One entry per (version range and cpe_uri) the package vulnerability has manifested in.
Identifies all occurrences of this vulnerability in the package for a specific distro/location. For example: glibc in cpe:/o:debian:debian_linux:8 for versions 2.1 - 2.2
Used in:
The cpe_uri in [cpe format] (https://cpe.mitre.org/specification/) in which the vulnerability manifests. Examples include distro or storage location for vulnerable jar.
The name of the package where the vulnerability was found.
The min version of the package in which the vulnerability exists.
The max version of the package in which the vulnerability exists.
The severity (eg: distro assigned severity) for this vulnerability.
A vendor-specific description of this note.
The fix for this specific package version.
The type of package; whether native or non native(ruby gems, node.js packages etc).
Whether this detail is obsolete. Occurrences are expected not to point to obsolete details.
The location of the vulnerability.
Used in:
,The cpe_uri in [cpe format] (https://cpe.mitre.org/specification/) format. Examples include distro or storage location for vulnerable jar.
The package being described.
The version of the package being described.