10

If someone has to decide between 2 very similar server programs, or operating systems, then it searches on sites like:

http://www.exploit-db.com/search/

so that there he could get enough information about the given program/os's historical security bugs.

Do you know exploit-db like sites, where can people search for security bugs? What's the best place to search? What's the best place to compare two software/os-es?

schroeder
  • 123,438
  • 55
  • 284
  • 319
LanceBaynes
  • 6,149
  • 11
  • 60
  • 91
  • 1
    This question is very much similar too http://security.stackexchange.com/questions/1225/which-site-do-you-use-to-view-details-of-vulnerabilities/ – Chris Dale Mar 28 '11 at 05:33

4 Answers4

10

Try these for a start:

http://www.securityfocus.com

http://osvdb.org

http://web.nvd.nist.gov

http://secunia.com

TobyS
  • 1,597
  • 1
  • 12
  • 17
3

Couple others:

http://securityvulns.com/

http://www.vupen.com/english/security-advisories/

Tate Hansen
  • 13,714
  • 3
  • 40
  • 83
1

Let me cite:

www.cvedetails.com provides an easy to use web interface to CVE vulnerability data. You can browse for vendors, products and versions and view cve entries, vulnerabilities, related to them. You can view statistics about vendors, products and versions of products.

0

One more good addition is Vulners. That's security aggregator that collects all the most popular exploit databases in one place.

https://vulners.com

isox
  • 101
  • 1