Home
Help
Search
CVE Vulnerability Database
Security Knowledge Base
Browse
Oval Objects
Oval Sources
By Release Dates
OVAL Definitions
Windows
Compliance
Inventory
Patches
Vulnerabilities
Unix/Linux
Compliance
Inventory
Patches
Vulnerabilities
Red Hat Advisories
Suse Linux Advisories
IOS
PixOS
OVAL Classes
Compliance
Inventory
Miscellaneous
Patch
Vulnerability
Other
Feedback
About & Contact
|
What is this site ?
This site collects OVAL(Open Vulnerability and Assessment Language) definitions from several
sources like Mitre, Red Hat, Suse, NVD, Apache etc
and provides a unified, easy to use web interface to all IT security related items including
patches, vulnerabilities and compliance checklists.
You can view full details of oval definitions, which is not possible at any other public web site.
Other similar web sites just display comments about the definitions but here you can view exactly what you should look for to
verify a vulnerability or a patch.
Without itsecdb.com it is almost impossible to view details of an OVAL definition without getting lost in several xml files,
definition documentation, xml schemas etc.
itsecdb is fully integrated to www.cvedetails.com so you can easily
navigate between CVE, product and oval definition details.
Most of the definitions, whenever cpe or vulnerability mappings are possible,
are mapped to products defined by cvedetails.com to increase usability.
You can also browse or search for items used in oval definitions like file names, rpm packages, AIX patch numbers etc,
so you can easily find all patches or vulnerabilities related to any file. For example you can view list of all
patches, vulnerabilities and compliance checks related to
mshtml.dll here.
OVAL Definitions By Referenced Objects
Windows
- Registry Hives
- Registry Keys
- Registry Values
- File Paths
- File Names
- Users
- Security Principles
- WMI Namespaces
- Metabase Keys
- SIDs
Solaris
- Patches
- Packages
- Smf Fmri
AIX:
ESX:
- Patch Numbers
- Patch Names
IOS:
|
OVAL : Open Vulnerability and Assessment Language
Open Vulnerability and Assessment Language (OVAL) is an international, information security,
community standard to promote open and publicly available security content,
and to standardize the transfer of this information across the entire spectrum of security tools and services.
OVAL includes a language used to encode system details, and an assortment of content repositories held
throughout the community. The language standardizes the three main steps of the assessment process:
representing configuration information of systems for testing; analyzing the system
for the presence of the specified machine state (vulnerability, configuration, patch state, etc.);
and reporting the results of this assessment. The repositories are collections of publicly available
and open content that utilize the language.
For more information about OVAL visit
oval.mitre.org
CVE is a registred trademark of the MITRE Corporation and the authoritive source of CVE content is
MITRE's CVE web site.
CWE is a registred trademark of the MITRE Corporation and the authoritive source of CWE content is
MITRE's CWE web site.
OVAL is a registered trademark of The MITRE Corporation and the authoritive source of OVAL content is
MITRE's OVAL web site.
|
|
|
CVE is a registred trademark of the MITRE Corporation and the authoritive source of CVE content is
MITRE's CVE web site.
CWE is a registred trademark of the MITRE Corporation and the authoritive source of CWE content is
MITRE's CWE web site.
OVAL is a registered trademark of The MITRE Corporation and the authoritive source of OVAL content is
MITRE's OVAL web site.
Warning: This site and all data are provided as is.
It is not guaranteed that all information is accurate and complete.
Use any information provided on this site at your own risk.
By using this site you accept that you know that these data are provided as is and not guaranteed to be accurate, correct or complete.
All trademarks appearing on this site are the property of their respective owners in the US or other countries.
It is the responsibility of user to evaluate the accuracy, completeness or usefulness of any information, opinion, advice or other content.
EACH USER WILL BE SOLELY RESPONSIBLE FOR ANY consequences of his or her direct or indirect use of this web site.
ALL WARRANTIES OF ANY KIND ARE EXPRESSLY DISCLAIMED. This site will NOT BE LIABLE FOR ANY DIRECT,
INDIRECT or any other kind of loss.
PLEASE SEE nvd.nist.gov and oval.mitre.org for more details about OVAL language and definitions.
The information within this database may change without notice.
Use of this information constitutes acceptance for use in an AS IS condition.
There are NO warranties, implied or otherwise, with regard to this information or its use.
Any use of this information is at the user's risk.
In no event shall the author/distributor/web site owner/maintainer be held liable for
any damages whatsoever arising out of or in connection with the use or spread of this information.
Use of OVAL and all related data is subject to terms of use defined by Mitre at
oval.mitre.org/oval/about/termsofuse.html