German University Reports Severe Software Vulnerabilities Up in 2015

A German institution that maintains an online database of software vulnerabilities found that "serious" ones increased in 2015. According to Hasso Plattner Institute, while fewer software security vulnerabilities were reported worldwide in 2015 than in 2014, the number of published vulnerabilities with a high level of severity has increased. The university is concentrated on IT systems engineering, located in Potsdam.

Researchers tallied about 5,700 vulnerabilities throughout the year in HPI-VDB (the database for vulnerability analysis), compared to about 7,200 in 2014. However, while 2014 had about 1,800 weaknesses identified as "high severity," 2015 had about 2,000. However, that's still considerably down from 2008, when the database recorded a high of nearly 3,500 security flaws in software. Those assessed as medium severity dropped considerably from 2014 to 2015, while low severity vulnerabilities stayed nearly level.

The project, maintained by the IT Security Engineering Team at HPI, found that 7,000 new software products and 400 new development companies showed up in its database. The entire database stores more than 73,100 pieces of information on vulnerabilities, affecting 180,000 programs from 15,500 different software makers.

The data maintained in the HPI-VDB comes from multiple sources, primarily other publicly available Web sites with security information about vulnerabilities and security bulletins from vendors. Those include the Open Source Vulnerability Database (OSVD), Secunia, Carnegie Mellon University-run CERT, OVAL, SecurityFocus, Microsoft Security Bulletins and SAP Security Notes.

Users who register on the site are able to download information about single vulnerabilities in XML form. The researchers also make an API available for larger exports.

To protect users, HPI Director Christoph Meinel offered the same advice any security expert would: Patch software at every opportunity.

Next week the Institute will be hosting a two-week open course on maintaining privacy in social media. The MOOC is taught by computer scientist Anne Kayem and conducted in English.

About the Author

Dian Schaffhauser is a former senior contributing editor for 1105 Media's education publications THE Journal, Campus Technology and Spaces4Learning.

Featured

  • Digital Ai padlock locked for computing system on dark green background

    Microsoft, Nvidia Push Enterprise AI into Active Cyber Defense

    AI security is entering a new stage as enterprise organizations look beyond protecting models from prompt injection, unauthorized access, and data exposure.

  • digital graph

    Building Genuinely Data-Informed School Districts

    Schools today generate enormous amounts of data. The difference between collecting it and using it effectively often comes down to quality, access, and context.

  • education funding and graduation symbols on wooden dice

    What Is the Education Freedom Tax Credit and How Will It Work?

    The federal Education Freedom Tax Credit (EFTC) is a new source of funding for education that could benefit 90% of students in states that have opted in to the program. However, some confusion and misconceptions exist surrounding details of the program, including which programs may qualify, how parents can apply for scholarships, and how public school students can benefit.

  • Image of digital screen with data and math formulas on black background

    AI Models Generate Advances in Mathematical Research

    OpenAI has announced what it says is an AI-generated solution to the Navier-Stokes existence and smoothness problem, one of mathematics' seven Millennium Prize Problems, while Anthropic has reported separate advances in research mathematics and formal proof generation.