top | item 19139475

(no title)

21 | 7 years ago

And it has MORE reported CVEs than Windows:https://www.cvedetails.com/top-50-products.php?year=2018

discuss

order

Dahoon|7 years ago

When the list says Debian or Ubuntu it includes all software in Debian and Ubuntu. That includes software like Google Chrome, Firefox, Python, Ruby, etc. For example out of the 40 listed in 2019 in Debian 36(!) are Chrome bugs, not Debian bugs.

Sort by Vendor: https://www.cvedetails.com/top-50-vendors.php

CryoLogic|7 years ago

It's also OSS and it is much easier to surface security bugs for Linux than for Windows.

In my own research, I have attempted to send Microsoft security bugs only to be told they would be backlogged and reviewed later (which never happened to my knowledge).

21|7 years ago

> It's also OSS and it is much easier to surface security bugs for Linux than for Windows.

Shouldn't then the number of bugs decrease much faster, since they are easier to find? Unless they are introduced at even a greater rate than the ones in Windows.

imtringued|7 years ago

Maybe because more people can report them? With Windows you'll be lucky if Microsoft doesn't outright deny their existence.

Dahoon|7 years ago

That and saying Debian isn't like saying Windows. Debian is like 50.000 packages. Pretty much all CVES in this year so far listed as Debian CVES has been in Google Chrome browser...