Re: Vulnebrability level definition

From: raymond (ip_raymond@yahoo.com)
Date: Fri Feb 14 2003 - 10:27:01 EST


Hi,

I think that we should not be mixing the vulnerability
and risk together. Vulnerability is the weakness of a
design or system to be exploited. The risk is loss in
case it happens...

Therefore, CVE is all refering to Vulnerability. If
you put up a MSQL Server in a standalone machine
without any LAN connection. Is this a risk ?

__________________________________________________
Do you Yahoo!?
Yahoo! Shopping - Send Flowers for Valentine's Day
http://shopping.yahoo.com

----------------------------------------------------------------------------
This list is provided by the SecurityFocus Security Intelligence Alert (SIA)
Service. For more information on SecurityFocus' SIA service which
automatically alerts you to the latest security vulnerabilities please see:
https://alerts.securityfocus.com/



This archive was generated by hypermail 2.1.7 : Sat Apr 12 2008 - 10:53:28 EDT