Follow @Openwall on Twitter for new release announcements and other news
[<prev] [next>] [thread-next>] [day] [month] [year] [list]
Date: Sat, 8 Feb 2014 12:17:31 +0100
From: Raphael Geissert <>
Cc: Vulnerability Information Managers <>
Subject: Fwd: Old CVE ids, public, but still "RESERVED"

Sending a copy to oss-sec, in case there are people interested in this kind 
of information.

----------  Forwarded Message  ----------

Subject: Old CVE ids, public, but still "RESERVED"
Date: Friday 24 January 2014
From: Raphael Geissert <>
To: Vulnerability Information Managers <>


Attached are a list of CVE ids which are still marked as RESERVED
(i.e. no description/links/etc have been set) yet our security tracker
knows about them. The tracker only containing public data, it means
that the ids are not embargoed.

Hopefully these lists can be useful to MITRE to catch up on those, or
to anyone else.
I can generate these and other reports regularly if desired.

* The year in the file name corresponds to the year in the CVE id, not
necessarily the year of assignment.
* The lists only contain the CVE id, probably a short description, and
one line of data from our tracker. The full data can be obtained
either by going to or by
looking up on our text database.

Raphael Geissert - Debian Developer -

View attachment "still-reserved-2011-CVEs.txt" of type "text/plain" (14368 bytes)

View attachment "still-reserved-2012-CVEs.txt" of type "text/plain" (18434 bytes)

View attachment "still-reserved-2013-CVEs.txt" of type "text/plain" (34008 bytes)

Powered by blists - more mailing lists

Please check out the Open Source Software Security Wiki, which is counterpart to this mailing list.

Confused about mailing lists and their use? Read about mailing lists on Wikipedia and check out these guidelines on proper formatting of your messages.