Tag: National Vulnerability Database (NVD)

NIST to stop rating non-priority flaws due to volume increase
News

NIST to stop rating non-priority flaws due to volume increase

Because of the increasing volume of submissions, the National Institute of Standards and Technology will no longer assign severity levels to lower-priority vulnerabilities. Beginning on April 15, the service will only examine and offer supplementary information (such as product listings and severity ratings) for security vulnerabilities that satisfy particular standards pertaining to the risk they represent. All submitted vulnerabilities will still be listed in the National Vulnerability Database (NVD), however those deemed low priority will only receive a severity rating from the CVE Numbering Authority (CNA) that assessed and filed them. The non-regulatory federal agency stated in a statement this week that it will only offer more information on vulnerabilities that satisfy one...
New Chrome Zero-Day Actively Exploited; Google Issues Emergency Out-of-Band Patch
News

New Chrome Zero-Day Actively Exploited; Google Issues Emergency Out-of-Band Patch

Google fixed three security flaws in its Chrome browser, including one that it claimed was being actively exploited in the wild, with out-of-band upgrades on Monday. The high-severity vulnerability has been identified as an out-of-bounds read and write vulnerability in the V8 JavaScript and WebAssembly engine and is being tracked as CVE-2025-5419. According to the NIST's National Vulnerability Database (NVD), out-of-bounds read and write in Google Chrome V8 before 137.0.7151.68 may have enabled a remote attacker to take advantage of heap corruption through a specially constructed HTML website. On May 27, 2025, Google gave credit to Clement Lecigne and Benoît Sevens of Google Threat Analysis Group (TAG) for identifying and disclosing the vulnerability. Additionally, it mentioned t...