Vulnerability Research - What's Behind Drop in 2007 Vulnerability Counts? - eWeek Security Watch

What’s Behind Drop in 2007 Vulnerability Counts?

Written By
Ryan Naraine
Ryan Naraine
Feb 5, 2008
2 minute read
eWeek content and product recommendations are editorially independent. We may make money when you click on links to our partners. Learn More

For the first time since people started keeping track of this stuff, 2007 saw a noticeable decline in publicly reported security vulnerabilities.

In fact, according to data from IBM ISS X-Force, there was a 5.4 percent decline in new vulnerability disclosures from the previous year, a drop that could represent an anomaly, a statistical correction or a new trend in the amount of disclosures.

Here’s the chart:

As you can see, 2005 and 2006 saw huge jumps (approximately 41 percent each year) that were well above the historical average (27 percent a year), according to X-Force internal statistics.

Although there was a decrease in overall vulnerabilities, the company said high priority vulnerabilities increased by 28 percent, suggesting that researchers could simply be focusing on the sometimes more difficult, high-priority finds.

[ SEE: $20000 Bounty Placed on Windows Flaws ]

I think what we’re seeing here is how much the third-party brokers that buy flaws (and sometimes coordinate disclosure) are influencing the way vulnerabilities get reported and fixed by affected vendors.

More and more, I think hackers are going to places like iDefense’s VCP, TippingPoint’s Zero Day Initiative, WabiSabiLabi and the other lesser-known brokers to make money from their discoveries.

This basically means that a lot of vulnerabilities are never reported to a vendor and, by extension, never get fixed. See the ongoing RealNetworks drama for evidence of this.

Also, bear in mind that a lot of software vendors, including Microsoft, participate in the silent fixing of vulnerabilities, meaning that disclosure doesn’t match the actual weakness/strength of a software product.

Am I missing anything? What do you think is behind this flaw count reduction?

More from Rich Mogull, Pete Lindstrom and Larry Dignan.

eWeek Logo

eWeek has the latest technology news and analysis, buying guides, and product reviews for IT professionals and technology buyers. The site's focus is on innovative solutions and covering in-depth technical content. eWeek stays on the cutting edge of technology news and IT trends through interviews and expert analysis. Gain insight from top innovators and thought leaders in the fields of IT, business, enterprise software, startups, and more.

Property of TechnologyAdvice. © 2026 TechnologyAdvice. All Rights Reserved

Advertiser Disclosure: Some of the products that appear on this site are from companies from which TechnologyAdvice receives compensation. This compensation may impact how and where products appear on this site including, for example, the order in which they appear. TechnologyAdvice does not include all companies or all types of products available in the marketplace.