Dev
How CVE IDs Help You Track Security Vulnerabilities

CVE identifiers help developers track publicly disclosed vulnerabilities, affected software, and related security information. This article explains how to use them to monitor issues relevant to the services you operate.
Vulnerabilities and Exploits
A vulnerability and an exploit are related but distinct concepts. Understanding the difference helps clarify how a software flaw can become a security incident.
A vulnerability is a weakness that could allow unauthorized behavior. An exploit is code or a technique that takes advantage of that weakness. The relationship is illustrated below.

The relationship between vulnerabilities and exploits
For example, an attacker might exploit a software vulnerability to gain unauthorized access or cause a denial of service.
CVE: a common identifier for vulnerabilities
Just as a national identification number distinguishes one person from another, a CVE ID gives the security community a shared way to identify a specific vulnerability.
CVE stands for Common Vulnerabilities and Exposures. Before the system existed, organizations often used different names for the same weakness, making it difficult to compare reports and coordinate a response.
MITRE established the CVE program to provide a common identification system. CVE records are also used by the National Vulnerability Database (NVD), operated by the U.S. National Institute of Standards and Technology (NIST).
A CVE record assigns a unique identifier to a disclosed vulnerability and provides a description and references. Databases such as NVD add further analysis, including severity information. CVE identifiers follow the format shown below.

Rules for CVE identification numbers
Search the NVD for vulnerability information:
Understanding CVE through the batchOverflow Vulnerability
Let's take a famous smart contract vulnerability, batchOverflow, as an example. If you search for the keyword batchOverflow at the link above, you will encounter the vulnerability CVE-2018–10299 as a result. When you access the vulnerability page, you'll see a display like this.

The vulnerability CVE-2018–10299 known as batchOverflow
Different names—batchOverflow, BatchOverflow, or an integer-overflow flaw—can all refer to the same issue. The identifier CVE-2018-10299 provides an unambiguous reference.
The description explains the vulnerability, while the scoring section helps assess severity. NVD uses the Common Vulnerability Scoring System (CVSS) to provide severity information. The illustration below shows OWASP’s risk-rating approach, a separate method that considers likelihood and impact.

OWASP's risk grading methodology
Learning More About CVE-2018–10299
The batchOverflow issue was found in a Solidity smart contract for an ERC-20 token. It affected batchTransfer, a function intended to send a specified number of tokens to multiple wallets.

A mechanical counter rolling from 9 to 0 illustrates the idea of overflow.
The caller could supply a token amount that caused an arithmetic overflow, bypassing a balance check and enabling an excessive transfer. The vulnerability received a severity score of 7.5. In response, exchanges paused certain ERC-20 operations while conducting reviews.

Poloniex paused transactions for ERC-20 tokens
Arithmetic operations in smart contracts require careful handling of overflow and underflow. In the Solidity versions discussed in this historical article, the OpenZeppelin SafeMath library was a common defense. Consistent use still needed review, which is one reason specialist audits remain valuable.
Need more information or a smart contract audit? Contact SOOHO.IO.
👉 Contact Us
SOOHO.IO Official Channels
Website: https://www.sooho.io/
X (Twitter): https://twitter.com/soohoio
LinkedIn: https://www.linkedin.com/company/sooho/



