Dev

How CVE IDs Help You Track Security Vulnerabilities

CVE identifiers help developers track publicly disclosed vulnerabilities, affected software, and related security information. This article explains how to use them to monitor issues relevant to the services you operate.


Vulnerabilities and Exploits


A vulnerability and an exploit are related but distinct concepts. Understanding the difference helps clarify how a software flaw can become a security incident.


A vulnerability is a weakness that could allow unauthorized behavior. An exploit is code or a technique that takes advantage of that weakness. The relationship is illustrated below.


Relationship between a vulnerability and an exploit

The relationship between vulnerabilities and exploits


For example, an attacker might exploit a software vulnerability to gain unauthorized access or cause a denial of service.



CVE: a common identifier for vulnerabilities


Just as a national identification number distinguishes one person from another, a CVE ID gives the security community a shared way to identify a specific vulnerability.


CVE stands for Common Vulnerabilities and Exposures. Before the system existed, organizations often used different names for the same weakness, making it difficult to compare reports and coordinate a response.


MITRE established the CVE program to provide a common identification system. CVE records are also used by the National Vulnerability Database (NVD), operated by the U.S. National Institute of Standards and Technology (NIST).


A CVE record assigns a unique identifier to a disclosed vulnerability and provides a description and references. Databases such as NVD add further analysis, including severity information. CVE identifiers follow the format shown below.


CVE identifier format

Rules for CVE identification numbers


Search the NVD for vulnerability information:



Understanding CVE through the batchOverflow Vulnerability


Let's take a famous smart contract vulnerability, batchOverflow, as an example. If you search for the keyword batchOverflow at the link above, you will encounter the vulnerability CVE-2018–10299 as a result. When you access the vulnerability page, you'll see a display like this.


CVE-2018-10299, known as batchOverflow


The vulnerability CVE-2018–10299 known as batchOverflow


Different names—batchOverflow, BatchOverflow, or an integer-overflow flaw—can all refer to the same issue. The identifier CVE-2018-10299 provides an unambiguous reference.


The description explains the vulnerability, while the scoring section helps assess severity. NVD uses the Common Vulnerability Scoring System (CVSS) to provide severity information. The illustration below shows OWASP’s risk-rating approach, a separate method that considers likelihood and impact.


OWASP risk-rating methodology

OWASP's risk grading methodology



Learning More About CVE-2018–10299


The batchOverflow issue was found in a Solidity smart contract for an ERC-20 token. It affected batchTransfer, a function intended to send a specified number of tokens to multiple wallets.


A counter rolls from 9 to 0, illustrating overflow

A mechanical counter rolling from 9 to 0 illustrates the idea of overflow.


The caller could supply a token amount that caused an arithmetic overflow, bypassing a balance check and enabling an excessive transfer. The vulnerability received a severity score of 7.5. In response, exchanges paused certain ERC-20 operations while conducting reviews.


Poloniex announcement pausing ERC-20 transactions

Poloniex paused transactions for ERC-20 tokens


Arithmetic operations in smart contracts require careful handling of overflow and underflow. In the Solidity versions discussed in this historical article, the OpenZeppelin SafeMath library was a common defense. Consistent use still needed review, which is one reason specialist audits remain valuable.


Need more information or a smart contract audit? Contact SOOHO.IO.

👉 Contact Us



SOOHO.IO Official Channels
Recommended Articles

START WITH SOOHO.IO

Build the future of finance with SOOHO.IO.

START WITH SOOHO.IO

Build the future of finance with SOOHO.IO.

START WITH SOOHO.IO

Build the future of finance with SOOHO.IO.