Hacker Newsnew | past | comments | ask | show | jobs | submitlogin

>CVEs haven't been maintained since the early 90s

Can you clarify what you mean by this?



The wording was confusing for me too. At first reading I understood it as saying CVEs were no longer being issued for Acrobat, which definitely isn't the case. I assume the intended meaning was that Acrobat was first released in 1993[0], but the first CVE was CVE-1999-0001 (source: downloaded the raw dump from [1], ran grep -m1 CVE-....-0001).

But, I'm doubtful there would have been all that many CVEs issued for Acrobat from 1993-1998. There was only one CVE that mentioned "Acrobat" each year from 1999-2001, and three in 2002. The more recent years are the fun ones - but I have no idea whether that's a result of freshly-introduced exploitable bugs or just increased attention.

[0]: https://en.wikipedia.org/wiki/Adobe_Acrobat_version_history

[1]: https://cve.mitre.org/data/downloads/index.html




Guidelines | FAQ | Lists | API | Security | Legal | Apply to YC | Contact

Search: