CVE Vulnerability Research for 70 Open Source + Commercial Runtime Software Libraries
Budget: $250 – $750 USD
We are doing a security audit of 70 software libraries that our organization depends on.
The libraries are a mix of Open Source software libraries and Commercial Runtime software libraries
We are looking to hire someone who can review the entire list, and research each individual library for published Security Vulnerabilities (CVE's) from the NIST national vulnerability database.
The results of the research need to be summarised in a spreadsheet and include links to each CVE discovered and its base score.
The CVE's found for each library and associated links must be categorised into severity level.
The results should be compiled into a spreadsheet which we will give you a template for.
Care will need to be taken to ensure the precise library we list is what the associated CVE's you find are related to. e.g. If list a specific JPEG library and version, we are looking to understand every CVE for that library version that exists, but not every CVE out there that has something to do with a Jpeg (as there would be thousands of hits and not very useful to us).
The libraries are a mix of Open Source software libraries and Commercial Runtime software libraries
We are looking to hire someone who can review the entire list, and research each individual library for published Security Vulnerabilities (CVE's) from the NIST national vulnerability database.
The results of the research need to be summarised in a spreadsheet and include links to each CVE discovered and its base score.
The CVE's found for each library and associated links must be categorised into severity level.
The results should be compiled into a spreadsheet which we will give you a template for.
Care will need to be taken to ensure the precise library we list is what the associated CVE's you find are related to. e.g. If list a specific JPEG library and version, we are looking to understand every CVE for that library version that exists, but not every CVE out there that has something to do with a Jpeg (as there would be thousands of hits and not very useful to us).