Source where you can find if a CVE has a patch or not

I'm not aware of any good out-of-the-box services, but I usually cross-reference with sites like:

  • SecurityFocus: It usually references CVE. Patch status filed under "Solution".

  • PacketStormSecurity: Allows fulltext search (can search for CVE ID). Patch status filed under "Mitigation".

  • OSVDB: Has an option to search with CVE ID. Patch status filed under "Solution".

  • IBM XForce: Allows CVE ID search. Patch status filed under "Remediation".


The National Vulnerability Database offer searching the vulnerability database using the CVE number. The details include patch information as well as resource links for the available patch on the vendor's website (if patch is available). When you search a vulnerability, the details include a section called References to Advisories, Solutions, and Tools. In that section, look at the Type: Advisory.

Tags:

Cve