{"status":"ok","message-type":"work","message-version":"1.0.0","message":{"indexed":{"date-parts":[[2026,6,10]],"date-time":"2026-06-10T16:28:28Z","timestamp":1781108908232,"version":"3.54.1"},"reference-count":25,"publisher":"IGI Global Scientific Publishing","issue":"4","content-domain":{"domain":[],"crossmark-restriction":false},"short-container-title":[],"published-print":{"date-parts":[[2018,10,1]]},"abstract":"<p>This paper introduces VuWaDB, which is a database for vulnerability workarounds. When faced with a newly discovered vulnerability, experts tend to use workarounds in order to mitigate the risks until a patch is issued by the vendor. Currently, the available vulnerability databases suffer from the lack of comprehensive workaround solutions. Furthermore, the presented workarounds are only limited to a few vulnerabilities but also poorly recorded in natural language sentences and plain text format. In order to construct VuWaDB, first, the related information was gathered from a number of well-known vulnerability databases and then extracted, analyzed, and labeled. In this regard, VuWaDB organizes the workarounds in six categories: configuration, modify code, redirect, remove, restrict access and, utility tool. Lastly, it was analyzed from the statistical point of view.<\/p>","DOI":"10.4018\/ijisp.2018100102","type":"journal-article","created":{"date-parts":[[2018,10,18]],"date-time":"2018-10-18T07:43:05Z","timestamp":1539848585000},"page":"24-34","source":"Crossref","is-referenced-by-count":2,"title":["VuWaDB"],"prefix":"10.4018","volume":"12","author":[{"given":"Atefeh","family":"Khazaei","sequence":"first","affiliation":[{"name":"Yazd University, Yazd, Iran"}],"role":[{"vocabulary":"crossref","role":"author"}]},{"ORCID":"https:\/\/orcid.org\/0000-0002-6805-4852","authenticated-orcid":true,"given":"Mohammad","family":"Ghasemzadeh","sequence":"additional","affiliation":[{"name":"Yazd University, Yazd, Iran"}],"role":[{"vocabulary":"crossref","role":"author"}]},{"given":"Christoph","family":"Meinel","sequence":"additional","affiliation":[{"name":"Hasso Plattner Institute, Potsdam, Germany"}],"role":[{"vocabulary":"crossref","role":"author"}]}],"member":"2432","reference":[{"key":"IJISP.2018100102-0","unstructured":"Apple Listserv. (n.d.). Retrieved from https:\/\/lists.apple.com\/archives\/security-announce"},{"key":"IJISP.2018100102-1","unstructured":"CERT CC Vulnerability Notes. (n.d.). Retrieved from https:\/\/www.kb.cert.org\/vuls\/"},{"key":"IJISP.2018100102-2","unstructured":"Common Vulnerabilities and Exposures. (n.d.). Retrieved from http:\/\/cve.mitre.org\/"},{"key":"IJISP.2018100102-3","unstructured":"Debian Linux Security Information. (n.d.). Retrieved from http:\/\/www.debian.org\/security\/"},{"key":"IJISP.2018100102-4","unstructured":"Forum of Incident Response and Security Teams (FIRST). (n.d.). Common Vulnerabilities Scoring System (CVSS). Retrieved from http:\/\/www.first.org\/cvss\/"},{"key":"IJISP.2018100102-5","doi-asserted-by":"publisher","DOI":"10.1109\/APNOMS.2015.7275369"},{"key":"IJISP.2018100102-6","doi-asserted-by":"publisher","DOI":"10.1016\/j.cose.2011.12.014"},{"key":"IJISP.2018100102-7","author":"J. D.Howard","year":"1997","journal-title":"An analysis of security incidents on the Internet 1989-1995"},{"key":"IJISP.2018100102-8","unstructured":"HP Customer Support. (n.d.). Retrieved from https:\/\/support.hp.com\/us-en"},{"key":"IJISP.2018100102-9","first-page":"1","article-title":"Software Vulnerabilities Database Selection Using MoSCoW Prioritisation Method","author":"A.Khazaei","year":"2016","journal-title":"3rd International Conference on Applied Research in Computer & Information"},{"key":"IJISP.2018100102-10","doi-asserted-by":"publisher","DOI":"10.3233\/IFS-151733"},{"key":"IJISP.2018100102-11","doi-asserted-by":"publisher","DOI":"10.1109\/MITP.2003.1176486"},{"key":"IJISP.2018100102-12","unstructured":"MITRE Corporation. (n.d.). Common Weakness Enumeration (CWE). Retrieved from http:\/\/cwe.mitre.org\/"},{"key":"IJISP.2018100102-13","doi-asserted-by":"crossref","unstructured":"Mokhov, S. A., Laverdi\u2019ere, M. A., & Benredjem, D. (2008). Taxonomy of Linux kernel vulnerability solutions. Innovative Techniques in Instruction Technology, E-learning, E-assessment, and Education, 485\u2013493.","DOI":"10.1007\/978-1-4020-8739-4_86"},{"key":"IJISP.2018100102-14","unstructured":"Mozilla Foundation Security Advisories (MFSA). (n.d.). Retrieved from https:\/\/www.mozilla.org\/en-US\/security\/advisories\/"},{"key":"IJISP.2018100102-15","unstructured":"National Vulnerability Database (NVD). (n.d.). Retrieved from https:\/\/nvd.nist.gov\/"},{"key":"IJISP.2018100102-16","unstructured":"Open Source Vulnerability Database (OSVDB). (n.d.). Retrieved from http:\/\/osvdb.org\/"},{"key":"IJISP.2018100102-17","unstructured":"Open Vulnerability Assessment Language (OVAL). (n.d.). Retrieved from http:\/\/oval.mitre.org"},{"key":"IJISP.2018100102-18","unstructured":"Redhat Support. (n.d.). Retrieved from https:\/\/www.redhat.com\/en\/services\/support"},{"key":"IJISP.2018100102-19","unstructured":"Secunia Research Community. (n.d.). Retrieved from http:\/\/secunia.com\/advisories\/"},{"key":"IJISP.2018100102-20","unstructured":"Security Focus. (n.d.). Retrieved from https:\/\/www.securityfocus.com\/"},{"key":"IJISP.2018100102-21","unstructured":"Security Tracker. (n.d.). Retrieved from http:\/\/securitytracker.com\/"},{"key":"IJISP.2018100102-22","unstructured":"Van Dyke, C. W. (2004). An In-Depth Analysis of Common Software Vulnerabilities and Their Solutions (Master thesis). Oregon State University."},{"key":"IJISP.2018100102-23","unstructured":"VUPEN Security Database. (n.d.). Retrieved from http:\/\/www.vupen.com\/english\/"},{"key":"IJISP.2018100102-24","unstructured":"Younan, Y. (2003). An overview of common programming security vulnerabilities and possible solutions (Master thesis). Vrije Universiteit Brussel."}],"container-title":["International Journal of Information Security and Privacy"],"original-title":[],"language":"ng","link":[{"URL":"https:\/\/www.igi-global.com\/viewtitle.aspx?TitleId=216847","content-type":"unspecified","content-version":"vor","intended-application":"similarity-checking"}],"deposited":{"date-parts":[[2022,5,6]],"date-time":"2022-05-06T19:51:29Z","timestamp":1651866689000},"score":1,"resource":{"primary":{"URL":"https:\/\/services.igi-global.com\/resolvedoi\/resolve.aspx?doi=10.4018\/IJISP.2018100102"}},"subtitle":["A Vulnerability Workaround Database"],"short-title":[],"issued":{"date-parts":[[2018,10,1]]},"references-count":25,"journal-issue":{"issue":"4","published-print":{"date-parts":[[2018,10]]}},"URL":"https:\/\/doi.org\/10.4018\/ijisp.2018100102","relation":{},"ISSN":["1930-1650","1930-1669"],"issn-type":[{"value":"1930-1650","type":"print"},{"value":"1930-1669","type":"electronic"}],"subject":[],"published":{"date-parts":[[2018,10,1]]}}}