What are the criteria for evaluating a security bug?
• How serious is the vulnerability? • Critical: the bug can lead to arbitrary code execution. • Severe: the bug can compromise confidentiality, integrity or availability of resources. • Moderate: anything else – for example, the bug exposes operational information such as number of active sessions.