"Starting today, I plan on posting a monthly vulnerability scorecard for common server and workstation Operating System products. I'm going to keep these scorecards pretty clean of discussion, but you can review my methodology, sources and assumptions." Note that these results speak
only of
fixed vulnerabilities; the author
aims to include information on non-fixed problems and the time it takes to fix problems as well. You should also
read this, by the way.