Tell us about a system for managing vulnerability database that works across enterprise, private and open source, is staffed enough to research both impact and disputes, is funded enough to work for decades, isn't partisan to any industry interests, can classify vulnerabilities in a non ambiguous way, can handle public submissions at any volume in a timely manner...
and one that will never make decisions that is incorrect or disliked by any party.