For calendar year 2010, mixing public and embargoed:
235 (32%) from some public mailing list or internet site
177 (24%) from relationships with upstream projects
75 (10%) found by Red Hat
70 (10%) reported to us by 3rd party (secalert@redhat.com or other)
64 (9%) from relationship with other peer vendors
51 (7%) vendor-sec
46 (6%) from the public feed of new CVE names
13 (2%) from some co-ordination service like CERT/CC