National Cyber Security by LIGATT - http://www.nationalcybersecurity.com
Vulnerability Summary for the Week of May 19, 2008
http://www.nationalcybersecurity.com/articles/160/1/Vulnerability-Summary-for-the-Week-of-May-19-2008/Page1.html
Grey McKenzie
National Cyber Security Founder

Cyber security watchdog Grey McKenzie is one of the nation's leading Internet security experts.

Some of his clients include members of the Department of Homeland Security, State Department, Department of Defense & the Federal Bureau of Investigation.

His SpyCop security software products are in use by over 50,000 individuals & companies worldwide

To schedule an interview or consult with Grey call 850-708-7660 
By Grey McKenzie
Published on Wednesday 28th 2008
 
The US-CERT Cyber Security Bulletin provides a summary of new vulnerabilities that have been recorded by the National Institute of Standards and Technology (NIST) National Vulnerability Database (NVD) in the past week. The NVD is sponsored by the Department of Homeland Security (DHS) National Cyber Security Division (NCSD) / United States Computer Emergency Readiness Team (US-CERT). For modified or updated entries, please visit the NVD, which contains historical vulnerability information.

The vulnerabilities are based on the CVE vulnerability naming standard and are organized according to severity, determined by the Common Vulnerability Scoring System (CVSS) standard. The division of high, medium, and low severities correspond to the following scores:

  • High - Vulnerabilities will be labeled High severity if they have a CVSS base score of 7.0 - 10.0

  • Medium - Vulnerabilities will be labeled Medium severity if they have a CVSS base score of 4.0 - 6.9

  • Low - Vulnerabilities will be labeled Low severity if they have a CVSS base score of 0.0 - 3.9

Entries may include additional information provided by organizations and efforts sponsored by US-CERT. This information may include identifying information, values, definitions, and related links. Patch information is provided when available. Please note that some of the information in the bulletins is compiled from external, open source reports and is not a direct result of US-CERT analysis.