<?xml version="1.0" encoding="UTF-8" ?>
<rss xmlns:dc="http://purl.org/dc/elements/1.1/" version="2.0" xmlns:atom="http://www.w3.org/2005/Atom"><channel><title>Common Vulnerability Scoring System News</title><link>http://www.first.org/newsroom/news/cvss.html</link><atom:link href="http://www.first.org/newsroom/news/cvss.xml" rel="self" type="application/rss+xml" /><description>CVSS proposes an open and universal vulnerability scoring system to address and solve the lack of cohesion and interoperability among vendor-specific ones, resulting on the promotion of a common language to discuss vulnerability severity and impact.</description><dc:publisher>FIRST.org, Inc</dc:publisher><copyright>© 1995-2008 by FIRST.org, Inc.</copyright><pubDate>Mon, 07 Jul 2008 18:43:00 +0100</pubDate><lastBuildDate>Fri, 16 Jul 2010 15:13:50 +0100</lastBuildDate><generator>Tecnodesign</generator><language>en-us</language><ttl>20</ttl><image><title>Common Vulnerability Scoring System News</title><link>http://www.first.org/newsroom/news/cvss.html</link><url>http://www.first.org/_images/first-news.png</url></image><item><title>CVSS-SIG successful working meeting during the 20th annual FIRST conference</title><link>http://www.first.org/cvss/meeting_agenda_20080623.html </link><guid isPermaLink="false">firstnews:40330</guid><description>The Common Vulnerability Scoring System Special Interest Group (CVSS- SIG) had a very busy and successful working meeting during the 20th annual FIRST conference in Vancouver. We covered many of the CVSS use cases post v2 deployment - namely PCI and S-CAP - thanks for all the great participation.</description><pubDate>Mon, 07 Jul 2008 18:43:00 +0100</pubDate></item><item><title>FIRST CVSS-SIG meeting,	Vancouver 2008</title><link>http://www.first.org/meetings/cvss/</link><guid isPermaLink="false">firstnews:40262</guid><description>The Common Vulnerability Scoring System Special Interest Group (CVSS-SIG) has scheduled a working meeting during the 20th annual FIRST conference in Vancouver (June 22-27,2008). This meeting will take place on Monday, June 23rd  08:30-10:30 PST</description><pubDate>Fri, 20 Jun 2008 20:17:00 +0100</pubDate></item><item><title>New Scoring System Protects Credit Card Transactions</title><link>http://www.first.org/newsroom/globalsecurity/sql101.html</link><guid isPermaLink="false">firstnews:34564</guid><description>ScienceDaily  As this year's holiday season approaches, your credit card transactions may be a little more secure thanks to standards adopted by the payment card industry. The latest incarnation of these standards include the Common Vulnerability Scoring System (CVSS) Version 2 that was coauthored this year by researchers at the National Institute of Standards and Technology and Carnegie Mellon University in collaboration with 23 other organizations</description><pubDate>Sun, 11 Nov 2007 13:34:00 +0100</pubDate></item><item><title>The Common Vulnerability Scoring System (CVSS) and Its Applicability to Federal Agency Systems</title><link>http://www.first.org/cvss/cvss_applicability.html</link><guid isPermaLink="false">firstnews:97</guid><description>NIST IR 7435 is published as final.  CVSS provides an open framework for communicating the characteristics and impacts of IT vulnerabilities.  </description><pubDate>Fri, 31 Aug 2007 16:41:00 +0100</pubDate></item><item><title>CVSS Version 2 Scoring with Nessus and the Passive Vulnerability Scanner</title><link>http://blog.tenablesecurity.com/2007/07/cvss-version-2-.html</link><guid isPermaLink="false">firstnews:92</guid><description>On Wednesday, August 15th, 2007, Tenable Network Security will begin converting CVSS base scores for Nessus and the Passive Vulnerability Scanner (PVS) plugins from version 1 to version 2. This blog entry discusses how some of the plugin severity...</description><pubDate>Thu, 19 Jul 2007 15:22:00 +0100</pubDate></item><item><title>CVSS Version 2 Scoring with Nessus and the Passive Vulnerability Scanner</title><link>http://www.first.org/newsroom/globalsecurity/sql92.html</link><guid isPermaLink="false">firstnews:34565</guid><description>On Wednesday, August 15th, 2007, Tenable Network Security will begin converting CVSS base scores for Nessus and the Passive Vulnerability Scanner (PVS) plugins from version 1 to version 2. This blog entry discusses how some of the plugin severity...</description><pubDate>Thu, 19 Jul 2007 15:22:00 +0100</pubDate></item><item><title>A revised vulnerability rating system gains steam</title><link>http://searchwinit.techtarget.com/originalContent/0,289142,sid1_gci1263306,00.html</link><guid isPermaLink="false">firstnews:91</guid><description>A standardized system to rank computer system vulnerabilities has been revised to help IT managers make better decisions more quickly about potential threats [SearchWinIt.com]</description><pubDate>Mon, 09 Jul 2007 21:00:00 +0100</pubDate></item><item><title>A revised vulnerability rating system gains steam</title><link>http://www.first.org/newsroom/globalsecurity/sql91.html</link><guid isPermaLink="false">firstnews:34566</guid><description>A standardized system to rank computer system vulnerabilities has been revised to help IT managers make better decisions more quickly about potential threats [SearchWinIt.com]</description><pubDate>Mon, 09 Jul 2007 21:00:00 +0100</pubDate></item><item><title>New tool for testing application security</title><link>http://computerworld.com/action/article.do?command=viewArticleBasic&#x26;articleId=9025760</link><guid isPermaLink="false">firstnews:89</guid><description>Standards-based system to rate vulnerabilities [Computerworld]</description><pubDate>Tue, 26 Jun 2007 17:00:00 +0100</pubDate></item><item><title>New tool for testing application security</title><link>http://www.first.org/newsroom/globalsecurity/sql89.html</link><guid isPermaLink="false">firstnews:34567</guid><description>Standards-based system to rate vulnerabilities [Computerworld]</description><pubDate>Tue, 26 Jun 2007 17:00:00 +0100</pubDate></item><item><title>NIST releases FISMA security control tools</title><link>http://www.gcn.com/online/vol1_no1/44331-1.html</link><guid isPermaLink="false">firstnews:77</guid><description>The National Institute of Standards and Technology has released a suite of tools to help automate vulnerability management and evaluate compliance with federal IT security requirements.</description><pubDate>Thu, 21 Jun 2007 05:24:00 +0100</pubDate></item><item><title>NIST releases FISMA security control tools</title><link>http://www.first.org/newsroom/globalsecurity/sql77.html</link><guid isPermaLink="false">firstnews:34568</guid><description>The National Institute of Standards and Technology has released a suite of tools to help automate vulnerability management and evaluate compliance with federal IT security requirements.</description><pubDate>Thu, 21 Jun 2007 05:24:00 +0100</pubDate></item><item><title>National Vulnerability Database Version 2.0 - NVD Now Supports CVSS Version 2.0 (June 20, 2007)!!</title><link>http://nvd.nist.gov/cvss.cfm</link><guid isPermaLink="false">firstnews:76</guid><description>NVD is the U.S. government repository of standards based vulnerability management data represented using the Security Content Automation Protocol (SCAP). This data enables automation of vulnerability management, security measurement, and compliance.</description><pubDate>Wed, 20 Jun 2007 22:00:00 +0100</pubDate></item><item><title>National Vulnerability Database Version 2.0 - NVD Now Supports CVSS Version 2.0 (June 20, 2007)!!</title><link>http://www.first.org/newsroom/globalsecurity/sql76.html</link><guid isPermaLink="false">firstnews:34569</guid><description>NVD is the U.S. government repository of standards based vulnerability management data represented using the Security Content Automation Protocol (SCAP). This data enables automation of vulnerability management, security measurement, and compliance.</description><pubDate>Wed, 20 Jun 2007 22:00:00 +0100</pubDate></item><item><title>Flaw grading system graduates to next version</title><link>http://www.securityfocus.com/brief/531</link><guid isPermaLink="false">firstnews:75</guid><description>The Forum of Incident Response and Security Teams (FIRST) announced on Wednesday a revised version of the Common Vulnerability Scoring System (CVSS), which modifies the ranking system's recipe for judging the severity of software flaws.</description><pubDate>Wed, 20 Jun 2007 20:00:00 +0100</pubDate></item><item><title>Flaw grading system graduates to next version</title><link>http://www.first.org/newsroom/globalsecurity/sql75.html</link><guid isPermaLink="false">firstnews:34570</guid><description>The Forum of Incident Response and Security Teams (FIRST) announced on Wednesday a revised version of the Common Vulnerability Scoring System (CVSS), which modifies the ranking system's recipe for judging the severity of software flaws.</description><pubDate>Wed, 20 Jun 2007 20:00:00 +0100</pubDate></item><item><title>New version of Common Vulnerability Scoring System released</title><link>http://www.first.org/newsroom/releases/20070620-1.html</link><guid isPermaLink="false">firstnews:71</guid><description>Seville Spain  June 20, 2007: Millions of computer users worldwide will enjoy more secure virtual experiences and transactions with the advent today of CVSSv2  the latest version of the Common Vulnerability Scoring System.</description><pubDate>Wed, 20 Jun 2007 02:00:00 +0100</pubDate></item><item><title>Magic Numbers or Snake Oil? The Common Vulnerability Scoring System</title><link>http://www.heise-security.co.uk/articles/89049</link><guid isPermaLink="false">firstnews:66</guid><description>Can a single number sum up the full significance of a security vulnerability? The CVSS attempts to prove that it can, but it has its weak points.</description><pubDate>Wed, 30 May 2007 15:15:00 +0100</pubDate></item><item><title>Magic Numbers or Snake Oil? The Common Vulnerability Scoring System</title><link>http://www.first.org/newsroom/globalsecurity/sql66.html</link><guid isPermaLink="false">firstnews:34571</guid><description>Can a single number sum up the full significance of a security vulnerability? The CVSS attempts to prove that it can, but it has its weak points.</description><pubDate>Wed, 30 May 2007 15:15:00 +0100</pubDate></item><item><title>CVSS Scores and Calculators</title><link>http://www.first.org/cvss/scores.html</link><guid isPermaLink="false">firstnews:42</guid><description>Several sites provide easy ways to get CVSS scores. The major ones are listed on the SIG website.</description><pubDate>Fri, 01 Dec 2006 14:25:00 +0100</pubDate></item></channel></rss>