Firefox tops list of 12 most vulnerable apps

Firefox tops list of 12 most vulnerable apps
Written by Ryan Naraine @ 10:41 am 12/15/2008


Mozilla’s flagship Firefox browser has earned the dubious title of the most vulnerable software program running on the Windows platform.

According to application whitelisting vendor Bit9, Firefox topped the list of 12 widely deployed desktop applications that suffered through critical security vulnerabilities in 2008. These flaws exposed millions of Windows users to remote code execution attacks.

The other applications on the list are all well-known and range from browsers to media players, to VOIP chat and anti-virus software programs. Here’s Bit9’s dirty dozen:


Read more at the source:
Firefox tops list of 12 most vulnerable apps | Zero Day | ZDNet.com
 

My Computer

System One

  • Manufacturer/Model
    Acer Aspire Notebook 5633WLMi.[5630 Series]
    CPU
    Intel Centrino Duo Processor - Intel Core 2 CPU.
    Memory
    4GB DDR2 [3.07GB maximum real available]
    Graphics card(s)
    nVidia GeForce Go 7300, 128MB
    Sound Card
    Realtek HD Audio, Ver. 6.0.1.5717, 2.08MB
    Monitor(s) Displays
    Acer Aspire Notebook - 15.4"; Acer LCD Monitor X223Wsd - 22".
    Screen Resolution
    1280x800x60Hertz [max.]
    Hard Drives
    Notebook - Samsung HM320JI 320GB HD installed 07 August 2009. External HDs [4];Maxtor One Touch4 - 500GB External HD [Drive M:\].Western Digital WDXMS1200TA - 120GB External HD [Drive G:\ - Windows Defender Backup Files only]. Two x LaCie 320GB Mobi
    Mouse
    Logitech Wireless V320 for Notebooks - Model M/N: M-RCD125
    Internet Speed
    Down 20000kb/sec / Up 1000kb/sec [Bigpond-Aus]
    Other Info
    Brother MFC-465CN; PC to Fax/Scan/Copy/Photo MFC. Epson Perfection V300 Photo Scanner. Siemens Speedstream 6520 Router. Wacom 'Bamboo Fun' CTE-650 PC Tablet, Stylus and Mouse. UAC - On;Activated. Browsers; [1] FireFox v3.6[2] IE8. Honorary R.S.M. to the 4th [Assault Pioneer] Troop Pune Sepoys , and 3rd Troop Jodhpur Bengali Lancers.
I tried FF when v3 came out. I wasent impressed. I still belive it is the best alternative to IE, however IE works best as far as I'm concerned.

Besides with being behind 3 sometimes 4 routers as well as all the software security there is no-way I can possibly be attacked.

Before the flamers get started!

Your wrong! I cannot be hacked. Or infected.
 

My Computer

System One

  • Manufacturer/Model
    My Ever Changing Whim!
    CPU
    Intel Core 2 Quad 9650
    Motherboard
    Intel DQ35JO
    Memory
    6GB Corsair DDR2 800
    Graphics card(s)
    ASUS 9800GT Ultimate
    Sound Card
    Onboard
    Monitor(s) Displays
    19 inch Sceptre 19 inch Acer
    Screen Resolution
    1280x1024
    Hard Drives
    1 320GB Seagate SATA 1 250GB Western Digital SATA 1 200GB Maxtor SATA 2x160GB Western Digitals SATA 1 320GB Seagate External 1 120GB Western Digital External 1 80GB Westen Digital External 1 4GB Crucial Flash Drive for Ready Boost
    PSU
    600watt Fortron Source
    Case
    Antec
    Cooling
    Fresh Air
    Mouse
    Razer Diamondback
    Keyboard
    Microsoft Natural Ergonamic 4000
    Other Info
    My main rig runs Vista Ultimate or Server 2008. Depending on which Acronis image I decide to load.
Any system can be broken into...that being said i'd say you're pretty well protected.
 

My Computer

System One

  • CPU
    Intel Q6600
    Motherboard
    ASUS P5K MBoard.
    Memory
    4G OCZ PC2 8500 Platinum
    Graphics card(s)
    EVGA 8800GTS Vid Card
    Hard Drives
    500G Seagate SATA 200G Seagate SATA 100G WD Caviar SATA 80G WD Caviar IDE
    PSU
    OCZ Elite 800W PSU
    Case
    RaidMax Smilodon Case
    Other Info
    Lite-On dual layer DVD burner X 2 Dos 6.2;Win2K;XP; & Vista Ultimate 64Bit.
I tried FF when v3 came out. I wasent impressed. I still belive it is the best alternative to IE, however IE works best as far as I'm concerned.

Besides with being behind 3 sometimes 4 routers as well as all the software security there is no-way I can possibly be attacked.

Before the flamers get started!

Your wrong! I cannot be hacked. Or infected.


I really hope you never ever regret those words:devil:
 

My Computer

System One

  • Manufacturer/Model
    Acer Aspire 5920gmi notebook
    CPU
    Intel Core 2 Duo T7300 2.00GHz
    Memory
    4GB
    Graphics card(s)
    NVIDIA GeForce 8600M GS
    Sound Card
    Realtek
    Screen Resolution
    1280 x 800 x 4294967296 colors
    Internet Speed
    crawl
Interesting list lol
 

My Computer

System One

  • CPU
    Intel Q6600
    Motherboard
    eVGA 790i Ultra
    Memory
    Corsair DDR3-1333 2 x 2Gb @ 1400mhz
    Graphics card(s)
    2 x eVGA GTX260 Super Clocked
    Hard Drives
    Seagate 80Gb, WD 640Gb and Ext 400Gb Storage
NEVER had any problems with Firefox.

May well be the case, but that doesn't mean you're safe.

If positions were reversed and FF3 had the market share that IE has today, then guess where the exploits would be being targetted?

As a matter of fact, Mozilla has released a fifth update to FF3 today which plugs some more vulnerabilities. Didn't see half as much copy or fuss about this, but then again it is an opportune moment to bury such news......
 
Last edited:

My Computer

System One

  • CPU
    Intel Pentium D: 3.4GHz
    Memory
    4GB
    Graphics card(s)
    NVidia 8800 GTS
IE7 is patched by MS, but what do you do with something like Citrix?
 

My Computer

System One

  • Manufacturer/Model
    Dell XPS720
    CPU
    Intel Quad Q6600 2.40GHz
    Motherboard
    Dell 0YU822, NVIDIA nForce 680i SLI SPP / SLI MCP
    Memory
    4GB DDR2 800MHz
    Graphics card(s)
    Gainward GeForce GTX 560 Ti, 1024 MB GDDR5
    Sound Card
    Creative SB X-Fi Xtreme Gamer
    Monitor(s) Displays
    Dell 2407WFP-HC
    Screen Resolution
    1920x1200
    Hard Drives
    NVIDIA 640GB SATA Raid 0 (2x320GB) (7200 rpm) for Vista, Intel X25-M G2 160 GB for W7, Maxtor OT III External HDD, WD Elements 1 TB External HDD
    Internet Speed
    100/20
    Other Info
    M779 PCIe PAL/SECAM/DVB-T Desktop TV Tuner. Broadcom NetXtreme 57xx Gigabit Controller.
Never had any problems with Firefox,but with IE7 there was always something or other,but i do think IE8 Beta 2 is ok,got some nice features.Also does anyone else find Firefox much faster? Maybe its my pc but firefox is considerably faster than IE,which is the main reason i use it,although i prefer the look n feel of IE.
 

My Computer

System One

  • Manufacturer/Model
    Own
    CPU
    AMD FX 8120 Black Edition,3.1GHz oc'd to 4GHz
    Motherboard
    Gigabyte GA-990FXA-UD7
    Memory
    Corsair Vengeance 12GB DDR3 1600Mhz
    Graphics card(s)
    EVGA GTX 570 HD SuperClocked
    Monitor(s) Displays
    24" BenQ EW2430 LED Monitor
    Screen Resolution
    1920x1080
    Hard Drives
    2TB Seagate ST2000DM001 Barracuda 7200,SATA 3 6GB/s. 128GB OCZ Octane, 2.5" SSD.
    PSU
    850W Powercool PCPC850AUBA
    Case
    Xclio Touch 767 Full Tower,With Touch Panel.
    Cooling
    Antec Kúhler H2O 620 Watercooler
    Mouse
    Sharkoon FireGlider Gaming Mouse
    Keyboard
    Razer Arctosa Black Edition Gaming Keyboard
    Internet Speed
    Virgin 30-35Mb/s
    Other Info
    Krator N4-21U26W Neso4 Avante Garde 2.1 Speaker
Re: List of 12 most vulnerable apps disputed.

"Experts are taking issue to a recent study which warned users of potential risk of using Firefox

A recent security study from Bit9 argued that Mozilla's Firefox was the most vulnerable application and thus a major threat to businesses. One of the chief reasons it gave was the lack of a large-network patching system. For this reason, despite recent security flaws, it did not consider Microsoft's Internet Explorer software, as it assumed that such a patching system dramatically lowered vulnerability.

Bit9 went as far as to suggest that enterprises block their employees from having access to Firefox and delete it from work computers.

Some firms, including Mozilla, were quick to take issue with Bit9's alarming comments. Representatives from Mozilla's security branch, Human Shield contacted DailyTech with remarks on the topic. The company's Johnathan Nightingale states, "While we're always happy to see stories that focus on educating our users about security, there are some problems with Bit9's methodology that hinder its ability to draw any meaningful conclusions."

According to Mr. Nightingale, by raising the "risk" of companies which disclose critical vulnerabilities, Bit9's study punishes openness, a critical key to security. It rewards companies that keep their vulnerabilities secret, he argues.

He also criticizes Bit9's stance on patching, stating that the firm's claims fall short of reality. He states, "Bit9 seems to understand (the need for smarter metrics) in its focus on application support for updates, but again it fails to account for the real world experience. Firefox does not deliver WSUS updates, but our built-in update mechanism requires no user intervention, and we consistently see 90% adoption within six days of a new update being released."

He concludes, "The Firefox vulnerabilities Bit9 discusses are long-since fixed, with the majority of these fixes coming within days of it being announced. That is the real measure of application security: are known vulnerabilities fixed promptly, tested carefully, and deployed thoroughly? Bug counting is unfortunately common because it's easy, but it should not be a substitute for real security measurement."

Similar sentiments were also echoed by various readers on DailyTech as well as several sources in the security business. While the Bit9 study certainly takes a controversial and interesting position, according to many its claims are overly broad and flawed. Whether this is the case is largely a matter of opinion, but one thing's for sure -- whether you're on Firefox, Opera, Chrome, or Internet Explorer, security is largely in the hands of the user."

DailyTech - Mozilla Disputes Bit9's Claim That Firefox is "Most Vulnerable App"




I too believe this list is fundamentally flawed in that it identifies programs to be included on the list by the fact that they do not have a "patch" system, but rely on new versions to repair flaws. Given the number of critical patches issued by IE during the same period I don't believe the fact that a manual updated, compared to an automatic update is sufficient reason to justify a program as being "inherently insecure".

Take a look here :-

Mozilla Firefox 3.x - Advisories by Product - Secunia Advisories - Vulnerability Intelligence - Secunia.com

Microsoft Internet Explorer 7.x - Advisories by Product - Secunia Advisories - Vulnerability Intelligence - Secunia.com

Having said that, I agree, all browsers are unsafe by design, like a car you need to learn how to "drive" safely. The only perfectly safe system is a stand-alone with no external access. In this age it's not possible. We allow so many programs to go through our firewalls, both software and hardware, that reliance on a firewall for protection is like taking a shower in a raincoat. The only solution is to take sensible precautions that offer a reasonable measure of protection and allow you to do what you want to do, with minimised risk, and be prepared for the worst happening by backing up data etc. that you can't afford to lose.

Norm
 

My Computer

System One

  • Manufacturer/Model
    Scratch Built
    CPU
    Intel Quad Core 6600
    Motherboard
    Asus P5B
    Memory
    4096 MB Xtreme-Dark 800mhz
    Graphics card(s)
    Zotac Amp Edition 8800GT - 512MB DDR3, O/C 700mhz
    Monitor(s) Displays
    Samsung 206BW
    Screen Resolution
    1680 X 1024
    Hard Drives
    4 X Samsung 500GB 7200rpm Serial ATA-II HDD w. 16MB Cache .
    PSU
    550 w
    Case
    Thermaltake
    Cooling
    3 x octua NF-S12-1200 - 120mm 1200RPM Sound Optimised Fans
    Mouse
    Targus
    Keyboard
    Microsoft
    Internet Speed
    1500kbs
    Other Info
    Self built.
Firefox isnt impressive... I prefer Safari and Chrome instead.
 

My Computer

System One

  • Manufacturer/Model
    Compaq
    CPU
    intel core 2 duo T 5550 @ 1.83 MHz
    Motherboard
    intel 965 chipset family
    Memory
    2 GB DDR 2 SD RAM @ 667 MHz
    Graphics card(s)
    On board upto 358 MB RAM
    Sound Card
    Onboard
    Monitor(s) Displays
    15"
    Hard Drives
    160 GB WDC
I don't think we ever will be or can be 100% safe.

I use Firefox because I like the Tabs, the few buttons by the back button like new tab, home, reload.

Also like how easy it is to find my bookmarks.

That's why I use Firefox!

Safari IMO blows.
 

My Computer

System One

  • Manufacturer/Model
    Asus Laptop's = the best by far!
    CPU
    Intel core 2 duo 2.5gig
    Motherboard
    Asus
    Memory
    4gigs DDR2
    Graphics card(s)
    Nvidia 9500m Gs 512mb
    Monitor(s) Displays
    15.4" laptop screen and 19" external
    Screen Resolution
    1440x900 and 1280x1224
    Hard Drives
    250 in the laptop, 750gig external
Didn't one of you guys from here make a web browser? what was it called again.... hey if its not on their list then its gotta be safe right? lol
 

My Computer

System One

  • Manufacturer/Model
    Me :P
    CPU
    Core 2 Quad Q6600
    Motherboard
    Abit IN9 32X MAX
    Memory
    8 GB OCZ PC2-6400 nVIDIA SLI-Ready Edition (4X2GB)
    Graphics card(s)
    AMP! GeForce GTX 260² 896MB 448-bit GDDR3 (650MHz/2100MHz
    Sound Card
    Realtek 7.1 CH HD Audio
    Monitor(s) Displays
    17" Fujitsu siemens TFT + 32" LG HD LCD TV
    Screen Resolution
    1280x1024 + 1360x768
    Hard Drives
    150GB Raptor HDD 500GB Caviar HDD
    PSU
    Thermaltake W0133RB 1200W PSU
    Case
    Antec 900
    Cooling
    Stock + Antec 900 case fans
    Mouse
    Logitech MX Revolution
    Keyboard
    Logitech G15 (full layout)
The most dangerous part for a browser, is the user.


Now that's true 100% x2 lol.

The user will download stuff, open anything, click on links, and do just about anything not thinking about what might happen lol.
 

My Computer

System One

  • Manufacturer/Model
    Asus Laptop's = the best by far!
    CPU
    Intel core 2 duo 2.5gig
    Motherboard
    Asus
    Memory
    4gigs DDR2
    Graphics card(s)
    Nvidia 9500m Gs 512mb
    Monitor(s) Displays
    15.4" laptop screen and 19" external
    Screen Resolution
    1440x900 and 1280x1224
    Hard Drives
    250 in the laptop, 750gig external
Gangsta Chimp.JPG
 

My Computers

System One System Two

  • Operating System
    Windows 10 Pro x64 Latest Release Preview
    Monitor(s) Displays
    Acer G276HL 27", (DVi) + Samsung 39" HDTV (HDMI)
    Screen Resolution
    2 x 1920x1080 @50Hz
  • Manufacturer/Model
    Real World Computers (Custom by Me)
    CPU
    AMD FX8350 Vishera 8 Core @4GHz
    Motherboard
    Asus M5A78L-M USB3
    Memory
    32GB [4x8GB] DDR3 1600 MHz
    Sound Card
    ASUS Xoner DG + SPDIF to 5.1 System + HDMI
    Monitor(s) Displays
    Samsung 32" TV
    Screen Resolution
    1920 x 1080
    Hard Drives
    Internal Crucial CT256MX100SSD1 256GB SSD, Seagate ST2000DM001-1CH1 2TB, External (USB3) Seagate Backup+ Hub BK SCSI Disk 8TB 2.5/3.5 Hot Swap Cradle, USB3 + eSata (client HDDs) NAS 4TB
    PSU
    Aerocool Templarius Imperator 750W 80+ Silver
    Case
    AeroCool X-Warrior Red Devil Tower
    Cooling
    Hyper103 CPU, Rear 120mm, Front 2x120mm, Side 2x120mm
    Internet Speed
    68 MB Down 18.5 MB Up
    Other Info
    Six Sensor Auto / Manual Digital cooling (Fan) control with Touch control Panel
Rotflmao
 

My Computer

System One

  • Manufacturer/Model
    Acer Aspire 5920gmi notebook
    CPU
    Intel Core 2 Duo T7300 2.00GHz
    Memory
    4GB
    Graphics card(s)
    NVIDIA GeForce 8600M GS
    Sound Card
    Realtek
    Screen Resolution
    1280 x 800 x 4294967296 colors
    Internet Speed
    crawl

My Computer

System One

  • Manufacturer/Model
    Scratch Built
    CPU
    Intel Quad Core 6600
    Motherboard
    Asus P5B
    Memory
    4096 MB Xtreme-Dark 800mhz
    Graphics card(s)
    Zotac Amp Edition 8800GT - 512MB DDR3, O/C 700mhz
    Monitor(s) Displays
    Samsung 206BW
    Screen Resolution
    1680 X 1024
    Hard Drives
    4 X Samsung 500GB 7200rpm Serial ATA-II HDD w. 16MB Cache .
    PSU
    550 w
    Case
    Thermaltake
    Cooling
    3 x octua NF-S12-1200 - 120mm 1200RPM Sound Optimised Fans
    Mouse
    Targus
    Keyboard
    Microsoft
    Internet Speed
    1500kbs
    Other Info
    Self built.

My Computer

System One

  • Manufacturer/Model
    Acer Aspire Notebook 5633WLMi.[5630 Series]
    CPU
    Intel Centrino Duo Processor - Intel Core 2 CPU.
    Memory
    4GB DDR2 [3.07GB maximum real available]
    Graphics card(s)
    nVidia GeForce Go 7300, 128MB
    Sound Card
    Realtek HD Audio, Ver. 6.0.1.5717, 2.08MB
    Monitor(s) Displays
    Acer Aspire Notebook - 15.4"; Acer LCD Monitor X223Wsd - 22".
    Screen Resolution
    1280x800x60Hertz [max.]
    Hard Drives
    Notebook - Samsung HM320JI 320GB HD installed 07 August 2009. External HDs [4];Maxtor One Touch4 - 500GB External HD [Drive M:\].Western Digital WDXMS1200TA - 120GB External HD [Drive G:\ - Windows Defender Backup Files only]. Two x LaCie 320GB Mobi
    Mouse
    Logitech Wireless V320 for Notebooks - Model M/N: M-RCD125
    Internet Speed
    Down 20000kb/sec / Up 1000kb/sec [Bigpond-Aus]
    Other Info
    Brother MFC-465CN; PC to Fax/Scan/Copy/Photo MFC. Epson Perfection V300 Photo Scanner. Siemens Speedstream 6520 Router. Wacom 'Bamboo Fun' CTE-650 PC Tablet, Stylus and Mouse. UAC - On;Activated. Browsers; [1] FireFox v3.6[2] IE8. Honorary R.S.M. to the 4th [Assault Pioneer] Troop Pune Sepoys , and 3rd Troop Jodhpur Bengali Lancers.

My Computer

System One

  • Manufacturer/Model
    Self Built
    CPU
    i7 3770K HT ON 4.7GHz
    Motherboard
    P8Z68 Deluxe Gen 3
    Memory
    8GB G.Skill Ripjaws X 2133mhz
    Graphics card(s)
    2x Gigabyte GTX 670 OC WindForce SLI
    Sound Card
    X-FI Forte + ATH-AD900
    Monitor(s) Displays
    x2 Dell U2410 / 58" Samsung / "40 Sony
    Screen Resolution
    1920*1200 / 1920x1080
    Hard Drives
    2x Intel 520 240GB * Crucial M4 128GB * 2x Samsung F3 1TB (RAID 0) * 2x WD Caviar Blacks 2TB (RAID 0)
    PSU
    Corsair AX1200W
    Case
    Lian Li PC-V1020A
    Cooling
    NH-D14: 3x140mm Gelid Wing 14: Sunbeam Rheobus Extreme
    Mouse
    Razer Imperator + Thermaltake Theron
    Keyboard
    Topre Realforce // Ducky Shine Cherry MX Black
    Other Info
    Laptop Specs: Clevo Sager P170HM // 17.3 Matte 1920x1200 // i7 2720QM // 8GB 1333mhz // Dedicated GTX 485M // 240GB Intel 520 + 750GB + Blu-Ray // Samsung Story 2TB USB 3.0
Back
Top