Firefox tops list of 12 most vulnerable apps

Firefox tops list of 12 most vulnerable apps
Written by Ryan Naraine @ 10:41 am 12/15/2008


Mozilla’s flagship Firefox browser has earned the dubious title of the most vulnerable software program running on the Windows platform.

According to application whitelisting vendor Bit9, Firefox topped the list of 12 widely deployed desktop applications that suffered through critical security vulnerabilities in 2008. These flaws exposed millions of Windows users to remote code execution attacks.

The other applications on the list are all well-known and range from browsers to media players, to VOIP chat and anti-virus software programs. Here’s Bit9’s dirty dozen:


Read more at the source:
Firefox tops list of 12 most vulnerable apps | Zero Day | ZDNet.com
 
But I hope its always better than IE . Recently there were rumors across the web stating the security vulnerability in IE !!

There are always rumors stating IE's securuty vulnerabilities. Often because they are true ;)

The only 100% safe way to browse is to not use a computer :p
 

My Computer

System One

  • Manufacturer/Model
    Self Built
    CPU
    i7 3770K HT ON 4.7GHz
    Motherboard
    P8Z68 Deluxe Gen 3
    Memory
    8GB G.Skill Ripjaws X 2133mhz
    Graphics card(s)
    2x Gigabyte GTX 670 OC WindForce SLI
    Sound Card
    X-FI Forte + ATH-AD900
    Monitor(s) Displays
    x2 Dell U2410 / 58" Samsung / "40 Sony
    Screen Resolution
    1920*1200 / 1920x1080
    Hard Drives
    2x Intel 520 240GB * Crucial M4 128GB * 2x Samsung F3 1TB (RAID 0) * 2x WD Caviar Blacks 2TB (RAID 0)
    PSU
    Corsair AX1200W
    Case
    Lian Li PC-V1020A
    Cooling
    NH-D14: 3x140mm Gelid Wing 14: Sunbeam Rheobus Extreme
    Mouse
    Razer Imperator + Thermaltake Theron
    Keyboard
    Topre Realforce // Ducky Shine Cherry MX Black
    Other Info
    Laptop Specs: Clevo Sager P170HM // 17.3 Matte 1920x1200 // i7 2720QM // 8GB 1333mhz // Dedicated GTX 485M // 240GB Intel 520 + 750GB + Blu-Ray // Samsung Story 2TB USB 3.0
whitelisting vendor Bit9, Firefox topped the list of 12 widely deployed desktop applications that suffered through critical security vulnerabilities in 2008. These flaws exposed millions of Windows users to remote code execution attacks.
 

My Computer

whitelisting vendor Bit9, Firefox topped the list of 12 widely deployed desktop applications that suffered through critical security vulnerabilities in 2008. These flaws exposed millions of Windows users to remote code execution attacks.
This has been discussed ad nauseum in this forum. It's a flawed study, do some more research

Norm
 

My Computer

System One

  • Manufacturer/Model
    Scratch Built
    CPU
    Intel Quad Core 6600
    Motherboard
    Asus P5B
    Memory
    4096 MB Xtreme-Dark 800mhz
    Graphics card(s)
    Zotac Amp Edition 8800GT - 512MB DDR3, O/C 700mhz
    Monitor(s) Displays
    Samsung 206BW
    Screen Resolution
    1680 X 1024
    Hard Drives
    4 X Samsung 500GB 7200rpm Serial ATA-II HDD w. 16MB Cache .
    PSU
    550 w
    Case
    Thermaltake
    Cooling
    3 x octua NF-S12-1200 - 120mm 1200RPM Sound Optimised Fans
    Mouse
    Targus
    Keyboard
    Microsoft
    Internet Speed
    1500kbs
    Other Info
    Self built.
Considering I do a small amount of website design, I run IE, Firefox, Chrome and Opera, with Opera being my browser of choice. I probably should load on Safari too

I guess I'm currently 4x as vulnerable

Or maybe I should stop visiting those Russian websites ...
 

My Computer

System One

  • CPU
    AMD x2 Dual Core 3600+ 1.9GHz
    Motherboard
    GigaByte GA-M55SLI-S4
    Memory
    2GB DDR PC2 5300 RAM
    Graphics card(s)
    NVidia GeForce GTS 250 512mb
whitelisting vendor Bit9, Firefox topped the list of 12 widely deployed desktop applications that suffered through critical security vulnerabilities in 2008. These flaws exposed millions of Windows users to remote code execution attacks.

Just to put things into perspective, the security of a system is entirely dependant on the end user having the common sense to have in place, all the applications as they fell necessary to protect their system, however loose or tight they wish it to be.

This also includes subscribing to sites that provide ample warning of vulnerabilities, and in some cases, work-around fixes. The more 'protective' information gathered, the better prepared the user is for any security 'attack'.

Having said that, I switched to Firefox 3 at the time of the last IE7 fiasco, and on the back of some very good advice, freely given by Members of this Forum and also contained in a number of various articles that I researched without prompt.

Throughout the IE7 fiasco, I hum'd and haw'd as for days I tried to stay up with MS Security Notifications advising of this and that work-around fix. And all for what?? To continue with a browser where IE7 was constantly telling me "Internet Explorer has stopped unexpectedly, and has restarted", sometimes up to five or six times a session?? No way.....I'd had enough!!

Four weeks ago, I switched to Firefox 3 and quite frankly, haven't looked back. FF3 loads far quicker than IE7 ever did, has all the protective and other add-ons that I could ever wish for, and the interactive features are brilliant. Not only is it very easy to navigate, by far the best part is that it has NOT ONCE FAILED OR STOPPED UNEXPECTEDLY during a session, even with multi-windows open......IE7 could NEVER handle it!

I have my protective measure in place........it's called Firefox 3 and Add-ons, plus my AV etc., of course.
 

My Computer

System One

  • Manufacturer/Model
    Acer Aspire Notebook 5633WLMi.[5630 Series]
    CPU
    Intel Centrino Duo Processor - Intel Core 2 CPU.
    Memory
    4GB DDR2 [3.07GB maximum real available]
    Graphics card(s)
    nVidia GeForce Go 7300, 128MB
    Sound Card
    Realtek HD Audio, Ver. 6.0.1.5717, 2.08MB
    Monitor(s) Displays
    Acer Aspire Notebook - 15.4"; Acer LCD Monitor X223Wsd - 22".
    Screen Resolution
    1280x800x60Hertz [max.]
    Hard Drives
    Notebook - Samsung HM320JI 320GB HD installed 07 August 2009. External HDs [4];Maxtor One Touch4 - 500GB External HD [Drive M:\].Western Digital WDXMS1200TA - 120GB External HD [Drive G:\ - Windows Defender Backup Files only]. Two x LaCie 320GB Mobi
    Mouse
    Logitech Wireless V320 for Notebooks - Model M/N: M-RCD125
    Internet Speed
    Down 20000kb/sec / Up 1000kb/sec [Bigpond-Aus]
    Other Info
    Brother MFC-465CN; PC to Fax/Scan/Copy/Photo MFC. Epson Perfection V300 Photo Scanner. Siemens Speedstream 6520 Router. Wacom 'Bamboo Fun' CTE-650 PC Tablet, Stylus and Mouse. UAC - On;Activated. Browsers; [1] FireFox v3.6[2] IE8. Honorary R.S.M. to the 4th [Assault Pioneer] Troop Pune Sepoys , and 3rd Troop Jodhpur Bengali Lancers.

My Computer

System One

  • Manufacturer/Model
    Self Built
    CPU
    i7 3770K HT ON 4.7GHz
    Motherboard
    P8Z68 Deluxe Gen 3
    Memory
    8GB G.Skill Ripjaws X 2133mhz
    Graphics card(s)
    2x Gigabyte GTX 670 OC WindForce SLI
    Sound Card
    X-FI Forte + ATH-AD900
    Monitor(s) Displays
    x2 Dell U2410 / 58" Samsung / "40 Sony
    Screen Resolution
    1920*1200 / 1920x1080
    Hard Drives
    2x Intel 520 240GB * Crucial M4 128GB * 2x Samsung F3 1TB (RAID 0) * 2x WD Caviar Blacks 2TB (RAID 0)
    PSU
    Corsair AX1200W
    Case
    Lian Li PC-V1020A
    Cooling
    NH-D14: 3x140mm Gelid Wing 14: Sunbeam Rheobus Extreme
    Mouse
    Razer Imperator + Thermaltake Theron
    Keyboard
    Topre Realforce // Ducky Shine Cherry MX Black
    Other Info
    Laptop Specs: Clevo Sager P170HM // 17.3 Matte 1920x1200 // i7 2720QM // 8GB 1333mhz // Dedicated GTX 485M // 240GB Intel 520 + 750GB + Blu-Ray // Samsung Story 2TB USB 3.0
Why isn't IE on this list? In my opinion this is a joke. FF is one of the most secure browsers out their.
 

My Computer

System One

  • Manufacturer/Model
    Gateway: GM5472
    CPU
    AMD Athlon(tm) 64 X2 Dual Core Processor 5000+ (2 CPUs), ~2.
    Memory
    4
    Graphics card(s)
    ATI Radeon HD 3650
    Cooling
    Dynex
    Keyboard
    Dynex
Why isn't IE on this list? In my opinion this is a joke. FF is one of the most secure browsers out their.

It's not there because it didn't fit into the rules, meaning because MS release patches for it that can ultimately be passed on "on mass" throughout a network (assuming the sys admin allows it), IE is therefore deemed less vulnerable.

FFs beef with this is clear and well made, considering they patch their software without any user interaction and stats that, admittedly they have probably gathered, suggest that 90% of their users have FF patched within a week of release.

Someone else posted something along these lines, but in far more detail, which I would refer too if I wasn't so lazy
 

My Computer

System One

  • CPU
    AMD x2 Dual Core 3600+ 1.9GHz
    Motherboard
    GigaByte GA-M55SLI-S4
    Memory
    2GB DDR PC2 5300 RAM
    Graphics card(s)
    NVidia GeForce GTS 250 512mb
Why isn't IE on this list? In my opinion this is a joke. FF is one of the most secure browsers out their.

It's not there because it didn't fit into the rules, meaning because MS release patches for it that can ultimately be passed on "on mass" throughout a network (assuming the sys admin allows it), IE is therefore deemed less vulnerable.

FFs beef with this is clear and well made, considering they patch their software without any user interaction and stats that, admittedly they have probably gathered, suggest that 90% of their users have FF patched within a week of release.

Someone else posted something along these lines, but in far more detail, which I would refer too if I wasn't so lazy
You have a point. It just seems where ever you go people are saying IE is easy to hack or something like that, that you don't even look at the facts anymore.
 

My Computer

System One

  • Manufacturer/Model
    Gateway: GM5472
    CPU
    AMD Athlon(tm) 64 X2 Dual Core Processor 5000+ (2 CPUs), ~2.
    Memory
    4
    Graphics card(s)
    ATI Radeon HD 3650
    Cooling
    Dynex
    Keyboard
    Dynex
Most of these reports hitting headlines are paid for and so made with certain conditions which can only give 1 result - the wanted :) Not the first time or the last.

Secunia have made same mistake of comparing what cant be compared Read past the headlines - Firefox is fixed faster at Mozilla Security Blog

Symantec too, Google it - think they retracted after Mozilla got pissed off! 1 year ago or so.
 

My Computer

System One

  • CPU
    AMD X2 6000
    Motherboard
    Gigabyte GA-MA790FX-DS5
    Memory
    Corsair 4x1gb 6400C4
    Graphics card(s)
    XFX 8800GTS XT 320mb, Generic Nvidia 6200 PCI 128mb
    Sound Card
    Onboard Realtek ALC889A
    Monitor(s) Displays
    24" Samsung 245b, 20" Dell 2007WFP, 19" Samsung 193P
    Hard Drives
    WD Raptor 74gb, Maxtor 300gb, WD Caviar 16SE 500gb
    PSU
    Corsair 520W
    Case
    Cooler Master Centurion 532
    Mouse
    Logitech MX1100R
    Keyboard
    Logitech G15
    Internet Speed
    20mb down, 1mb up
Back
Top