Feeds

Firefox went ton up in bugs in 2008

Secunia stats inflame browser beef

Combat fraud and increase customer satisfaction

Firefox had more vulnerabilities than Internet Explorer last year, but zero-day threats to the Mozilla browser were fixed more quickly than those affecting IE.

An annual scorecard report from security notification firm Secunia found that Firefox was hit by 115 security flaws in 2008, more than the combined number of its three main competitors: Internet Explorer (31), Opera (30), and Safari (32).

But Mozilla was far more adept at dealing with the appearance of zero-day vulnerabilities than Microsoft, according to Secunia. It reports that Mozilla took an average of 43 days to deal with three such incidents last year, not all of which covered critical flaws.

Meanwhile, Microsoft took an average of 100 days to deal with three zero-day flaws, the worst of which Secunia describes as "high risk." Three other less serious IE flaws that emerged last year remain unpatched.

In 2008, the security notification firm handed out its highest "extremely critical" with 11 advisories - a sharp increase from just two in 2007. On a more positive note, the number of zero-day vulnerabilities across all software packages decreased from 20 in 2007 to 12 in 2008.

Secunia's report includes stats from its patching assessment tool, Secunia PSI, which is free for consumers. These show Firefox 2.0 is unpatched one in three time (34 per cent). That's poor, but figures for Macromedia Flash Player 6.x (unpatched 83 per cent of the time) and Sun Java JRE 1.5.x/5.x (96 per cent) are far worse.

"Too many users give up patching software when it is not straightforward," Secunia reports. "Many choose to handle the applications that are easy-to-patch, whereas the applications that take longer or are difficult to patch are simply ignored."

Secunia also looked at the number of security bugs last year affecting browser plugs. Duff ActiveX controls accounted for 366 flaws last year, far dwarfing bugs particular to Java (54), Flash (19), and QuickTime plugins (30).

Secunia's complete 17-page report, which is liberally sprinkled with graphs, can be found here (pdf). ®

3 Big data security analytics techniques

More from The Register

next story
This time it's 'Personal': new Office 365 sub covers just two devices
Redmond also brings Office into Google's back yard
Batten down the hatches, Ubuntu 14.04 LTS due in TWO DAYS
Admins dab straining server brows in advance of Trusty Tahr's long-term support landing
Inside the Hekaton: SQL Server 2014's database engine deconstructed
Nadella's database sqares the circle of cheap memory vs speed
Microsoft lobs pre-release Windows Phone 8.1 at devs who dare
App makers can load it before anyone else, but if they do they're stuck with it
Half of Twitter's 'active users' are SILENT STALKERS
Nearly 50% have NEVER tweeted a word
Oh no, Joe: WinPhone users already griping over 8.1 mega-update
Hang on. Which bit of Developer Preview don't you understand?
Internet-of-stuff startup dumps NoSQL for ... SQL?
NoSQL taste great at first but lacks proper nutrients, says startup cloud whiz
Windows 8.1, which you probably haven't upgraded to yet, ALREADY OBSOLETE
Pre-Update versions of new Windows version will no longer support patches
IRS boss on XP migration: 'Classic fix the airplane while you're flying it attempt'
Plus: Condoleezza Rice at Dropbox 'maybe she can find ... weapons of mass destruction'
prev story

Whitepapers

Top three mobile application threats
Learn about three of the top mobile application security threats facing businesses today and recommendations on how to mitigate the risk.
Combat fraud and increase customer satisfaction
Based on their experience using HP ArcSight Enterprise Security Manager for IT security operations, Finansbank moved to HP ArcSight ESM for fraud management.
The benefits of software based PBX
Why you should break free from your proprietary PBX and how to leverage your existing server hardware.
Five 3D headsets to be won!
We were so impressed by the Durovis Dive headset we’ve asked the company to give some away to Reg readers.
SANS - Survey on application security programs
In this whitepaper learn about the state of application security programs and practices of 488 surveyed respondents, and discover how mature and effective these programs are.