On GameSpot: Wii Fit tells 10-year-old she's fat
BNET Business Network:
BNET
TechRepublic
ZDNet

By Tom Espiner
Posted on ZDNet News: Sep 19, 2005 8:10:00 PM

Mozilla Web browsers are potentially more vulnerable to attack than Microsoft's Internet Explorer, according to a Symantec report.

But the report, released Monday, also found that hackers are still focusing their efforts on IE.

The open-source Mozilla Foundation browsers, such as the popular Firefox, have typically been seen as more secure than IE, which has suffered many security problems in the past. Mitchell Baker, president of the foundation, said earlier this year that its browsers were fundamentally more secure than IE. She also predicted that Mozilla Foundation browsers would not face as many problems as IE, even as their market share grows.

Symantec's Internet Security Threat Report Volume VIII contains data for the first six months of this year that may contradict this perception.

According to the report, 25 vendor-confirmed vulnerabilities were disclosed for the Mozilla browsers during the first half of 2005, "the most of any browser studied," the report's authors stated. Eighteen of these flaws were classified as high severity.

"During the same period, 13 vendor-confirmed vulnerabilities were disclosed for IE, eight of which were high severity," the report noted.

The average severity rating of the vulnerabilities associated with both IE and Mozilla browsers in this period was classified as "high", which Symantec defined as "resulting in a compromise of the entire system if exploited."

The Mozilla Foundation did not immediately respond to requests for comment.

Symantec reported that the gap between vulnerabilities being reported and exploit code being released has dropped to six days on average. However, it's not clear from the report how quickly Microsoft and Mozilla released patches for their respective vulnerabilities, or how many of the vulnerabilities were targeted by hackers, though Microsoft generally releases patches only on a monthly basis.

Symantec admitted that "at the time of writing, no widespread exploitation of any browser except Microsoft Internet Explorer has occurred," but added that it "expects this to change as alternative browsers become increasingly widely deployed."

There is one caveat: Symantec counts only those security flaws that have been confirmed by the vendor. According to security monitoring company Secunia, there are 19 security issues that Microsoft still has to deal with for Internet Explorer, while there are only three for Firefox.

The report also highlighted a trend away from the focus of security being on "servers, firewalls, and other systems with external exposure." Instead, "client-side systems--primarily end-user systems--(are) becoming increasingly prominent targets of malicious activity."

Web browser vulnerabilities are becoming a preferred entry point into systems, the report stated. It also highlighted the trend of hackers operating for financial gain rather than recognition, increased potential exposure of confidential information, and a "dramatic increase in malicious code variants".

Tom Espiner of ZDNet UK reported from London. CNET News.com's Joris Evers contributed to this report.

  • Talkback
  • Most Recent of 324 Talkback(s)
Misposted
I just discovered your reply while surfing another subject many months later, and now realize I misunderstood the original point you were making. The JS at our site is not malevolent, of course -- as you can easily see for yourself. My bad. Apologies. (I also use FF, BTW, not the other one.)... (Read the rest)
Posted by: code_flogger Posted on: 08/06/06 You are currently: Logged In as: a Guest  | Login | Terms of Use
Here's the Important Part  coffeenite | 09/19/05
This is a stupid article anyway  IceTheNet@... | 09/19/05
exactly..like anyone worht anything takes Symantec seriously anymore  Jeff Spicoli | 09/19/05
We Are Much Better Off Getting Advice From YOU?  PMC-CON | 09/19/05
no, mindless twits like you should keep listening to Microsoft and Symantec  Jeff Spicoli | 09/19/05
Mindless twits aye?  golowenow | 09/19/05
Aye aye matey!  Jeff Spicoli | 09/19/05
McAfee is free on Comcast  golowenow | 09/20/05
I NEVER get nothing  YaBaby | 09/21/05
PMC-CON  brian ansorge | 09/20/05
symantec has been the target for some viruses lately...  linuxoverwindows | 09/19/05
NAV & McAfee have been disappointing as of late  sctang73@... | 09/20/05
doesn't matter either way  al881 | 09/20/05
It's been a long time, too  Update victim | 09/20/05
BS?  D-Ram | 09/20/05
Norton was great - Symantic SUCKS!  The Computer Pimp | 09/20/05
Very Laughable NAV Sucks  IceTheNet@... | 09/21/05
...and your posting is idiotic  cicuta | 09/20/05
Learning to read should be your priority  IceTheNet@... | 09/21/05
and learning to write should be yours  cicuta | 09/22/05
And minding your own business should be yours  IceTheNet@... | 09/23/05
19 to 3  jim@... | 09/19/05
finish the line...  linuxoverwindows | 09/19/05
This report is a joke!!  FreeBSD | 09/20/05
Symantec and Microsoft are joined at the hip  RobertoSalazar | 09/19/05
SYM + MS  rickearley | 09/19/05
Join at the hip ooooh yeah  bcbooks | 09/20/05
And where is the Linux version of Symantec?  johnlb2002 | 09/20/05
Sure! They make billions out of 'securing' IE why would they like  michael_t | 09/19/05
All that says  I_am_hellion_z | 09/19/05
fact or fiction  voska | 09/21/05
and..  D-Ram | 09/20/05
so what? at least IE is not only browers anymore  M_c | 09/19/05
they have  b_ruce | 09/19/05
Except...  thetargos | 09/20/05
In hindsight  IT_User | 09/19/05
Well  IT Scion | 09/20/05
Agreed and  Sheeva | 09/21/05
Another Thing  RobertoSalazar | 09/19/05
Another thing redacted  cdgoldin | 09/19/05
IE vs FF "reality"  cgraham_z | 09/19/05
would you rather ff tell everyone how to hack you  IceTheNet@... | 09/19/05
Symantec...The Standard of Non-Credibility  slingzenarrowzuvowtrayjissforchin | 09/19/05
Transparent attempt to safeguard their source of income  michael_t | 09/19/05
Actually, FireFox is based on very mature code ...  OldFossil | 09/19/05
How old is the Gecko engine?  michael_t | 09/19/05
There amounts of time for their rendering engines are that different  IT Scion | 09/20/05
Not really  michael_t | 09/20/05
Not really  michael_t | 09/20/05
yes really  IT Scion | 09/20/05
Mature or old and feeble?  cdgoldin | 09/19/05
Learn, then talk  radicaldude | 09/19/05
Why did you miss this?  michael_t | 09/19/05
Prove It  node357 | 09/19/05
Incorrect Information!!  xjahn | 09/19/05
Your logic sucks  NonZealot | 09/19/05
your "logic" didn't take us any further  Jeff Spicoli | 09/19/05
Your logic is ... impeccable... Kudos.  michael_t | 09/19/05
Well, I'm no Einstein!  NonZealot | 09/19/05
dude, you TOTALLY invalidated yourself  Jeff Spicoli | 09/19/05
Your not quite getting it  richardthegreat | 09/20/05
Logic very flawed  AmusedAtItAll | 09/20/05
You would be  voska | 09/21/05
Nice rant  IT Scion | 09/20/05
Shut up and get back to work or get a life  Jeff the god of biscuits | 09/20/05
I agree  djc1309@... | 09/20/05
Here's a fact for you ...  I_am_hellion_z | 09/19/05
wrong  Jeff Spicoli | 09/19/05
Where is the fact? The "better moustrap"?  michael_t | 09/19/05
Fact is, its vulnerable and therefore insecure.  darreno1 | 09/19/05
Re: Fact is, its vulnerable and therefore insecure.  nightshade0143 | 09/20/05
As FF gains market share the attacks will increase..  darreno1 | 09/20/05
well you forgot about repair ratio.  IceTheNet@... | 09/20/05
It also depends on your OS  Chad_z | 09/20/05
And the beat goes on ...  OldFossil | 09/19/05
These type of stats won't matter until  Real World | 09/19/05
oops  Real World | 09/19/05
I respectfully disagree ...  OldFossil | 09/19/05
I'm not saying  Real World | 09/19/05
Can't say I've ever heard that  voska | 09/19/05
It wasn't in the  Real World | 09/20/05
Exactly why I don't let my family  ebrke | 09/20/05
MOZILLA VS. IE  mesmd | 09/19/05
HYPE VS. REALITY  cdgoldin | 09/19/05
First thing you said that makes any sense  IceTheNet@... | 09/20/05
Exactly  IT Scion | 09/20/05
Better than Opera's?? Not in thousand years!  markbn | 09/20/05
opera is a good browser but  IceTheNet@... | 09/23/05
RE: opera is a good browser but  markbn | 09/24/05
your confused  IceTheNet@... | 09/24/05
RE: your (sic) confused  markbn | 09/25/05
Spelling  realoldnavyretired | 09/21/05
Doubletalk from Symantec  dhryder | 09/19/05
So True....  EBathory | 09/19/05
At least one has come true  node357 | 09/19/05
Most end up WIN PC anyway  rock06r | 09/20/05
Only time will tell who will rein supreme  liqour43@... | 09/19/05
Quality vs. Bottom Line  talontamer | 09/19/05
AV is a community responsibility  node357 | 09/19/05
so you would be ok infecting everyone else?  rock06r | 09/20/05
Faulty Comparison  dl@... | 09/19/05
Firefox is based on older software  mnordhoff | 09/20/05
RE: Faulty Comparison  HerbieHightower | 09/20/05
Ummm  IT Scion | 09/20/05
For total computer safety....  Shutterbug | 09/19/05
RE For total computer safety....  OmarZewddie | 09/20/05
Most of you are in denial  balsover | 09/19/05
True, but.....  todbran@... | 09/19/05
You are dreaming  balsover | 09/19/05
Good luck...  PeregrineFalcon | 09/19/05
Do those exploits...  balsover | 09/19/05
Locked Down Users  PMC-CON | 09/19/05
Disable ActiveX....  todbran@... | 09/19/05
You are ignorant.  balsover | 09/19/05
BTW Flash is ActiveX If You Let It Be ... (nt)  PMC-CON | 09/19/05
Then it is a problem. nt  balsover | 09/19/05
Not exactly.  enduser_z | 09/19/05
then do not run that page  balsover | 09/19/05
You'd be able to run the page..  TheSickEmpire | 09/19/05
You sure can  voska | 09/19/05
most of the flashy sites these days  balsover | 09/19/05
Turning off ActiveX is not needed.  IT Scion | 09/21/05
ActiveX  IT Scion | 09/20/05
Right right .... Mozilla developers are in denial  michael_t | 09/19/05
Actually I said that you were in denial  balsover | 09/19/05
So true.  darreno1 | 09/19/05
Says The Guy Who Never Used FF  nikoli | 09/20/05
Let me tell you....  todbran@... | 09/19/05
You are aware  Real World | 09/19/05
Also...  toadlife | 09/19/05
Duhhhh  todbran@... | 09/19/05
See response above...  PeregrineFalcon | 09/19/05
How do you stop the popups?  enduser_z | 09/19/05
USE FF  IceTheNet@... | 09/19/05
Hardly anyone complains.  Real World | 09/20/05
of course they would loose their job  IceTheNet@... | 09/20/05
Where to begin  Real World | 09/20/05
typos  IceTheNet@... | 09/21/05
People who don't understand security...  Sxooter_z | 09/19/05
Then There's The Other Method...  slingzenarrowzuvowtrayjissforchin | 09/19/05
and a 3rd method  IceTheNet@... | 09/19/05
Nonsense!  cdgoldin | 09/19/05
OK Here We Go!  IceTheNet@... | 09/19/05
Yes, please do go on  cdgoldin | 09/19/05
OK well I see there is no ignorance in your family  IceTheNet@... | 09/19/05
Place them where you want  IceTheNet@... | 09/19/05
I had Norton and McCaffee  s_gamgee | 09/21/05
Huray  IceTheNet@... | 09/23/05
Go get em!  golowenow | 09/19/05
Oooooooooooo-kay  Henaway | 09/19/05
Active x? Plugins? What the dif??  golowenow | 09/19/05
You should be fired  IceTheNet@... | 09/19/05
Message has been deleted.  balsover | 09/19/05
Message has been deleted.  IceTheNet@... | 09/19/05
well they deleted a good message  IceTheNet@... | 09/19/05
Apparently overweight and illiterate as well...  Scrat | 09/20/05
Oh please...  itanal | 09/20/05
Message has been deleted.  IceTheNet@... | 09/20/05
Message has been deleted.  RobX2005 | 09/20/05
Message has been deleted.  itanal | 09/20/05
ZDnet Scum Bag Editors  IceTheNet@... | 09/21/05
I was just proving a point that ZDnet Deleted  IceTheNet@... | 09/21/05
Why not burned at the stake?  cdgoldin | 09/19/05
Oops. Make that "TalkBack".. (NT)  cdgoldin | 09/19/05
Message has been deleted.  IceTheNet@... | 09/19/05
Unsupported opinion is not fact, no matter how many times you say it is  cdgoldin | 09/19/05
Oh I C you can say orifice but not as  IceTheNet@... | 09/19/05
Spelling lesson for you???  livewire^ | 09/21/05
Firefox vulnerabilities  Peronthious | 12/07/05
vulnerabilities: 31 for IE vs 28 for Firefox  dabruro | 09/19/05
Not the same time frame  george_ou | 09/19/05
If those older ones are still  Linux Guy 1000 | 09/19/05
That's the funniest explanation I've heard yet...  ju1ce | 09/20/05
The bottom line  georgep_z | 09/19/05
Ever get tired of idiot fanboys?  ThinkAboutIt | 09/19/05
I get tired of idiots period.  IceTheNet@... | 09/19/05
Don't help him out with his spelling.  Grayson Peddie | 09/19/05
Yes and as has been  Linux Guy 1000 | 09/19/05
Ask and ye shall be informed  cdgoldin | 09/19/05
Doesn't really matter  IceTheNet@... | 09/19/05
JVM Scripts?  PMC-CON | 09/20/05
For PCM-CON  IceTheNet@... | 09/22/05
99% of the sites I write use JS  Jeff the god of biscuits | 09/19/05
I have an idea  Linux Guy 1000 | 09/20/05
Amen to that (nt)  IT Scion | 09/21/05
Just FYI  IceTheNet@... | 09/19/05
That's nice an all but....  darreno1 | 09/19/05
True True True  IceTheNet@... | 09/19/05