On GameSpot: Metal Gear Online and more On the Spot
BNET Business Network:
BNET
TechRepublic
ZDNet

By Tom Espiner, News.com
Posted on ZDNet News: Sep 19, 2005 8:10:00 PM

Mozilla Web browsers are potentially more vulnerable to attack than Microsoft's Internet Explorer, according to a Symantec report.

But the report, released Monday, also found that hackers are still focusing their efforts on IE.

The open-source Mozilla Foundation browsers, such as the popular Firefox, have typically been seen as more secure than IE, which has suffered many security problems in the past. Mitchell Baker, president of the foundation, said earlier this year that its browsers were fundamentally more secure than IE. She also predicted that Mozilla Foundation browsers would not face as many problems as IE, even as their market share grows.

Symantec's Internet Security Threat Report Volume VIII contains data for the first six months of this year that may contradict this perception.

According to the report, 25 vendor-confirmed vulnerabilities were disclosed for the Mozilla browsers during the first half of 2005, "the most of any browser studied," the report's authors stated. Eighteen of these flaws were classified as high severity.

"During the same period, 13 vendor-confirmed vulnerabilities were disclosed for IE, eight of which were high severity," the report noted.

The average severity rating of the vulnerabilities associated with both IE and Mozilla browsers in this period was classified as "high", which Symantec defined as "resulting in a compromise of the entire system if exploited."

The Mozilla Foundation did not immediately respond to requests for comment.

Symantec reported that the gap between vulnerabilities being reported and exploit code being released has dropped to six days on average. However, it's not clear from the report how quickly Microsoft and Mozilla released patches for their respective vulnerabilities, or how many of the vulnerabilities were targeted by hackers, though Microsoft generally releases patches only on a monthly basis.

Symantec admitted that "at the time of writing, no widespread exploitation of any browser except Microsoft Internet Explorer has occurred," but added that it "expects this to change as alternative browsers become increasingly widely deployed."

There is one caveat: Symantec counts only those security flaws that have been confirmed by the vendor. According to security monitoring company Secunia, there are 19 security issues that Microsoft still has to deal with for Internet Explorer, while there are only three for Firefox.

The report also highlighted a trend away from the focus of security being on "servers, firewalls, and other systems with external exposure." Instead, "client-side systems--primarily end-user systems--(are) becoming increasingly prominent targets of malicious activity."

Web browser vulnerabilities are becoming a preferred entry point into systems, the report stated. It also highlighted the trend of hackers operating for financial gain rather than recognition, increased potential exposure of confidential information, and a "dramatic increase in malicious code variants".

Tom Espiner of ZDNet UK reported from London. CNET News.com's Joris Evers contributed to this report.

  • Talkback
  • Most Recent of 324 Talkback(s)
Misposted
I just discovered your reply while surfing another subject many months later, and now realize I misunderstood the original point you were making. The JS at our site is not malevolent, of course -- as you can easily see for yourself. My bad. Apologies. (I also use FF, BTW, not the other one.)... (Read the rest)
Posted by: Code_Flogger Posted on: 08/06/06 You are currently: Logged In | Log out
Here's the Important Part coffeenite   | 09/19/05
This is a stupid article anyway IceTheNet@...   | 09/19/05
exactly..like anyone worht anything takes Symantec seriously anymore Jeff Spicoli   | 09/19/05
We Are Much Better Off Getting Advice From YOU? PMC-CON   | 09/19/05
no, mindless twits like you should keep listening to Microsoft and Symantec Jeff Spicoli   | 09/19/05
Mindless twits aye? golowenow   | 09/19/05
Aye aye matey! Jeff Spicoli   | 09/19/05
McAfee is free on Comcast golowenow   | 09/20/05
I NEVER get nothing YaBaby   | 09/21/05
PMC-CON brian ansorge   | 09/20/05
symantec has been the target for some viruses lately... linuxoverwindows   | 09/19/05
NAV & McAfee have been disappointing as of late sctang73@...   | 09/20/05
doesn't matter either way al881   | 09/20/05
It's been a long time, too Update victim   | 09/20/05
BS? D-Ram   | 09/20/05
Norton was great - Symantic SUCKS! The Computer Pimp   | 09/20/05
Very Laughable NAV Sucks IceTheNet@...   | 09/21/05
...and your posting is idiotic cicuta   | 09/20/05
Learning to read should be your priority IceTheNet@...   | 09/21/05
and learning to write should be yours cicuta   | 09/22/05
And minding your own business should be yours IceTheNet@...   | 09/23/05
19 to 3 jim@...   | 09/19/05
finish the line... linuxoverwindows   | 09/19/05
This report is a joke!! FreeBSD   | 09/20/05
Symantec and Microsoft are joined at the hip RobertoSalazar   | 09/19/05
SYM + MS rickearley   | 09/19/05
Join at the hip ooooh yeah bcbooks   | 09/20/05
And where is the Linux version of Symantec? johnlb2002   | 09/20/05
Sure! They make billions out of 'securing' IE why would they like michael_t   | 09/19/05
All that says I_am_hellion_z   | 09/19/05
fact or fiction voska   | 09/21/05
and.. D-Ram   | 09/20/05
so what? at least IE is not only browers anymore M_c   | 09/19/05
they have b_ruce   | 09/19/05
Except... thetargos   | 09/20/05
In hindsight IT_User   | 09/19/05
Well IT Scion   | 09/20/05
Agreed and Sheeva   | 09/21/05
Another Thing RobertoSalazar   | 09/19/05
Another thing redacted cdgoldin   | 09/19/05
IE vs FF "reality" cgraham_z   | 09/19/05
would you rather ff tell everyone how to hack you IceTheNet@...   | 09/19/05
Symantec...The Standard of Non-Credibility slingzenarrowzuvowtrayjissforchin   | 09/19/05
Transparent attempt to safeguard their source of income michael_t   | 09/19/05
Actually, FireFox is based on very mature code ... OldFossil   | 09/19/05
How old is the Gecko engine? michael_t   | 09/19/05
There amounts of time for their rendering engines are that different IT Scion   | 09/20/05
Not really michael_t   | 09/20/05
Not really michael_t   | 09/20/05
yes really IT Scion   | 09/20/05
Mature or old and feeble? cdgoldin   | 09/19/05
Learn, then talk radicaldude   | 09/19/05
Why did you miss this? michael_t   | 09/19/05
Prove It node357   | 09/19/05
Incorrect Information!! xjahn   | 09/19/05
Your logic sucks NonZealot   | 09/19/05
your "logic" didn't take us any further Jeff Spicoli   | 09/19/05
Your logic is ... impeccable... Kudos. michael_t   | 09/19/05
Well, I'm no Einstein! NonZealot   | 09/19/05
dude, you TOTALLY invalidated yourself Jeff Spicoli   | 09/19/05
Your not quite getting it richardthegreat   | 09/20/05
Logic very flawed AmusedAtItAll   | 09/20/05
You would be voska   | 09/21/05
Nice rant IT Scion   | 09/20/05
Shut up and get back to work or get a life Jeff the god of biscuits   | 09/20/05
I agree djc1309@...   | 09/20/05
Here's a fact for you ... I_am_hellion_z   | 09/19/05
wrong Jeff Spicoli   | 09/19/05
Where is the fact? The "better moustrap"? michael_t   | 09/19/05
Fact is, its vulnerable and therefore insecure. darreno1   | 09/19/05
Re: Fact is, its vulnerable and therefore insecure. nightshade0143   | 09/20/05
As FF gains market share the attacks will increase.. darreno1   | 09/20/05
well you forgot about repair ratio. IceTheNet@...   | 09/20/05
It also depends on your OS Chad_z   | 09/20/05
And the beat goes on ... OldFossil   | 09/19/05
These type of stats won't matter until Real World   | 09/19/05
oops Real World   | 09/19/05
I respectfully disagree ... OldFossil   | 09/19/05
I'm not saying Real World   | 09/19/05
Can't say I've ever heard that voska   | 09/19/05
It wasn't in the Real World   | 09/20/05
Exactly why I don't let my family ebrke   | 09/20/05
MOZILLA VS. IE mesmd   | 09/19/05
HYPE VS. REALITY cdgoldin   | 09/19/05
First thing you said that makes any sense IceTheNet@...   | 09/20/05
Exactly IT Scion   | 09/20/05
Better than Opera's?? Not in thousand years! markbn   | 09/20/05
opera is a good browser but IceTheNet@...   | 09/23/05
RE: opera is a good browser but markbn   | 09/24/05
your confused IceTheNet@...   | 09/24/05
RE: your (sic) confused markbn   | 09/25/05
Spelling realoldnavyretired   | 09/21/05
Doubletalk from Symantec dhryder   | 09/19/05
So True.... EBathory   | 09/19/05
At least one has come true node357   | 09/19/05
Most end up WIN PC anyway rock06r   | 09/20/05
Only time will tell who will rein supreme liqour43@...   | 09/19/05
Quality vs. Bottom Line talontamer   | 09/19/05
AV is a community responsibility node357   | 09/19/05
so you would be ok infecting everyone else? rock06r   | 09/20/05
Faulty Comparison dl@...   | 09/19/05
Firefox is based on older software mnordhoff   | 09/20/05
RE: Faulty Comparison HerbieHightower   | 09/20/05
Ummm IT Scion   | 09/20/05
For total computer safety.... Shutterbug   | 09/19/05
RE For total computer safety.... OmarZewddie   | 09/20/05
Most of you are in denial balsover   | 09/19/05
True, but..... todbran@...   | 09/19/05
You are dreaming balsover   | 09/19/05
Good luck... PeregrineFalcon   | 09/19/05
Do those exploits... balsover   | 09/19/05
Locked Down Users PMC-CON   | 09/19/05
Disable ActiveX.... todbran@...   | 09/19/05
You are ignorant. balsover   | 09/19/05
BTW Flash is ActiveX If You Let It Be ... (nt) PMC-CON   | 09/19/05
Then it is a problem. nt balsover   | 09/19/05
Not exactly. enduser_z   | 09/19/05
then do not run that page balsover   | 09/19/05
You'd be able to run the page.. TheSickEmpire   | 09/19/05
You sure can voska   | 09/19/05
most of the flashy sites these days balsover   | 09/19/05
Turning off ActiveX is not needed. IT Scion   | 09/21/05
ActiveX IT Scion   | 09/20/05
Right right .... Mozilla developers are in denial michael_t   | 09/19/05
Actually I said that you were in denial balsover   | 09/19/05
So true. darreno1   | 09/19/05
Says The Guy Who Never Used FF nikoli   | 09/20/05
Let me tell you.... todbran@...   | 09/19/05
You are aware Real World   | 09/19/05
Also... toadlife   | 09/19/05
Duhhhh todbran@...   | 09/19/05
See response above... PeregrineFalcon   | 09/19/05
How do you stop the popups? enduser_z   | 09/19/05
USE FF IceTheNet@...   | 09/19/05
Hardly anyone complains. Real World   | 09/20/05
of course they would loose their job IceTheNet@...   | 09/20/05
Where to begin Real World   | 09/20/05
typos IceTheNet@...   | 09/21/05
People who don't understand security... Sxooter_z   | 09/19/05
Then There's The Other Method... slingzenarrowzuvowtrayjissforchin   | 09/19/05
and a 3rd method IceTheNet@...   | 09/19/05
Nonsense! cdgoldin   | 09/19/05
OK Here We Go! IceTheNet@...   | 09/19/05
Yes, please do go on cdgoldin   | 09/19/05
OK well I see there is no ignorance in your family IceTheNet@...   | 09/19/05
Place them where you want IceTheNet@...   | 09/19/05
I had Norton and McCaffee s_gamgee   | 09/21/05
Huray IceTheNet@...   | 09/23/05
Go get em! golowenow   | 09/19/05
Oooooooooooo-kay Henaway   | 09/19/05
Active x? Plugins? What the dif?? golowenow   | 09/19/05
You should be fired IceTheNet@...   | 09/19/05
Message has been deleted. balsover   | 09/19/05
Message has been deleted. IceTheNet@...   | 09/19/05
well they deleted a good message IceTheNet@...   | 09/19/05
Apparently overweight and illiterate as well... Scrat   | 09/20/05
Oh please... itanal   | 09/20/05
Message has been deleted. IceTheNet@...   | 09/20/05
Message has been deleted. RobX2005   | 09/20/05
Message has been deleted. itanal   | 09/20/05
ZDnet Scum Bag Editors IceTheNet@...   | 09/21/05
I was just proving a point that ZDnet Deleted IceTheNet@...   | 09/21/05
Why not burned at the stake? cdgoldin   | 09/19/05
Oops. Make that "TalkBack".. (NT) cdgoldin   | 09/19/05
Message has been deleted. IceTheNet@...   | 09/19/05
Unsupported opinion is not fact, no matter how many times you say it is cdgoldin   | 09/19/05
Oh I C you can say orifice but not as IceTheNet@...   | 09/19/05
Spelling lesson for you??? livewire^   | 09/21/05
Firefox vulnerabilities Peronthious   | 12/07/05
vulnerabilities: 31 for IE vs 28 for Firefox dabruro   | 09/19/05
Not the same time frame george_ou  ZDNet | 09/19/05
If those older ones are still Linux Guy 1000   | 09/19/05
That's the funniest explanation I've heard yet... ju1ce   | 09/20/05
The bottom line georgep_z   | 09/19/05
Ever get tired of idiot fanboys? ThinkAboutIt   | 09/19/05
I get tired of idiots period. IceTheNet@...   | 09/19/05
Don't help him out with his spelling. Grayson Peddie   | 09/19/05
Yes and as has been Linux Guy 1000   | 09/19/05
Ask and ye shall be informed cdgoldin   | 09/19/05
Doesn't really matter IceTheNet@...   | 09/19/05
JVM Scripts? PMC-CON   | 09/20/05
For PCM-CON IceTheNet@...   | 09/22/05
99% of the sites I write use JS Jeff the god of biscuits   | 09/19/05
I have an idea Linux Guy 1000   | 09/20/05
Amen to that (nt) IT Scion   | 09/21/05
Just FYI IceTheNet@...   | 09/19/05
That's nice an all but.... darreno1   | 09/19/05
True True True IceTheNet@...   | 09/19/05
Don't need IT Scion   | 09/21/05
For IT Scion Waa go home to mama!! IceTheNet@...   | 09/23/05
Most sites that use DHTML balsover   | 09/19/05