Firefox tops list of most vulnerable Windows application

Status
Not open for further replies.
Associate
Joined
21 Apr 2008
Posts
1,088
Location
By the river
" In a list, published by security firm Bit9, of 12 most vulnerable applications for the Windows platform, Firefox finished at the top of the list : 2008’s Popular Applications with Critical Vulnerabilities. "

linky

source

No mention of IE! :eek:
 
They seem to have used peculiar criteria to compile that list. They have put Firefox at the top of the list because Mozilla identified and patched the vulnerabilities? Well it isn't vulnerable to those vulnerabilities any more then, is it?
 
" In a list, published by security firm Bit9, of 12 most vulnerable applications for the Windows platform, Firefox finished at the top of the list : 2008’s Popular Applications with Critical Vulnerabilities. "

linky

source

No mention of IE! :eek:

There's no mention of IE because of their selection criteria (cannot be resolved by automated fix, eg windows update, but has to be resolved/patched by the end user)

Part of the issue here is that it's aimed at network managers, so they are looking at programs with vunerabilties that the network manager can't easily resolve, and Firefox isn't aimed at that market particularly.
 
There's no mention of IE because of their selection criteria (cannot be resolved by automated fix, eg windows update, but has to be resolved/patched by the end user)

Part of the issue here is that it's aimed at network managers, so they are looking at programs with vunerabilties that the network manager can't easily resolve, and Firefox isn't aimed at that market particularly.

I wonder why they don't consider Firefox's auto update feature to be automated?
 
I wonder why they don't consider Firefox's auto update feature to be automated?

Because it can't be used in an enterprise enviroment due to permissions requirements? It's designed for a machine where the user has admin permissions for a start. it's also designed to link and update firefox add-ons as well as the standard browser, both of which are not useful in an enterprise enviroment.

http://it.toolbox.com/blogs/managing-infosec/hacking-firefox-automatic-update-16567
 
Status
Not open for further replies.
Back
Top Bottom