Categories: Security

Firefox Had More Bugs Than IE and Safari Combined

Nearly twice as many security vulnerabilities were found in the Firefox browser compared to IE and Apple Safari combined, according to new research.

Firefox had 115 security vulnerabilities reported in 2008, according to browser vulnerability research released by Secunia late last week.

However, the news is not all bad, as the same report showed that Mozilla was much quicker to respond than Microsoft when flaws were publicly disclosed either prior to or without vendor notification.

Three Firefox vulnerabilities were publicised last year under those conditions. All three were patched, with the longest patch taking 86 days to arrive, according to Secunia. For IE, however, only three of the six such vulnerabilities were patched as of 31 December. One of the IE vulnerabilities remained open for 294 days in 2008, according to the report.

The report noted that not all vulnerabilities are created equal. The three aforementioned Firefox flaws were rated “less critical,” while the Microsoft vulnerabilities were more of a mixed bag. The three unpatched IE flaws were rated either “not critical” or “less critical.” Two of the patched bugs were classified as “moderate” and “high,” while the third patched bug was considered “less critical.”

On 4 March, Mozilla released an update plugging eight security holes in Firefox 3.07, of which six were rated critical. The vulnerabilities affect the browser’s garbage collection, PNG libraries, layout and JavaScript engines.

The critical vulnerabilities could enable hackers to run arbitrary code. But there is also a vulnerability rated “high” that could allow a Web site to use nsIRDFService and a cross-domain redirect to steal private data from users authenticated to the redirected Web site.

The update came a day after Opera Software issued a security update for its browser, and roughly a week after Apple released a beta version of Safari 4.

Brian Prince eWEEK USA 2014. Ziff Davis Enterprise Inc. All Rights Reserved

Share
Published by
Brian Prince eWEEK USA 2014. Ziff Davis Enterprise Inc. All Rights Reserved

Recent Posts

Intel Chief Flattens Leadership StructureIntel Chief Flattens Leadership Structure

Intel Chief Flattens Leadership Structure

New Intel chief executive Lip-Bu Tan flattens company's leadership structure as he seeks to end…

16 mins ago
Google To Appeal Portions Of Ad Monopoly RulingGoogle To Appeal Portions Of Ad Monopoly Ruling

Google To Appeal Portions Of Ad Monopoly Ruling

Google says it will appeal 'adverse' portions of ruling that found its ad business is…

45 mins ago
TSMC Denies Talks With Intel Over Chipmaking Joint VentureTSMC Denies Talks With Intel Over Chipmaking Joint Venture

TSMC Denies Talks With Intel Over Chipmaking Joint Venture

Denial from TSMC, after multiple reports it was in talks with Intel over a joint…

3 days ago

Apple iPhone Shipments In China Slide, As Cook Talks With Trump Official

CEO Tim Cook talks to Trump official, as IDC notes China's smartphone market growth, and…

3 days ago

AMD Warns Of $800m Charge From US Chip Restrictions On China

Another big name chip maker expects a hefty financial charge, after the US tightened rules…

3 days ago

Google Digital Ad Network Ruled Illegal Monopoly By Judge

More bad news for Google. Second time in less than a year that some part…

4 days ago