ZDNet UK


Skip to Main Content

ZDNet.co.uk - Winner of Best Business Website 2007
  1. Home
  2. News
  3. Blogs
  4. Reviews
  5. Prices
  6. Resources
  7. Community
  8. My ZDNet

 

ZDNet UK RSS Feeds


IT Jobs

Enterprise open source Toolkit

Symantec: Mozilla browsers more vulnerable than IE

Tom Espiner ZDNet.co.uk

Published: 19 Sep 2005 14:00 BST

  • Email
  • Trackback
  • Clip Link
  • Print friendly
  • Post Comment

Mozilla Web browsers are currently potentially more vulnerable to attack than Microsoft's Internet Explorer (IE), according to a Symantec report out on Monday; the same report also found that today's hackers are still focusing their efforts on IE.

Mozilla browsers, such as the popular Firefox, have typically been seen as more secure than IE, which has suffered many security problems in the past. Mitchell Baker, president and chief lizard wrangler of the Mozilla Foundation, insisted earlier this year that Mozilla browsers were fundamentally more secure than IE, and would not face as many problems as IE even as their marker share grows. But Symantec's Internet Security Threat Report Volume VIII  contains data for the first six months of this year that may contradict this perception.

According to the report, 25 vendor-confirmed vulnerabilities were disclosed for the Mozilla browsers during the first half of 2005, "the most of any browser studied". Eighteen of these were classified as high severity.

"During the same period, 13 vendor-confirmed vulnerabilities were disclosed for IE, eight of which were high severity," according to the report.

The average severity rating of the vulnerabilities associated with both Internet Explorer and Mozilla browsers in this period was classified as "high", which Symantec defined as "resulting in a compromise of the entire system if exploited".

Symantec reported that the gap between vulnerabilities being reported and exploit code being released has dropped to six days on average. However, it's not clear from the report how quickly Microsoft and Mozilla released patches for their respective vulnerabilities, or how many of the vulnerabilities were targeted by hackers, though Microsoft only generally releases patches on a monthly basis.

Symantec admitted that "at the time of writing, no widespread exploitation of any browser except Microsoft Internet Explorer has occurred", but added that it "expects this to change as alternative browsers become increasingly widely deployed."

The Mozilla Foundation had not responded to requests for comment at the time of writing.

The report also highlighted a trend away from the focus of security being on "servers, firewalls, and other systems with external exposure". Instead, "client-side systems — primarily end-user systems — [are] becoming increasingly prominent targets of malicious activity".

Web browser vulnerabilities are becoming a preferred entry point into systems, according to the report.

The report also highlighted the trend of hackers operating for financial gain rather than recognition, increased potential exposure of confidential information, and a "dramatic increase in malicious code variants".

Update: After this story was published, Mozilla responded to Symantec's claims and defended its security record. Click here to read more.

  • Email
  • Trackback
  • Clip Link
  • Print friendly Print with Dell

Did you find this article useful?
108 out of 193 people found this useful


Company/Topic Alerts

Create a new alert from the list below:





Related Jobs

.NET .NET 3.5 Developer - (WFC / WFF) - Software House - London - 50K

Exposure to Java 2 and J2EE. As part of the project they will offer the chance to work jointly (design and architecture) with Microsoft, attend MS ...

Server Connectivity Principal Architect - SAN Connectivity HBA, Vendor

Any exposure to Server / Storage Server Connectivity Principal Architect, Solutions Architect, Storage Product Manager, Lead Presales Consultant - ...

Java Developer Java/J2EE, EJB, JSP, Struts, SQL

For more details about Salmon visit www.salmon.com We are looking for a junior Java developer) with exposure to related web based technologies. ...

Featured Talkback

Its the applications and device drivers that run on windows that cement its dominance. How many people would fork out hundreds of pounds for Vista if Linux ran all the software and kit they wanted to use.

By: pround

Read full story:
Windows' dominance stifles demand for Linux

Discussions

dogStar dogStar

Shake those Monkeys!

Friday 25 July 2008, 9:51 AM

1 comment
Freddyoky Freddyoky

Police And The Internet

Friday 25 July 2008, 8:32 AM

4 comments