Search: Home Bugtraq Vulnerabilities Mailing Lists Jobs Tools Beta Programs
Firefox exploit targets zero day vulns
John Leyden, The Register 2005-05-09

Security researchers have discovered two unpatched vulnerabilities in Firefox, the popular alternative web browser. The security bugs affect even the latest version of Firefox (version 1.0.3) and create a means for attackers to seize control of vulnerable systems using cross-site scripting attacks.

Comments Mode:
Firefox exploit targets zero day vulns 2005-05-09
TJ (4 replies)
Firefox exploit targets zero day vulns 2005-05-10
David Prinzing
Firefox exploit targets zero day vulns 2005-05-10
Anonymous (2 replies)
Firefox exploit targets zero day vulns 2005-05-10
David Prinzing
I agree that closed source tends to have more vulnerabilities because it is not publicly coded, but then again, Microsoft has more than the average amount of coders working on their projects. An inherent and systemic flaw in IE is that it is too closely tied to the OS which it runs on but this type of flaw can be fixed without removing IE entirely. The severity of flaws is not just a reflection upon coding but also upon the amount of users that the program has and/or the size of the public target.

Most open source projects may not have as many ?patches? as IE has, but they tend to release a new version of their product every time the smallest thing changes (i.e. some security flaw is found). How is this different than IE patching except that you have to re-install the entire product every time a new version is released? In reality you have to consider that IE isn?t perfect but we really have nothing to compare it to as its peer do we?

David Prinzing

Delta End, Inc

www.deltaend.com

www.deltaendhosting.com

[ reply ]

Link to this comment: http://www.securityfocus.com/comments/articles/11119/31822#31822
Firefox exploit targets zero day vulns 2005-05-10
Anonymous (2 replies)
Firefox exploit targets zero day vulns 2005-05-10
Anonymous (1 replies)
Firefox exploit targets zero day vulns 2005-05-11
Coldman (2 replies)
Firefox exploit targets zero day vulns 2005-05-12
Anonymous (1 replies)







 

Privacy Statement
Copyright 2009, SecurityFocus