Search:  

 
 
   All ForumsHot TopicsGallery






how-to block ads


 
Forums » Up and Running » Security » Security » Firefox is the Most Vulnerable Application in 2008
Search Topic:
Share Topic:
RSS topic:
toggle:
flat / full
normal / watch
Posting:
Post a:
Post a:
Adobe Flash Player for Linux SWF Processing Vulnerability »
« Microsoft patches IE, but Firefox is still safer  
AuthorAll Replies

SUMware
Premium
join:2002-05-21


4 edits
reply to matunga
Re: Daft list names Firefox, Adobe and VMWare as top threats

Note: matunga retitled the thread from the original "Daft list names Firefox, Adobe and VMWare as top threats" since my post.

More from your link:

quote:
Bit9, Inc., the pioneer and leader in Enterprise Application Whitelisting, unveiled its annual ranking of popular consumer applications with known security vulnerabilities. Often running outside of the IT department’s knowledge or control, these applications can be difficult to detect; they create data leakage risk in endpoints that are otherwise secure; and cause compliance breaches that can result in costly fines. The list, published in a research brief entitled “2008’s Popular Applications with Critical Vulnerabilities,” is designed to highlight the need for greater visibility and control over organizations’ endpoints, including laptops, PCs servers and Point-of-Sale systems.

each application on the list has the following characteristics:

Runs on Microsoft Windows.
• Is well-known in the consumer space and frequently downloaded by individuals.
Is not classified as malicious by enterprise IT organizations or security vendors.
• Contains at least one critical vulnerability that was:
o first reported in January 2008 or after,
o registered in the U.S. National Institute of Standards and Technology’s (NIST) official vulnerability database at »nvd.nist.gov, and given a severity rating of high (between 7.0-10.0) on the Common Vulnerability Scoring System (CVSS).

["The biggies"]

Relies on the end user, rather than a central IT administrator, to manually patch or upgrade the software to eliminate the vulnerability, if such a patch exists.

The application cannot be automatically and centrally updated via free Enterprise tools such as Microsoft SMS & WSUS.

To read the full list of applications, which includes products from Symantec, Yahoo!, Trend Micro, Sun Microsystems and more, download the research report at: »bit9.com/landing/2008vulnerableapps.php. There, IT managers can learn more about the application vulnerabilities, along with the benefits of using application white listing, a proactive approach to endpoint security.
[emphasis added]

It is important to notice the caveats. You'll never see MS IE in this list.

-

Bit9 is not an independent, impartial testing/reporting agency. This is a promotional and marketing tool.

»www.bit9.com/about/index.php
quote:
Bit9 is the pioneer and leader in Enterprise Application Whitelisting. The company's patented solutions ensure only trusted and authorized applications are allowed to run on Windows computers, eliminating the risk caused by malicious, illegal and unauthorized software.

Bit9 is privately held and based in Waltham, Massachusetts.


SnowyOne
Premium
join:2003-04-05
Kailua, HI
·RoadRunner Cable
·Clearwire Wireless

OT but...

said by SUMware See Profile :

Note: matunga retitled the thread from the original "Daft list names Firefox, Adobe and VMWare as top threats"...
I've never had an opinion on the merits of matunga See Profile's posts but this type of manipulation helps me understand some of the harsher criticism I've seen directed at him.

Personally I'd rather be guilty of posting something that flew in face of an agenda rather than manipulating facts to support an agenda.
-
Forums » Up and Running » Security » SecurityAdobe Flash Player for Linux SWF Processing Vulnerability »
« Microsoft patches IE, but Firefox is still safer  


Wednesday, 09-Dec 21:21:48 Terms of Use | Privacy Policy | Hosting by www.nac.net - DSL,Hosting & Co-lo | feedback | contact
over 10 years online! © 1999-2009 dslreports.com.
page compression OFF
Most commented news this week
· [199] Sprint Sued For Distracted Driving Death
· [106] AT&T Launching New 24 Mbps U-Verse Tier
· [82] 3G Network Test Says AT&T Is Tops
· [72] Mediacom Unveils 105 Mbps Pricing
· [66] Sprint Poised For A Turnaround?
· [63] WPA Cracker: Test WPA-PSK Networks In 20 Minutes
· [56] AT&T Hints At Usage-Based iPhone Data Pricing
· [51] The Future Of Wi-Fi Is Bright
· [47] Site Leaks Yahoo, Verizon Fed Data Share Pricing
· [44] Microwaving Your Innards Is Not 'Extreme'
Most people now reading
· Is sleeping similar to being dead? [General Questions]
· ICC Strats??? [World of Warcraft]
· ICC strats [World of Warcraft]
· Hot Girl falls face first down stairs [56k Lookout (Broadband Heavy)]
· Adobe Flash Player version 10.0.42.34 [Security]
· RG Firmware update to VDSL2 this morning [AT&T U-verse]
· Cross Server Dungeon Experience [World of Warcraft]
· Windows 7 boot manager editing questions [Microsoft Help]
· Gift Cards on eBay [General Questions]