September 19, 2005 1:10 PM PDT

Symantec: Mozilla browsers more vulnerable than IE

Mozilla Web browsers are potentially more vulnerable to attack than Microsoft's Internet Explorer, according to a Symantec report.

But the report, released Monday, also found that hackers are still focusing their efforts on IE.

The open-source Mozilla Foundation browsers, such as the popular Firefox, have typically been seen as more secure than IE, which has suffered many security problems in the past. Mitchell Baker, president of the foundation, said earlier this year that its browsers were fundamentally more secure than IE. She also predicted that Mozilla Foundation browsers would not face as many problems as IE, even as their market share grows.

Symantec's Internet Security Threat Report Volume VIII contains data for the first six months of this year that may contradict this perception.

According to the report, 25 vendor-confirmed vulnerabilities were disclosed for the Mozilla browsers during the first half of 2005, "the most of any browser studied," the report's authors stated. Eighteen of these flaws were classified as high severity.

"During the same period, 13 vendor-confirmed vulnerabilities were disclosed for IE, eight of which were high severity," the report noted.

The average severity rating of the vulnerabilities associated with both IE and Mozilla browsers in this period was classified as "high", which Symantec defined as "resulting in a compromise of the entire system if exploited."

The Mozilla Foundation did not immediately respond to requests for comment.

Symantec reported that the gap between vulnerabilities being reported and exploit code being released has dropped to six days on average. However, it's not clear from the report how quickly Microsoft and Mozilla released patches for their respective vulnerabilities, or how many of the vulnerabilities were targeted by hackers, though Microsoft generally releases patches only on a monthly basis.

Symantec admitted that "at the time of writing, no widespread exploitation of any browser except Microsoft Internet Explorer has occurred," but added that it "expects this to change as alternative browsers become increasingly widely deployed."

There is one caveat: Symantec counts only those security flaws that have been confirmed by the vendor. According to security monitoring company Secunia, there are 19 security issues that Microsoft still has to deal with for Internet Explorer, while there are only three for Firefox.

The report also highlighted a trend away from the focus of security being on "servers, firewalls, and other systems with external exposure." Instead, "client-side systems--primarily end-user systems--(are) becoming increasingly prominent targets of malicious activity."

Web browser vulnerabilities are becoming a preferred entry point into systems, the report stated. It also highlighted the trend of hackers operating for financial gain rather than recognition, increased potential exposure of confidential information, and a "dramatic increase in malicious code variants".

Tom Espiner of ZDNet UK reported from London. CNET News.com's Joris Evers contributed to this report.

See more CNET content tagged:
Mozilla Web browser, Mozilla Corp., Symantec Corp., vulnerability, Microsoft Internet Explorer

Add a Comment (Log in or register) 123 comments (Showing first 20 comments)
My opinion.
by System Tyrant September 19, 2005 1:49 PM PDT
Sounds to me like an incomplete report. From their own admission it doesn't take into consideration how fast a flaw is fixed or how many are still open.

It looks to me more like a one sided report trying to make open source look less secure than closed source. Not having read the report it sounds like what it might be saying is that flaws are easier to find in open source than in closed source.

Without consideration for how long each browser took to fix the flaw and the number of exploits before a patch was released this report just doesn't look like much to help a user or company make an informed decision on what browser to use (if that was the purpose of the report). Like I said though I haven't read the report and you can't go by what the press says, so it maybe just the oppisite of that.
Reply to this comment View all 2 replies
My opinion.
by System Tyrant September 19, 2005 1:49 PM PDT
Sounds to me like an incomplete report. From their own admission it doesn't take into consideration how fast a flaw is fixed or how many are still open.

It looks to me more like a one sided report trying to make open source look less secure than closed source. Not having read the report it sounds like what it might be saying is that flaws are easier to find in open source than in closed source.

Without consideration for how long each browser took to fix the flaw and the number of exploits before a patch was released this report just doesn't look like much to help a user or company make an informed decision on what browser to use (if that was the purpose of the report). Like I said though I haven't read the report and you can't go by what the press says, so it maybe just the oppisite of that.
Reply to this comment View all 2 replies
Symantic is becoming....
by September 19, 2005 1:59 PM PDT
the new disinformation minister.
They will do anything to keep people using Windows and IE...more
profit.
Reply to this comment View all 2 replies
Symantic is becoming....
by September 19, 2005 1:59 PM PDT
the new disinformation minister.
They will do anything to keep people using Windows and IE...more
profit.
Reply to this comment View all 2 replies
The foundation OS, is the FLAW, no matter the browser veiled ovder it
by September 19, 2005 2:05 PM PDT
Windows security is Non-existent, thats the basis of this study.
No matter what internet browser is placed on top if Windows,
the cracks or hooks in this operating system are still present no
matter what browser is used.

Sure, Firefox browser doesnt have as many pre-built hooks
down into Windows as Internet Explorer does, probably because
reverse-engineering Windows code is against the law for them,
but if the bricks of this Internet house are built on top of
Windows, there is only so much protection you can have.

The ultimate goal would be for MSFT to build a true Internet OS,
one that is not for the desktop, does not have hooks to DCOM,
or .exe, or Active-X. Until Windows is locked down, by design,
from the start, no browser will be able to protect PC users from
the features Windows offered to businesses for tying data
together, that are subsequently used by the hackers to tie the
hooks into a "web" of unintentional process calls and backdoor
traps.

Using a more secure OS from the beginning is the only solution,
and with Bill Gates screwing his unknowing customers any
chance he gets, this will not happen anytime soon.

What a shame as we waste countless hours and billions of
dollars while he got the fortunes by making a horses rump of
you with his desire to stop Netscape at any cost; lets just mash
IE into Windows.

Although Gates is dumb, he is betting that many others are
dumber than he is, thus they keep buying Windows.
Reply to this comment View all 4 replies
The foundation OS, is the FLAW, no matter the browser veiled ovder it
by September 19, 2005 2:05 PM PDT
Windows security is Non-existent, thats the basis of this study.
No matter what internet browser is placed on top if Windows,
the cracks or hooks in this operating system are still present no
matter what browser is used.

Sure, Firefox browser doesnt have as many pre-built hooks
down into Windows as Internet Explorer does, probably because
reverse-engineering Windows code is against the law for them,
but if the bricks of this Internet house are built on top of
Windows, there is only so much protection you can have.

The ultimate goal would be for MSFT to build a true Internet OS,
one that is not for the desktop, does not have hooks to DCOM,
or .exe, or Active-X. Until Windows is locked down, by design,
from the start, no browser will be able to protect PC users from
the features Windows offered to businesses for tying data
together, that are subsequently used by the hackers to tie the
hooks into a "web" of unintentional process calls and backdoor
traps.

Using a more secure OS from the beginning is the only solution,
and with Bill Gates screwing his unknowing customers any
chance he gets, this will not happen anytime soon.

What a shame as we waste countless hours and billions of
dollars while he got the fortunes by making a horses rump of
you with his desire to stop Netscape at any cost; lets just mash
IE into Windows.

Although Gates is dumb, he is betting that many others are
dumber than he is, thus they keep buying Windows.
Reply to this comment View all 4 replies
But the report, released Monday...
by Nathan Lunn September 19, 2005 2:15 PM PDT
Released where? Since the story (conveniently) neglected to supply a link to the report, here it is. Although, you will have to give much personally identifiable information to Symantic, the Great Security Company that they are, in order to download the 106 page PDF report.

https://ses.symantec.com/content.cfm?articleid=1539
Reply to this comment
But the report, released Monday...
by Nathan Lunn September 19, 2005 2:15 PM PDT
Released where? Since the story (conveniently) neglected to supply a link to the report, here it is. Although, you will have to give much personally identifiable information to Symantic, the Great Security Company that they are, in order to download the 106 page PDF report.

https://ses.symantec.com/content.cfm?articleid=1539
Reply to this comment
Once more.....
by Earl Benser September 19, 2005 2:24 PM PDT
... we seem to have a solution in search of a problem. Symantec
makes fairly good virus protection software, but other than for
MS products, the need for Symantec's programs is quite low.
With no threat, no sales.

As reported: "Symantec admitted that "at the time of writing, no
widespread exploitation of any browser except Microsoft
Internet Explorer has occurred," but added that it "expects this
to change as alternative browsers become increasingly widely
deployed.".

Can't blame them for trying to pump sales. But we don't have to
pay any serious attention to their rather obvious marketing
maneuvers.
Reply to this comment
Once more.....
by Earl Benser September 19, 2005 2:24 PM PDT
... we seem to have a solution in search of a problem. Symantec
makes fairly good virus protection software, but other than for
MS products, the need for Symantec's programs is quite low.
With no threat, no sales.

As reported: "Symantec admitted that "at the time of writing, no
widespread exploitation of any browser except Microsoft
Internet Explorer has occurred," but added that it "expects this
to change as alternative browsers become increasingly widely
deployed.".

Can't blame them for trying to pump sales. But we don't have to
pay any serious attention to their rather obvious marketing
maneuvers.
Reply to this comment
Mitchell Baker is.... a man?
by aabcdefghij987654321 September 19, 2005 2:28 PM PDT
Quoting the article:
"Mitchell Baker, president of the foundation, said earlier this year that its browsers were fundamentally more secure than IE. He also predicted that Mozilla Foundation browsers would not face as many problems as IE, even as their market share grows."

Mitchell Baker is a woman:
http://tinyurl.com/dd9tm

Good way to check the sources!
Reply to this comment View all 2 replies
Mitchell Baker is.... a man?
by aabcdefghij987654321 September 19, 2005 2:28 PM PDT
Quoting the article:
"Mitchell Baker, president of the foundation, said earlier this year that its browsers were fundamentally more secure than IE. He also predicted that Mozilla Foundation browsers would not face as many problems as IE, even as their market share grows."

Mitchell Baker is a woman:
http://tinyurl.com/dd9tm

Good way to check the sources!
Reply to this comment View all 2 replies
Misleading Title
by dysonl September 19, 2005 2:33 PM PDT
Unfortunately, most people will read only the title and form an opinion as to which browser is better.
Reply to this comment View reply
Misleading Title
by dysonl September 19, 2005 2:33 PM PDT
Unfortunately, most people will read only the title and form an opinion as to which browser is better.
Reply to this comment View reply
vulnerabilities: 31 for IE vs 28 for Firefox
by dabruro September 19, 2005 2:38 PM PDT
Including the secunia vendor-unacknowledged ones:
13+18=31 for MS IE
25+ 3=28 for Firefox
Reply to this comment View all 2 replies
vulnerabilities: 31 for IE vs 28 for Firefox
by dabruro September 19, 2005 2:38 PM PDT
Including the secunia vendor-unacknowledged ones:
13+18=31 for MS IE
25+ 3=28 for Firefox
Reply to this comment View all 2 replies
geeze
by WebmasterOfWarStoke.com September 19, 2005 2:41 PM PDT
sometimes i think that certin companies are in certin other companies back pockets
ive noticed not just symantec but several other companies bad mouthing firefox for the last couple of months ever since they broke the 15% marketshare usage barrier
its like somone is afraid ;)
well if you are realy wanting tobe secure you can use the updated CVS versions of Mozila and firefox updated almost every day
to keep up with all the security problems or do like i do and grab the most recent major revision when ever an update is available
Reply to this comment
geeze
by WebmasterOfWarStoke.com September 19, 2005 2:41 PM PDT
sometimes i think that certin companies are in certin other companies back pockets
ive noticed not just symantec but several other companies bad mouthing firefox for the last couple of months ever since they broke the 15% marketshare usage barrier
its like somone is afraid ;)
well if you are realy wanting tobe secure you can use the updated CVS versions of Mozila and firefox updated almost every day
to keep up with all the security problems or do like i do and grab the most recent major revision when ever an update is available
Reply to this comment
Apples & oranges
by dam7ri September 19, 2005 2:47 PM PDT
What everyone fails to realize is that Symantec found 25 flaws in the first 6 months of this year, in Firefox. How many flaws have been found in IE, since its release? What version of IE are we on now, and we are still dealing with the same flaws as the previous versions. Let's not even take into account the length of time that we are exposed to vulnerabilities, with IE. Firefox gets fixed, quickly.
Reply to this comment View reply
Apples & oranges
by dam7ri September 19, 2005 2:47 PM PDT
What everyone fails to realize is that Symantec found 25 flaws in the first 6 months of this year, in Firefox. How many flaws have been found in IE, since its release? What version of IE are we on now, and we are still dealing with the same flaws as the previous versions. Let's not even take into account the length of time that we are exposed to vulnerabilities, with IE. Firefox gets fixed, quickly.
Reply to this comment View reply
 See all 123 Comments >>
Powered by Jive Software
advertisement

Latest tech news headlines

RSS Feeds

Add headlines from CNET News to your homepage or feedreader.

More feeds available in our RSS feed index.

advertisement

Inside CNET News

Scroll Left Scroll Right
  • News - Business Tech

    Chrome's JavaScript challenge to Silverlight

    The advent of Google's Chrome browser, software pros say, should spur a big speedup for JavaScript, which would raise its standing against Microsoft's Silverlight technology.

  • Gallery

    Photos: Top 10 reviews of the week

    Here are CNET Reviews' 10 favorite items from the past week, including the TiVo HD XL, Sony Cyber-shot DSC-H50, and the Dish Network's newest digital TV converter box.

  • News - Apple

    Apple watchers spot 'iPod Nano' pix, iTunes hints

    The rumor mill has long been predicting a longer, leaner new version of the iPod Nano, and now it's conjuring up some pictures.

  • Coop's Corner

    Chris Shipley 1, Internet lynch mob 0

    Demo's impresario goes public with a tart and smartly written riposte to the shoot-from-the-lip crowd.

  • Video

    Katie Couric reflects on first Webcast

    The political conventions are over and so are CBS Evening News anchor Katie Couric's first series of Webcasts. CNET's Kara Tsuboi sat down with Couric on the final night of the Republican National Convention to discuss what she liked about Webcasting, some of her most memorable guests, and whether TV news will still be around by the next round of conventions.

  • News - Digital Media

    Google-focused satellite enters orbit

    The search titan has exclusive rights among online mapping sites to images from the new GeoEye-1 satellite, which launched Saturday.

  • Video

    YouTube plays party politics

    During the presidential campaigning four years ago, YouTube didn't even exist. Now it's a tool candidates must master to get their message across. CNET's Kara Tsuboi stops by the YouTube upload booths at the Democratic and Republican conventions to find out why Google's video site has such a big presence in Denver and St. Paul, Minn.

  • News - Gaming and Culture

    Are Demo and TechCrunch50 fragmenting their audiences?

    With both events scheduled to start Monday, many press, as well as venture capitalists and others are having to choose which one to attend.

  • News - Cutting Edge

    Execs predict next Google-like tech

    On eve of company's 10-year anniversary, researchers and business pundits speculate about what technologies might someday have as much impact as Google.

  • Gallery

    Images: The art of 'Spore' prototypes

    Will Wright and his Maxis team worked on dozens of prototypes to test the elements of their soon-to-be-released evolution game. Here's a sampling.

  • Crossfade

    The Standard, 'A Different Skin': Free MP3 of the Day

    Eschewing the danceable beats favored by many of its post-punk brethren, while opting instead for more ominous and insistent rhythms, is what makes the Standard visceral and engaging. Download a free MP3 of "A Different Skin" courtesy of CNET Download Mus

  • Green Tech

    Duke Energy to invest in mini solar power plants

    Can hundreds of rooftop solar panels collectively operate like a central power plant? Duke Energy launches $100 million distributed solar program to find out.