Free Republic
Browse · Search
Bloggers & Personal
Topics · Post Article

To: Bush2000
946 Mozilla Critical New Bugs

I think that's a good point. However I don't know how it would compare to IE, there's not a corollary site for MS internal bug fix logs, I don't think. But maybe we could look at security vulnerabilities.

So, you got me thinking though. To really compare, we'd need some metric to weigh the potential risk, which we don't have in order to compare.

Ignoring the relative severity of this particular exploit – unique to Windows/IE, – I thought it might be interesting to look at a comparison of number security vulnerabilites specific to the two browsers.

FWIW, here's what I got from http://www.securityfocus.com/bid/vendor/ since Jan. 1, 2004:

Security Vulnerabilities specific to Mozilla Browser
 2004-06-14: Mozilla Browser URI Obfuscation Weakness
 2004-05-26: Mozilla Browser Zombie Document Cross-Site Scripting Vulnerability
 2004-05-26: Mozilla Browser Cookie Path Restriction Bypass Vulnerability
 2004-04-15: Mozilla Messenger Remote Denial Of Service Vulnerability
 2004-03-10: Mozilla Browser Script.prototype.freeze/thaw Arbitrary Code Execution Vulnerability
 2004-03-10: Mozilla Browser Proxy Server Authentication Credential Disclosure Vulnerability
 2004-01-20: Mozilla Browser Cross Domain Violation Vulnerability

Security Vulnerabilities specific to Internet Explorer
 2004-06-21: Microsoft Internet Explorer Modal Dialog Zone Bypass Vulnerability
 2004-06-16: Microsoft Internet Explorer HREF Save As Denial of Service Vulnerability
 2004-06-15: Microsoft Internet Explorer Wildcard DNS Cross-Site Scripting Vulnerability
 2004-06-10: Microsoft Internet Explorer ADODB.Stream Object File Installation Weakness
 2004-06-10: Multiple Microsoft Internet Explorer Script Execution Vulnerabilities
 2004-06-07: Microsoft Internet Explorer URL Local Resource Access Weakness
 2004-06-04: Microsoft Internet Explorer ITS Protocol Zone Bypass Vulnerability
 2004-05-18: Microsoft Internet Explorer CSS Style Sheet Memory Corruption Vulnerability
 2004-05-15: Microsoft Internet Explorer http-equiv Meta Tag Denial of Service Vulnerability
 2004-05-14: Microsoft Internet Explorer Codebase Double Backslash Local Zone File Execution Weakness
 2004-05-14: Microsoft Internet Explorer Double Backslash CHM File Execution Weakness
 2004-05-14: Microsoft Internet Explorer Interface Spoofing Vulnerability
 2004-05-11: Microsoft Internet Explorer Unconfirmed Memory Corruption Vulnerability
 2004-05-10: Microsoft Internet Explorer XML Parsing Denial Of Service Vulnerability
 2004-05-10: Microsoft Internet Explorer Embedded Image URI Obfuscation Weakness
 2004-04-30: Microsoft Internet Explorer Meta Data Foreign Domain Spoofing Vulnerability
 2004-04-21: Microsoft Outlook Express MHTML Forced File Execution Vulnerability
 2004-04-21: Microsoft Outlook Express MHTML Redirection Local File Parsing Vulnerability
 2004-04-17: Microsoft Internet Explorer Object Element Data Denial Of Service Vulnerability
 2004-04-12: Microsoft Internet Explorer Bitmap File Processing Denial of Service Vulnerability
 2004-04-07: Microsoft Internet Explorer Remote IFRAME Denial Of Service Vulnerability
 2004-04-06: Microsoft Internet Explorer Macromedia Flash Player Plug-in Remote Denial of Service Vulnerability
 2004-04-06: Microsoft Internet Explorer MSWebDVD Object Denial of Service Vulnerability
 2004-04-01: Microsoft Internet Explorer HTML Form Status Bar Misrepresentation Vulnerability
 2004-03-29: Microsoft Internet Explorer Shell: IFrame Cross-Zone Scripting Vulnerability
 2004-03-04: Microsoft Internet Explorer Script URL Cross-Domain Access Violation Vulnerability
 2004-03-04: Microsoft Internet Explorer window.open Search Pane Cross-Zone Scripting Vulnerability
 2004-03-04: Microsoft Internet Explorer window.open Media Bar Cross-Zone Scripting Vulnerability
 2004-02-27: Microsoft Internet Explorer Cross-Domain Event Leakage Vulnerability
 2004-02-16: Microsoft Internet Explorer Bitmap Processing Integer Overflow Vulnerability
 2004-02-11: Microsoft Internet Explorer Unauthorized Clipboard Contents Disclosure Vulnerability
 2004-02-10: Microsoft Internet Explorer Double-Null URI Denial Of Service Vulnerability
 2004-02-09: Microsoft Internet Explorer LoadPicture File Enumeration Weakness
 2004-02-03: Microsoft Internet Explorer NavigateAndFind() Cross-Zone Policy Vulnerability
 2004-02-02: Microsoft Internet Explorer BackToFramedJPU Cross-Domain Policy Vulnerability
 2004-02-02: Microsoft Internet Explorer Window.MoveBy/Method Caching Mouse Click Event Hijacking Vulnerability
 2004-01-27: Microsoft Internet Explorer CLSID File Extension Misrepresentation Vulnerability
 2004-01-02: Microsoft Internet Explorer Malicious Shortcut Self-Executing HTML Vulnerability

108 posted on 06/26/2004 10:53:44 PM PDT by D-fendr
[ Post Reply | Private Reply | To 91 | View Replies ]


To: D-fendr

Bush2000 will get back to you when he's done mowing Bill Gate's lawn.


109 posted on 06/27/2004 7:02:18 AM PDT by Musket
[ Post Reply | Private Reply | To 108 | View Replies ]

Free Republic
Browse · Search
Bloggers & Personal
Topics · Post Article


FreeRepublic, LLC, PO BOX 9771, FRESNO, CA 93794
FreeRepublic.com is powered by software copyright 2000-2008 John Robinson