Internet Explorer and Firefox Vulnerability Analysis Report

Jeff Jones on his blog about the Internet Explorer and Firefox Vulnerability Analysis Report:

For most people, their web browser is central to their interaction with the Internet, connecting to global web sites and helping them consume online services providing everything from booking flights to banking services to online shopping. This reality makes browsers a key tool when evaluating the security experience of users as the browser interprets Web content and programs delivered from around the world.

Over the past few years, there has been much discussion of the need for improvements in browser security, but few hard data studies performed to support assertions concerning the security of available browsers.

This report documents the results of my analysis of Internet Explorer and Firefox vulnerabilities over the past few years since Internet Explorer 6 on Windows XP SP2 became available and Mozilla launched Firefox.

The report in detail examines vulnerabilities over the past 3 years, breaks them down by severity, looks at version-over-version trends for each browser and finally examines how each browser is doing in terms of unfixed vulnerabilities.

https://blogs.technet.com/security/archive/2007/11/30/download-internet-explorer-and-firefox-vulnerability-analysis.aspx

In addition, see also my previous blog:
https://blogs.technet.com/ms_schweiz_security_blog/archive/2007/12/01/the-first-year-of-ie7.aspx

Urs

Comments

  • Anonymous
    December 03, 2007
    The comment has been removed
  • Anonymous
    December 03, 2007
    the analysis do not taken undocumented vulnerabilities of IE and the response time to zero-day exploit release for each browser.. Firefox responsed quickly than IE when some vulnerabilities discovered, as it is open source coded.