Browsers And Security

Apple issues Safari 4.0.5 to fix 16 vulnerabilities

Angela Moscaritolo March 12, 2010

Apple has pushed out the latest version of Safari -- its first update to the web browser since November -- to close 16 holes.
 

Mozilla recants assertion that Firefox add-on has trojan

Dan Kaplan February 11, 2010

Mozilla has retracted earlier claims that one of its Firefox plug-ins contained malware.
 

Mozilla says two Firefox browser plug-ins contain trojan

Dan Kaplan February 08, 2010

Mozilla is advising users who may have downloaded two "experimental" Firefox add-ons that they contain malware.
 

Chrome 4.0 released to address several flaws

Angela Moscaritolo January 26, 2010

Chrome 4.0.249.78 for Windows addresses 13 vulnerabilities, six of which are rated "high" in severity, according to Google's release notes.
 

Mozilla releases Firefox 3.6 with new security feature

Angela Moscaritolo January 21, 2010

The newest version of the Firefox web browser, released Thursday, contains a feature that detects whether plug-ins are out of date.
 

Opera 10.10 released

Angela Moscaritolo November 23, 2009

Opera Software on Monday issued Opera 10.10 (Opera Unite) which fixes an "extremely severe" heap buffer overflow vulnerability that could cause the browser to freeze or terminate or lead to a crash that could be used to execute code, Opera said. The updated browser also fixes a separate "highly severe" issue with scripting error messages that could allow cross-site scripting, as well as a "moderately severe" issue, of which details will be disclosed at a later date. — AM
 

Firefox finds users interested in updating Flash Player

Dan Kaplan September 17, 2009

Mozilla is reporting initial success in getting users updated to the latest version of Flash.
 

Firefox updated for security flaws

Chuck Miller September 10, 2009

The Firefox browser has been updated for four security flaws, three of which were rated as "critical."
 

Firefox pings Flash users

Dan Kaplan September 08, 2009

Users who upgrade to the next versions of the Firefox web browser -- 3.5.3 and 3.0.14, due out Wednesday -- will be notified if they are running a vulnerable version of the Adobe Flash Player, Mozilla's "Human Shield" Johnathan Nightingale announced Friday. The move comes out of concerns that a majority of Flash users are running out-of-date versions of the software. Nightingale said the warnings will enable people to avoid crashes, stability issues and other security problems. Mozilla plans to partner with other plug-in providers to offer similar alerts. — DK
 

Microsoft leads browsers in malware, phishing defense

Dan Kaplan August 14, 2009

Surprised? Microsoft came out on top in a recent test that studied how well the leading web browsers respond to malware and phishing.
 

WordPress issues new version, closes password flaw

Chuck Miller August 12, 2009

The widely deployed WordPress blogging platform was patched to repair yet another hole.
 

Top websites using Flash cookies to track user behavior

Angela Moscaritolo August 11, 2009

Little-known Adobe Flash cookies are being used by some websites to get around users' attempts to avoid being tracked by advertising networks, according to research from University of California, Berkeley.
 

Firefox plugs SSL bugs

Dan Kaplan August 03, 2009

Mozilla has patched two vulnerabilities relating to the way browsers interact with SSL certificates. The flaws, which potentially could permit man-in-the-middle attacks, were disclosed by two researchers, Dan Kaminsky and Moxie Marlinspike, in separate presentations at last week's Black Hat conference in Las Vegas. Marlinspike showed how a heap overflow bug could be exploited to present a specially crafted SSL certificate to the user, while Kaminsky revealed a way to obtain a certificate that would work on a victim site. Users are encouraged to download the latest version of Firefox 3.5. — DK
 

Browser SSL warnings shown to be ineffective

Angela Moscaritolo July 28, 2009

New research shows that Secure Socket Layer warnings, used in web browsers to indicate a problem with a web page's certificate or the potential for a man-in-the-middle attack, are ineffective.
 

Security bug found in latest Firefox version

Chuck Miller July 14, 2009

An unpatched vulnerability in the newest version of Firefox could enable a hacker to remotely run arbitrary code on users' machines.
 

Mozilla Firefox 3.5 officially released

Chuck Miller June 30, 2009

After a prolonged beta period, Mozilla has officially released its new version of Firefox.