Showing posts with label Firefox. Show all posts
Showing posts with label Firefox. Show all posts

Thursday, March 05, 2009

Firefox 3.0.7 targets security issues


Mozilla on Wednesday released an update to the Firefox Web browser that its developers said fixes eight security issues found in Firefox 3.0.6, six of which were rated critical.

The most serious of the vulnerabilities fixed in Version 3.0.7 could allow attackers to run arbitrary code on a victim's computer, Mozilla warned in security advisories Wednesday.

The six critical flaws affected the browser's garbage collection, which monitors how Firefox modules use the computer's memory, as well as the browser's PNG libraries and in the layout and JavaScript engines.

Firefox 3.0.7 fixes several issues found in Firefox 3.0.6:

* Fixed several security issues.
* Fixed several stability issues.
* Official releases for the Estonian, Kannada, and Telugu languages are now available.
* Items in the "File" menu show as inactive after using the "Print" item from that menu - switching to a new tab restores them (bug 425844). This issue has been fixed.
*For some users, cookies would appear to go “missing” after a few days (bug 444600).
* Mac users of the Flashblock add-on, experienced an issue where sound from the Flash plug-in would continue to play for a short time after closing a tab or window (bug 474022).
* Fixed several issues related to accessibility features.

Mozilla developers said they weren't sure the layout and JavaScript flaws could be exploited.

"Some of these crashes showed evidence of memory corruption under certain circumstances and we presume that with enough effort at least some of these could be exploited to run arbitrary code," Mozilla said in an advisory.

Updates for Windows, Mac OS X, and Linux are available at the Mozilla site. Firefox 3 users will receive an update notification within 48 hours, or they can download the update manually by selecting "Check for Updates" from the Help menu.

The update, Mozilla's second this year, comes as Firefox continues to chip away at Internet Explorer's market dominance. Mozilla now has 21.77 percent of the global browser market share, compared with IE's 67.44 percent, a drop of more than 7 percentage points in a year.

Saturday, December 01, 2007

Firefox update 2.0.0.11


The Mozilla Firefox team has released Firefox 2.0.0.10 just two days ago but a bug discovered after the release prompted them to take immediate action. The bug is affecting an important HTML element interface which makes some extensions and websites unusable with that version of Firefox.

You can download the Firefox update 2.0.0.11 by clicking on Help / then Check for Updates on Firefox's menu.

Wednesday, October 24, 2007

Firefox 2.0.0.8 update to be updated soon

From Mozilla "The 2.0.0.8 release fixed some 200 issues, but accidentally regressed a few things. Most users won’t see any difference or experience any problems, and those 200 fixes make the 2.0.0.8 update very valuable, but you should never have to choose functionality over security. So we’re working fast to understand and fix these problems, and will shortly be issuing a 2.0.0.9 update to address them."

Read more about this issue here
.

Friday, October 19, 2007

New version of Firefox was released yesterday 2.0.0.8

A new version of Firefox was released yesterday. It's available on the official Mozilla website and through the update check in Firefox itself. Two critical, five moderate and two low security vulnerabilities have been fixed in the new version which makes it a recommended update for all Firefox users.

Fixed in Firefox 2.0.0.8

MFSA 2007-36 URIs with invalid %-encoding mishandled by Windows

MFSA 2007-35 XPCNativeWrapper pollution using Script object

MFSA 2007-34 Possible file stealing through sftp protocol

MFSA 2007-33 XUL pages can hide the window titlebar

MFSA 2007-32 File input focus stealing vulnerability

MFSA 2007-31 Browser digest authentication request splitting

MFSA 2007-30 onUnload Tailgating

MFSA 2007-29 Crashes with evidence of memory corruption (rv:1.8.1.8)

Get Firefox 2.0.0.8 here.

Thursday, September 27, 2007

Opera vs Firefox vs Internet Explorer

I saw this funny group of pictures over at Operawatch and thought it was hilarious. It is a visual comparison of how Firefox, Opera and Internet Explorer would look if they were vehicles.







Sunday, September 16, 2007

Free Software that I like

Free Software:

AVG free Antivirus

Windows Live Messenger

SMPlayer It's better than VLC media player and Media Player Classic. It's able to play the most known video & audio formats without the need of external codecs.

OpenOffice free office suite

GIMP GNU image manipulation program ( Like Adobe Photoshop, but Free )

Foobar2000 Great Free Media Player ( I like this better than Winamp, Itunes, and Windows Media Player )

Opera ( Probably the best Web Browser )

Firefox ( Another great Web Browser )

smartftp, the free secure FTP client for Windows

CCleaner CCleaner is a freeware system optimization and privacy tool.

Linux Operating System ( Ready to dump windows? )

30 Essential Pieces Of Free (and Open) Software for Windows

If that's not enough to get you started go to The Free Software Foundation ( Tons of Great Stuff Here )

Thursday, March 29, 2007

Vulnerability in Windows Animated Cursor Handling

Watch out for those web sites that have animated cursors. Especially make sure you don't surf to those with Internet Explorer unless you want to leave your computer vulnerable to hackers.

Microsoft has issued a notice that it is investigating the vulnerability. If users visit a web site or view an e-mail containing hacked .ani files (the animated cursor file type), so Microsoft's advice for the moment: be careful when opening unsolicited emails or browsing new web sites.

The vulnerability appears to affect Internet Explorer 6 and 7 running on Windows XP SP2.

All the more reason to switch to either Firefox or Opera for you browser.

Microsoft Security Advisory (935423)
Title: Vulnerability in Windows Animated Cursor Handling

Wednesday, February 28, 2007

How to use filters to Download all the MP3's on a Web page

Over at Lifehacker today they have a great article on how to supercharge your Firefox downloads with DownThemAll. DownThemAll is a powerful yet easy-to-use Mozilla Firefox extension that adds new advanced download capabilities to your browser. Lifehacker explains how to use filters to Download all the MP3's on a Web page. Go take a look at this informative article.

Saturday, February 24, 2007

Mozilla Fixes Firefox Bugs

Mozilla Corp. has released an update to its Firefox browser, fixing a number of security flaws in the product.

The Firefox 2.0.0.2 release includes a fix for a bug disclosed by security researcher Michal Zalewsky last week. That flaw can be exploited by attackers to manipulate cookie information in the Firefox browser, making it probably the most important fix in the update, according to Window Snyder, Mozilla's head of security strategy.

"The potential to compromise a user's account is almost as serious as compromising their machine," she said Friday via instant message. "Since the details of how to exploit the vulnerability are publicly available the risk to users is increased."

The updates also include a fix for a previously undisclosed memory corruption flaw in the browser that could be exploited to run unauthorized software on a Firefox user's computer.

This flaw could also affect Thunderbird users who have configured their mail client to run JavaScript automatically, something that Mozilla does not recommend. Thunderbird is Mozilla's free e-mail client.

The patches were released on Friday afternoon and should soon be delivered via Firefox's automatic software update mechanism, Snyder said.

Mozilla has patched a total of seven Firefox bugs and is also addressing two bugs in Thunderbird.

The latest browser release also includes enhancements to make it run better with Windows Vista as well as support for the Afrikaans, Belarusian, Georgian and Kurdish languages.

Saturday, January 27, 2007

PC World says Opera is safer than either Internet Explorer or Firefox

In a recent issue of PC World magazine columnist Scott Spanbauer wrote about the importance of staying safe online while browsing. Here is what he had to say about the Opera browser:

“While no software is perfectly secure, many experts (including me) think the Opera browser is safer than either IE or Firefox.”

To be fair, it sounds like he’s basing it on the fact that Opera has a small market share, and thus malware authors aren’t targeting it yet.

Tuesday, January 16, 2007

Firefox Google Search vs Yahoo...



The search box built in to the Firefox browser defaults to the Google search engine. But say an internet user escapes the confines of Google, and looks something up in Yahoo, which makes a rival search engine. A message pops up on the top right of the screen, pictured above, encouraging the user to switch. And, look closely, that's a miniature Google logo being selected by the arrow. Here's betting that many Yahoo devotees, not the most sophisticated of internet users, get extremely confused. Bad Yahoo...

Friday, January 12, 2007

Yahoo Using Dirty Tactics to Switch Google & Firefox Users?

The power struggle between Yahoo and Google for your desktop just took an evil turn, with evidence that suggests Yahoo is covertly trying to switch Google search users without their explicit permission. Read the complete article here at Marketing Pilgrim.

Friday, January 05, 2007

Internet Explorer was vulnerable to threats 284 days in 2006

Brian Krebs at the Washington Post's Security Fix blog wanted to put together some statistics on how long it took major software providers to fix vulnerabilities last year. He started with Microsoft, and found that Internet Explorer was vulnerable to critical flaws for a total of 284 days. That's more than 9 months.

In fact, there were at least 98 days when Microsoft had not issued a fix even though criminals were actively exploiting some of those flaws to grab personal data from Internet Explorer users.

Krebs says he ran his data by Microsoft before posting it on the blog, and that aside from some minor issues, the company didn't bring up anything that would change the overall finding.

By comparison, Firefox was only vulnerable to a serious security threat for one 9 day period last year. What's interesting is that for 2006, Opera 8 and Opera 9 didn't suffer from a single extremely critical vulnerability as classified by Secunia (although both did suffer a single highly critical vulnerability).

Be sure to go read todays post. Krebs takes a look at the number of security patches issued for Microsoft Office in 2006.

Wednesday, December 20, 2006

First Security Updates for Firefox 2.0

Yesterday Mozilla released the first update for the Firefox 2.0 browser, it fixes eight security vulnerabilities.

According to the company, release 2.0.0.1 of Firefox fixes flaws in memory corruption as well as the way the browser executes RSS (really simple syndication), Javascript and CSS (cascading style sheets) code, among other vulnerabilities. Mozilla also patched similar flaws in its Firefox 1.5 browser.

Five of the eight flaws were rated as critical, according to Firefox. A critical rating means a Firefox user would be vulnerable to attack and remote software installation on their machines just from browsing the Web in the usual fashion. Two of the flaws were rated as high, while one received a low security-risk rating, Firefox said.

What's New in Firefox 2.0.0.1? Click here to find out.

Wednesday, November 22, 2006

Firefox, IE vulnerable to fake login pages

Mozilla's Firefox 2 and Microsoft's Internet Explorer 7 are vulnerable to a flaw that could allow attackers to steal passwords.

Dubbed a reverse cross-site request, or RCSR, vulnerability by its discoverer, Robert Chapin, the flaw lets hackers compromise users' passwords and usernames by presenting them with a fake login form. Firefox Password Manager will automatically enter any saved passwords and usernames into the form.

The data is then automatically sent to an attacker's computer without the user's knowledge.

Read more about this here

Sunday, November 12, 2006

Firefox 2's built in spell check

Now that Firefox 2 has a built in spell check, it still has one issue, it doesn’t automatically spell check all fields by default. The normal behavior is to only spell check multi-line text fields. If you want to have it always spell check all text fields you need to follow these three simple steps.

1. Go to about:config in your URL bar
2. Search for spellcheckDefault
3. Change the value of spellcheckDefault to 2

That’s it. Now Firefox will spell check all input boxes automatically.

Monday, October 23, 2006

Firefox 2 due out tomorrow

For those of you who don't want to take the risk of installing IE7 of their machine, preferring instead to wait for the final release of FireFox 2 instead, well rejoice! PC Word has just announced that the new version of Mozilla's browser will be available for download on Oct. 24. Just 1 day left until we can finally get our hands on one of the most expected pieces of software of the year.

Saturday, September 23, 2006

Want to Digg? Not if you have Firefox


Going to Digg today? Not if you use Firefox. I went to Digg.com and went to digg a post and received an error "Digg not saved, Please try again later." I tried it in IE and Opera and had no problem with Digg. Does Digg have a problem with Firefox? It looks like it. By the way I asked my son to test it and he had the same results as me.

Saturday, September 16, 2006

Firefox Update 1.5.0.7

Mozilla Firefox 1.5.0.7 is now available for download from the Mozilla Firefox product page. Users of previous version will be offered the upgrade through the Firefox software update system. This release fixes several critical security vulnerabilities. See the Mozilla Firefox 1.5.0.7 Release Notes for more information.

Monday, March 13, 2006

21 times more likely to get spyware with IE!

'In May and October, Levy and colleague Steven Gribble sent their crawlers to 45,000 Web sites, cataloged the executable files found, and tested malicious sites' effectiveness by exposing unpatched versions of Internet Explorer and Firefox to drive-by downloads." Here are their results...

read more | digg story