Many systems remain unpatched against known vulnerabilities
Many systems remain unpatched against known vulnerabilities
R E L A T E D   C O N T E N T
ADVERTISEMENT

Web-based threats reach critical levels

Security watchdog reports 600 new flaws in the past three months

Tom Sanders in California, vnunet.com 04 May 2005
ADVERTISEMENT

Security experts discovered over 600 new vulnerabilities and web-based threats in the first three months of 2005, according to the Sans Institute.

Although fixes for the flaws have been made available in most cases, the security watchdog warned that many systems remain unpatched.

"These critical vulnerabilities are widespread and many of them are being exploited right now in our homes and offices," said Alan Paller, research director at the Sans Institute.

The Institute's updated Top 20 Internet Security Vulnerabilities list can be seen here. All the flaws are characterised as 'critical'.

Among the newcomers are several non-Microsoft products, including media players from Apple and Real Networks, AOL's WinAmp, and antivirus products from F-Secure, McAfee, Symantec and Trend Micro.

The media players are all susceptible to buffer overflow attacks. Users could be infected by visiting a website containing malicious code. The flaw affects Windows and Mac OS users.

The antivirus flaws could offer a backdoor into a system that allows hackers to take remote control.

There were still plenty of Microsoft products on the list, however, including several versions of Windows, MSN Messenger and Internet Explorer.

The list included two vendors of enterprise applications. Oracle had to patch vulnerabilities in its database server, application server, E-business Suite and Collaboration Suite that would allow remote users access to information and control of databases.

Computer Associates suffered a security vulnerability in its Licence Package that put several of the vendor's software products at risk from a buffer overflow attack.

See also:

Security appliance sector growing at compound annual growth rate of 18 per centUnified threat management devices drive main growth, reports IDC  12 May 2005
Wurmark-K displays a picture of an albino gorillaMonkey business hides Wurmark-k payload  10 May 2005
British photon power paves way for data security revolution  03 May 2005
Phishing attacks dropped by nearly a half in AprilInternet users warned not to lower their guard  03 May 2005
Infected email appears to come from FifaPromise of World Cup tickets hides deadly payload  03 May 2005
Zafi.B still top of the listJust one new entry in April top 10  29 Apr 2005
InfoSecurity Europe 2005Vendors fail to practise what they preach  29 Apr 2005
SecurityThe latest wave of cyber-crimes and acts of vandalism have demonstrated once again that many systems are still vulnerable to attack.  15 Apr 2004

All Hacking

Like this story? Spread the news by clicking below:

Post this to Delicious del.icio.us    Post this to Digg Digg this    Post this to reddit reddit!

Permalink for this story
R E A D E R   C O M M E N T S

M A R K E T P L A C E
Sponsored links
F E A T U R E D   J O B S
| JAM Recruitment
Background A fantastic opportunity has just arisen within this growing multinational organisation. Working as an EMEA Advisory Consultant your main duties and responsibilities will be to provide advice and support to international organisations looking to ... more >
| Aston Carter
This is a hands-on development team lead position that will push you to the limit of your architectural and mentoring capabilities. Technical amp; development (Agile) • Create effective data solutions, in partnership with the relevant ... more >
| Aston Carter
C++ Research Developer Global Pharmaceutical Company London C++ Research Developer Biotechology Global Medical Company London Global Biotechnology Company specialising in the research and development of cutting edge health care products is looking for an innovative, ... more >
| Computer People
Junior Network Operations Engineer – Borehamwood - £24k Junior / entry level network operations engineer required, will be responsible for supporting external clients network and security solutions. Excellent entry level position as my client offers ... more >
More job opportunities