HomeSecuritySecunia Vulnerability Review the most vulnerable applications of 2015

Secunia Vulnerability Review the most vulnerable applications of 2015

Secunia documented 15,435 software vulnerabilities in 3,870 applications during 2014, according to its annual 2015 Vulnerability Review (Secunia Vulnerability Review 2015), released by the company this week.secunia 2015

The number represents an 18% increase in vulnerabilities and a 22% increase over programs in 2013. But if you ask the general public to guess which programs have the most vulnerabilities, you'll probably catch them off guard... unless they've read Secunia's report.

Google's Chrome browser tops the list with 504 vulnerabilities, followed by Oracle Solaris (483), Gentoo Linux (350) and Microsoft's Internet Explorer (289). Apple's Mac OS X is in 13th place with 147 vulnerabilities, while Microsoft's Windows 8 is in 20th place with 105 vulnerabilities listed.

Only two Microsoft programs are in the Top 20 of the list of core programs, which lists IBM applications, on eight separate occasions. Tivoli Endpoint Manager is one of the worst performers, with 258 vulnerabilities, earning 8th place. The following applications are: Tivoli Storage Productivity Center (231), IBM Websphere Application Server (210), IBM Domino (177), IBM Lotus Notes (174), IBM Tivoli Composite Application Manager For Transactions (136), IBM Tivoli Application Dependency Discovery Manager (136), IBM Tivoli Application Dependency Discovery Manager (122), and IBM Websphere Portal (107) – see table below.

Programs from the same company may well share the same vulnerabilities, so IBM's performance is probably not as bad as it seems. Also, having a large number of vulnerabilities listed doesn't necessarily mean a program is insecure: finding and fixing vulnerabilities helps make Chrome the most secure browser. However, that doesn't mean the patch will necessarily work perfectly.

However, the time to patch continues to decrease. Secunia reports that of the 15,435 vulnerabilities, 83 percent had an update made available to users as soon as the vulnerability was publicly disclosed.

As usual, Microsoft applications were not responsible for the majority of vulnerabilities on personal computers. According to Secunia, Microsoft applications (including the Windows 7 operating system) accounted for 69% of the products in the Top 50 most frequently installed programs on computers, but only 23% contained vulnerabilities. That may sound good, but the percentages are quite high considering the popularity of Microsoft programs.top50 2015

Windows 8 was obviously the version with the most vulnerabilities, but the number dropped from 156 in 2013 to 105 in 2014. Windows 7 fared even better, as the number of vulnerabilities dropped from 102 to 33.

Web browsers now. They had the most vulnerabilities in the Top 50 programs. Google's Chrome came in first with 504 recorded vulnerabilities, followed by IE (289) and Mozilla Firefox (171).

Other applications with vulnerabilities were: Oracle Java JRE (119), Adobe Flash Player (99), Apple iTunes (84), Adobe Air (59), Adobe Reader (43), Microsoft Windows 7 (33), Apple QuickTime (14) and Microsoft Word (13).
For the record, Apple's Safari had 92 vulnerabilities listed.

But the biggest security disasters this year came from open source software with Heartbleed, SSL, and ShellShock. Secunia says these problems “have drawn attention to a previously neglected security hot topic: the use of open source applications and libraries in IT environments.”

📧
Subscribe to the SecNews Newsletter

The most important Security & Technology news in your Inbox.

SecNews
SecNewshttps://www.secnews.gr
In a world without fences and walls, who needs Gates and Windows

SEARCH

FOLLOW US

📧
Newsletter SecNews
The most important Security & Technology news in your inbox.

LIVE NEWS