<?xml version="1.0" encoding="UTF-8"?><rss version="2.0"
	xmlns:content="http://purl.org/rss/1.0/modules/content/"
	xmlns:dc="http://purl.org/dc/elements/1.1/"
	xmlns:atom="http://www.w3.org/2005/Atom"
	xmlns:sy="http://purl.org/rss/1.0/modules/syndication/"
		>
<channel>
	<title>Comments on: Firefox leads in browser vulnerabilities</title>
	<atom:link href="http://tech.blorge.com/Structure:%20/2009/11/09/firefox-leads-in-browser-vulnerabilities/feed/" rel="self" type="application/rss+xml" />
	<link>http://tech.blorge.com/Structure:/2009/11/09/firefox-leads-in-browser-vulnerabilities/</link>
	<description>Top Technology news</description>
	<lastBuildDate>Mon, 13 Feb 2012 11:40:13 +0000</lastBuildDate>
	<sy:updatePeriod>hourly</sy:updatePeriod>
	<sy:updateFrequency>1</sy:updateFrequency>
	<generator>http://wordpress.org/?v=3.2.1</generator>
	<item>
		<title>By: Robert</title>
		<link>http://tech.blorge.com/Structure:/2009/11/09/firefox-leads-in-browser-vulnerabilities/comment-page-1/#comment-227882</link>
		<dc:creator>Robert</dc:creator>
		<pubDate>Wed, 11 Nov 2009 04:56:01 +0000</pubDate>
		<guid isPermaLink="false">http://tech.blorge.com/Structure:/2009/11/09/firefox-leads-in-browser-vulnerabilities/#comment-227882</guid>
		<description>Secunia PSI shows; Description:
Stefan Esser has discovered a vulnerability in Internet Explorer, which can be exploited by malicious people to conduct cross-site scripting attacks.

The vulnerability exists because pages that don&#039;t specify a charset inherit the charset of the parent page. This can be exploited to execute arbitrary HTML and script code in a user&#039;s browser session in context of certain sites that are included e.g. via iframes in a malicious page that uses UTF-7 as charset.

Successful exploitation requires that the user is tricked into visiting a malicious web site.

The vulnerability is confirmed in Internet Explorer 7 and 8 on a fully patched Windows XP. Other versions may also be affected. While Mozilla Firefox 3.5.5 shows up as fully patched and SECURE.</description>
		<content:encoded><![CDATA[<p>Secunia PSI shows; Description:<br />
Stefan Esser has discovered a vulnerability in Internet Explorer, which can be exploited by malicious people to conduct cross-site scripting attacks.</p>
<p>The vulnerability exists because pages that don&#8217;t specify a charset inherit the charset of the parent page. This can be exploited to execute arbitrary HTML and script code in a user&#8217;s browser session in context of certain sites that are included e.g. via iframes in a malicious page that uses UTF-7 as charset.</p>
<p>Successful exploitation requires that the user is tricked into visiting a malicious web site.</p>
<p>The vulnerability is confirmed in Internet Explorer 7 and 8 on a fully patched Windows XP. Other versions may also be affected. While Mozilla Firefox 3.5.5 shows up as fully patched and SECURE.</p>
]]></content:encoded>
	</item>
	<item>
		<title>By: JDM</title>
		<link>http://tech.blorge.com/Structure:/2009/11/09/firefox-leads-in-browser-vulnerabilities/comment-page-1/#comment-227312</link>
		<dc:creator>JDM</dc:creator>
		<pubDate>Mon, 09 Nov 2009 22:47:50 +0000</pubDate>
		<guid isPermaLink="false">http://tech.blorge.com/Structure:/2009/11/09/firefox-leads-in-browser-vulnerabilities/#comment-227312</guid>
		<description>I suppose this is the greatest strength and weakness in any popular Opensource product.  

However, comparing Opensource and proprietary browsers on the basis of &quot;vulnerability&quot; is unfair to both.</description>
		<content:encoded><![CDATA[<p>I suppose this is the greatest strength and weakness in any popular Opensource product.  </p>
<p>However, comparing Opensource and proprietary browsers on the basis of &#8220;vulnerability&#8221; is unfair to both.</p>
]]></content:encoded>
	</item>
	<item>
		<title>By: mick</title>
		<link>http://tech.blorge.com/Structure:/2009/11/09/firefox-leads-in-browser-vulnerabilities/comment-page-1/#comment-227296</link>
		<dc:creator>mick</dc:creator>
		<pubDate>Mon, 09 Nov 2009 22:08:00 +0000</pubDate>
		<guid isPermaLink="false">http://tech.blorge.com/Structure:/2009/11/09/firefox-leads-in-browser-vulnerabilities/#comment-227296</guid>
		<description>spot on dorian, i use google chromium</description>
		<content:encoded><![CDATA[<p>spot on dorian, i use google chromium</p>
]]></content:encoded>
	</item>
	<item>
		<title>By: dorian</title>
		<link>http://tech.blorge.com/Structure:/2009/11/09/firefox-leads-in-browser-vulnerabilities/comment-page-1/#comment-227292</link>
		<dc:creator>dorian</dc:creator>
		<pubDate>Mon, 09 Nov 2009 22:06:27 +0000</pubDate>
		<guid isPermaLink="false">http://tech.blorge.com/Structure:/2009/11/09/firefox-leads-in-browser-vulnerabilities/#comment-227292</guid>
		<description>correct ncaissie, if u look at data, firefox is in fact slower than IE to correct vulnerabilities. I am surprised the article does not mention google chrome which only accounts for 1.2% of vulnerabilities, is updated fast and is (with its recent update) faster than firefox. I however use Opera</description>
		<content:encoded><![CDATA[<p>correct ncaissie, if u look at data, firefox is in fact slower than IE to correct vulnerabilities. I am surprised the article does not mention google chrome which only accounts for 1.2% of vulnerabilities, is updated fast and is (with its recent update) faster than firefox. I however use Opera</p>
]]></content:encoded>
	</item>
	<item>
		<title>By: ncaissie</title>
		<link>http://tech.blorge.com/Structure:/2009/11/09/firefox-leads-in-browser-vulnerabilities/comment-page-1/#comment-227250</link>
		<dc:creator>ncaissie</dc:creator>
		<pubDate>Mon, 09 Nov 2009 19:30:31 +0000</pubDate>
		<guid isPermaLink="false">http://tech.blorge.com/Structure:/2009/11/09/firefox-leads-in-browser-vulnerabilities/#comment-227250</guid>
		<description>You are wrong geo.
Firefox does not update very often. MS has procedures to follow and is accountable. Open source is not.</description>
		<content:encoded><![CDATA[<p>You are wrong geo.<br />
Firefox does not update very often. MS has procedures to follow and is accountable. Open source is not.</p>
]]></content:encoded>
	</item>
	<item>
		<title>By: geolight</title>
		<link>http://tech.blorge.com/Structure:/2009/11/09/firefox-leads-in-browser-vulnerabilities/comment-page-1/#comment-227176</link>
		<dc:creator>geolight</dc:creator>
		<pubDate>Mon, 09 Nov 2009 13:37:24 +0000</pubDate>
		<guid isPermaLink="false">http://tech.blorge.com/Structure:/2009/11/09/firefox-leads-in-browser-vulnerabilities/#comment-227176</guid>
		<description>The important bit is how fast do they address and fix those vulnerability? Microsoft takes forever to fix anything in IE, where are Firefox addresses vulnerability very fast, as such, a fully patched Firefox is waaay better than a fully patched IE. enough said....</description>
		<content:encoded><![CDATA[<p>The important bit is how fast do they address and fix those vulnerability? Microsoft takes forever to fix anything in IE, where are Firefox addresses vulnerability very fast, as such, a fully patched Firefox is waaay better than a fully patched IE. enough said&#8230;.</p>
]]></content:encoded>
	</item>
</channel>
</rss>

