madison

Zero Day

Ryan Naraine and Dancho Danchev

Kaspersky: 12 different vulnerabilities detected on every PC

By | August 18, 2011, 8:18am PDT

Summary: Researchers from Kaspersky have sampled their customer base, and found out that on average, every PC has 12 different vulnerabilities.

Researchers from Kaspersky have sampled their customer base, and found out that on average, every PC has 12 different vulnerabilities.

During the second quarter of 2011, the company saw 27,289,171 vulnerable applications and files detected on users’ computers, and detected an average of 12 different vulnerabilities on each computer.

Here are the vulnerabilities discovered:

  • Adobe Reader / Acrobat SING “uniqueName” Buffer Overflow Vulnerability
  • Sun Java JDK / JRE / SDK Multiple Vulnerabilities
  • Adobe Flash Player SharedObject Type Confusion Vulnerability
  • Adobe Flash Player Multiple Vulnerabilities
  • Adobe Flash Player Multiple Vulnerabilities
  • Sun Java JDK / JRE / SDK Multiple Vulnerabilities
  • Adobe Flash Player / AIR AVM2 Instruction Sequence Handling Vulnerability
  • Adobe Flash Player Unspecified Memory Corruption Vulnerability
  • Adobe Shockwave Player Multiple Vulnerabilities
  • Adobe Flash Player Unspecified Cross-Site Scripting Vulnerability

The company contributes the decline in Windows vulnerabilities, to improvements in the automatic Windows update mechanism and the growing proportion of users who have Windows 7 installed on their PCs. Moreover, Kaspersky Labs emphasizes on the fact that seven of the Top 10 vulnerabilities are found in one product only — Adobe Flash Player, and that vulnerabilities from 2007-2008 remain in the Top 10, with seven of the ten vulnerabilities were discovered in 2011, and the other three in 2010.

See also

With vulnerabilities found in Acrobat Reader and Adobe products clearly dominating the threatscape, end users and enterprise users should ensure that they are running the latest versions of their installed applications and browser plugins, at any time.

Kick off your day with ZDNet's daily e-mail newsletter. It's the freshest tech news and opinion, served hot. Get it.

Topics

Dancho Danchev is an independent security consultant and cyber threats analyst, with extensive experience in open source intelligence gathering, malware and cybercrime incident response.

Disclosure

Dancho Danchev

More details on Dancho Danchev's current and past professional affiliations, can be found in his LinkedIn profile.

Biography

Dancho Danchev

Dancho Danchev is an independent security consultant and cyber threats analyst, with extensive experience in open source intelligence gathering, and cybercrime incident response. He's been an active security blogger since 2007, and maintains a popular security blog sharing real-time threats intelligence data with the rest of the community on a daily basis. More details on Dancho Danchev's current and past professional affiliations, can be found in his LinkedIn profile. You can also follow him on Twitter

Talkback Most Recent of 25 Talkback(s)

Talkback - Tell Us What You Think

Formatting +
BB Codes - Note: HTML is not supported in forums
  • [b] Bold [/b]
  • [i] Italic [/i]
  • [u] Underline [/u]
  • [s] Strikethrough [/s]
  • [q] "Quote" [/q]
  • [ol][*] 1. Ordered List [/ol]
  • [ul][*] · Unordered List [/ul]
  • [pre] Preformat [/pre]
  • [quote] "Blockquote" [/quote]
Click Here

The best of ZDNet, delivered

ZDNet Newsletters

Get the best of ZDNet delivered straight to your inbox

Facebook Activity

White Papers, Webcasts, & Resources