Risk: Medium
HD Moore, who created security tool Metasploit Framework, declared that he would publish a new bug for every day on his blog at http://browserfun.blogspot.com/ throughout July.
True to his word, Moore published a multitude of flaws, including some in Internet Explorer, Firefox and Safari. The IE flaw could permit arbitrary code execution and is classified as 'highly critical' by Secunia.
On his blog at the beginning of July, Moore stated: "This blog will serve as a dumping ground for browser-based security research and vulnerability disclosure. The hacks we publish are carefully chosen to demonstrate a concept without disclosing a direct path to remote code execution."
References
- http://www.zdnet.com.au/news/security/soa/July_is_the_month_of_browser_bugs_Security_expert/0,2000061744,39262392,00.htm
- http://www.computerworld.com/action/article.do?command=viewArticleBasic&articleId=9001610&source=NLT_VVR&nlid=37
- http://browserfun.blogspot.com/
- http://secunia.com/advisories/20906/