Jeff Jones on his blog about the Internet Explorer and Firefox Vulnerability Analysis Report:
For most people, their web browser is central to their interaction with the Internet, connecting to global web sites and helping them consume online services providing everything from booking flights to banking services to online shopping. This reality makes browsers a key tool when evaluating the security experience of users as the browser interprets Web content and programs delivered from around the world.
Over the past few years, there has been much discussion of the need for improvements in browser security, but few hard data studies performed to support assertions concerning the security of available browsers.
This report documents the results of my analysis of Internet Explorer and Firefox vulnerabilities over the past few years since Internet Explorer 6 on Windows XP SP2 became available and Mozilla launched Firefox.
The report in detail examines vulnerabilities over the past 3 years, breaks them down by severity, looks at version-over-version trends for each browser and finally examines how each browser is doing in terms of unfixed vulnerabilities.
http://blogs.technet.com/security/archive/2007/11/30/download-internet-explorer-and-firefox-vulnerability-analysis.aspx
In addition, see also my previous blog:http://blogs.technet.com/ms_schweiz_security_blog/archive/2007/12/01/the-first-year-of-ie7.aspx
Urs
Firefox IS the safest browser on this planet, because using it with the noscript, adblock plus, customize google and RDR add-ons lets you browse the web more secure than the IE will ever get. M$'s browser sucks ass and will never become a good browser at all, because what it does is copy the look and feel of the firefox without implementing a better setup of the software itself. The way the user can set up the IE is just lame and way to complicated. GET TO WORK GUYS AND STOP SHITTIN' AROUND!!!
the analysis do not taken undocumented vulnerabilities of IE and the response time to zero-day exploit release for each browser..
Firefox responsed quickly than IE when some vulnerabilities discovered, as it is open source coded.