Vulnerability stats for Microsoft and OSS

Vulnerability stats for Microsoft and OSS

Posted 2005-12-26 20:07 by Christopher

[Note that I'm going to be revising this article in the near future, as it doesn't reflect the whole picture] 

Inevitably when discussing the merits of Open Source Software (OSS) vs. propritary software, the (in)security of Microsoft products is brought up.  I've gathered vulnerability numbers from Secunia, and did some non-scientific analysis on them.

I compared vulnerabilities in 2005 for operating systems (RedHat Advanced Server vs. Windows 2003),  web browsers (Firefox 1.x vs. Internet Explorer 6), e-mail products (Thunderbird vs. Outlook 2003), databases (PostgreSQL 8 vs SQL Server 2000), and office products (OpenOffice.org 1.1 vs. Office 2003).

In each case (except OOo vs. Office2k3, which was even) the OSS product had more vulnerabilities listed for 2005 than the propritary product.  It is also interesting, however, that in the two cases that can be compared (OS and web browser) there was a higher percentage of vulnerabilities marked "Extremely critical" and "highly critical" in the propritary product.  These numbers also don't reflect the number of vulnerabilities that are actually exploited, which may be higher for Windows (if you've know of a source for these stats please let me know.)

 

Product Vulnerabilities   Extreme or High
Firefox 1.x 22 32%
Internet Explorer 6 17 47%
 
Thunderbird 1.x 7 43%
Outlook 2003 0 0%
 
RedHat AS 4 136 25%
Windows 2003 36 31%
 
PostgreSQL 2 0%
MS SQL 2000 0 0%
 
OpenOffice 1.1 1 100%
Office 2003 1 100%