Is Flash really that bad or is everyone else just bad at reporting zero-day exploits publicly?
Is Flash really that bad or is everyone else just bad at reporting zero-day exploits publicly?
http://en.wikipedia.org/wiki/Adobe_Flash#Flash_client_securi...
Also "Zero Day Exploits" generally mean that the exploit was released to 3rd parties before it was given to the company whose software was being exploited.
Vulnerability known before the vendor can release a fix is "zero-day".
Acrobat 9.4.1 takes over to install. Oh that's right, there's a vulnerability in that version, so now we're gonna have to push 9.4.2
When a user's Flash installation is corrupted, many times the uninstaller fails, so we have to use Windows Installer Cleanup to remove it. Every week, there's a new issue. Can't these fellows get it right?
One of the best ways to get any bug fixed in any Library, OS etc... is to find a way to exploit it.
Java has ~3 times as many holes as Flash does (if one is comparing in the context of "browser plugins").