
Sans Institute : System Administration and Network Security Institute
Sans is focused on reporting system vulnerabilities. One of Sans main focus is to sell training programs to keep the network secure.
Here is an excerpt from Sans on their top twenty list of vulnerabilities.
Excerpt
Microsoft Internet Explorer is the world's most popular web browser and is installed by default on every Microsoft Windows system. Unpatched or older versions of Internet Explorer contain multiple vulnerabilities that can lead to memory corruption, spoofing and execution of arbitrary scripts or code. The most critical issues are the ones that lead to remote code execution without any user interaction when a user visits a malicious web page or reads a malicious email. Exploit code for many of these critical Internet Explorer flaws is publicly available. In addition, Internet Explorer has been leveraged to exploit vulnerabilities in other core Windows components such as HTML Help and the Graphics Rendering Engine. During the past year, hundreds of vulnerabilities in ActiveX controls installed by Microsoft and other software vendors have been discovered. These are also being exploited via Internet Explorer.
|