Categories: Security

Java poses the biggest security risks to PCs in US

According to a new series of reports published by Secunia firm, Oracle Java poses the biggest security risks to Desktop machines in the US.

According to the a new report published by Secunia security vendor, Oracle Java software represents the principal source of problems for private US desktops, followed by Apple Quicktime 7.x.

Oracle Java is of one of the most popular software, in 2014 the software was installed on 65 percent of computers, this aspect makes it a privileged target for hackers that exploit the numerous flaws discovered by the security community.

“If a vulnerable program remains unpatched on your PC, it means that your PC is vulnerable to being exploited by hackers. So if 49% of PCs running Adobe Reader X 10.x, who have a 32% market share, are unpatched, 16% of all PCs are made vulnerable by that program. The same PC can have several other unpatched, vulnerable programs installed. ” states the report.

The report issued by Secunia highlights that nearly 48 percent of users aren’t running the latest, patched versions, resulting exposed to numerous cyber threats.

“This is not because Java is more difficult to patch, but the program has a high market share and a lot of the users neglect to patch the program, even though a patch is available,” said Kasper Lingaard, the Secunia director of research and security.

In 2014, the security experts discovered 119 new vulnerabilities in Oracle Java software and 14 flaws in Apple Quicktime 7.x. Apple Quicktime was characterized by 57 percent penetration on desktops, but only 56 percent was patched.

The top-ten list of applications includes also Adobe Reader 10.x and 11.x, Microsoft .NET framework 2.x, 3.x, and 4.x, VLC Media Player 2.x, Internet Explorer 11.x and Microsoft XML Core Services 3.x.

Microsoft Internet Explorer is the software that contains the greatest number of vulnerabilities,  248, the number of flaws was increased compared last year.

Analyzing the distribution of vulnerabilities, it is possible to note that 47 percent of vulnerabilities last year was discovered in Microsoft applications, 47 percent for third-party software, and 6 percent of the operating system.

The data are coherent with the number of applications installed on desktop computers, which have in average 76 different programs installed from 27 different vendors, where Microsoft solutions account for 41 percent of the total.

Another concerning data is the percentage of users with unpatched operating system, nearly 12.9 percent while 5.7 percent of applications don’t have security patches available because they are in phase out (i.e. Adobe Flash Player 15 which is still installed on 73 percent of Desktops).

Secunia has released individual reports for eleven European countries, Australia, New Zealand and Saudi Arabia and results show a similar trend.

Enjoy reading the reports.

Pierluigi Paganini

(Security Affairs – Secunia, Java)

Pierluigi Paganini

Pierluigi Paganini is member of the ENISA (European Union Agency for Network and Information Security) Threat Landscape Stakeholder Group and Cyber G7 Group, he is also a Security Evangelist, Security Analyst and Freelance Writer. Editor-in-Chief at "Cyber Defense Magazine", Pierluigi is a cyber security expert with over 20 years experience in the field, he is Certified Ethical Hacker at EC Council in London. The passion for writing and a strong belief that security is founded on sharing and awareness led Pierluigi to find the security blog "Security Affairs" recently named a Top National Security Resource for US. Pierluigi is a member of the "The Hacker News" team and he is a writer for some major publications in the field such as Cyber War Zone, ICTTF, Infosec Island, Infosec Institute, The Hacker News Magazine and for many other Security magazines. Author of the Books "The Deep Dark Web" and “Digital Virtual Currency and Bitcoin”.

Recent Posts

CISA pushes Federal agencies to retire end-of-support edge devices

CISA ordered U.S. federal agencies to improve management of edge network devices and replace unsupported…

7 hours ago

Record-breaking 31.4 Tbps DDoS attack hits in November 2025, stopped by Cloudflare

AISURU/Kimwolf botnet hit a record 31.4 Tbps DDoS attack lasting 35 seconds in Nov 2025,…

1 day ago

Nearly 5 Million Web Servers Found Exposing Git Metadata – Study Reveals Widespread Risk of Code and Credential Leaks

A study found nearly 5 million servers exposing Git metadata, with 250,000 leaking deployment credentials…

1 day ago

U.S. CISA adds SmarterTools SmarterMail and React Native Community CLI flaws to its Known Exploited Vulnerabilities catalog<gwmw style="display:none;"></gwmw>

U.S. Cybersecurity and Infrastructure Security Agency (CISA) adds SmarterTools SmarterMail and React Native Community CLI…

1 day ago

Hacker claims theft of data from 700,000 Substack users; Company confirms breach

Substack confirmed a data breach after a hacker leaked data from nearly 700,000 users, including…

2 days ago

Pro-Russian group Noname057(16) launched DDoS attacks on Milano Cortina 2026 Winter Olympics

Italy stopped Russian-linked cyberattacks targeting Foreign Ministry offices and Winter Olympics websites and hotels, Foreign…

2 days ago

This website uses cookies.