Secunia CSI 5.0
Personal Software Inspector (PSI)
Online Software Inspector (OSI)
Features
Programs Covered
System Requirements
Reminder Service
Privacy
FAQ

Frequently Asked Questions

  1. Why do I get an "Unable to load Java applet" error every time I try to access the Secunia OSI?
  2. For the items marked as "insecure", how do I upgrade to the new, secure versions?
  3. For the items marked as "insecure", do I need to uninstall the old version before updating?
  4. How do I uninstall items that are not in the "Add or Remove Programs" section?
  5. Why do I have so many versions of Flash/Java?
  6. Windows Update says my Windows files are up to date, but the Secunia OSI is still reporting my software as insecure. What should I do?
  7. My software has an Automatic Update feature but the Secunia OSI is reporting the version as "insecure". What should I do?
  8. I've already (manually) updated my software version, but the Secunia Software Inspector is still reporting my software as insecure. What should I do?
  9. What can happen if I choose not to upgrade or update my insecure or end-of-life software?
  10. The Secunia OSI detects my software as secure, but I know that there is a more recent version of the software. Does this mean that I am really secure?
  11. I recently updated my vulnerable software to a BETA version, and now the Secunia OSI does not detect it anymore. What happened?
  12. What is the difference between the Secunia OSI (Online Software Inspector) and the Secunia PSI (Personal Software Inspector)?
  13. What is the difference between the Secunia OSI (Online Software Inspector) and the Secunia CSI (Corporate Software Inspector)?
  14. The Secunia OSI and the Secunia PSI give different or conflicting results. What does that mean?
  15. How often do you update detection rules?
  16. How can I suggest a feature or report an error in the Secunia OSI?
  1. Why do I get an "Unable to load Java applet" error every time I try to access the Secunia OSI?

    This error can be caused by a variety of reasons:

    • You do not have the minimum version of Java installed. You need Sun Java JRE 1.6.x or later installed in your system. To check if you have the latest version, go to www.java.com.
    • If you have the latest version installed, check if you can access other websites that use Java.
      • If you cannot access other websites that use Java, then this is likely a compatibility problem between your browser and your Java plug-in. Please refer to your browser documentation for more informaton, or use an alternative browser to access the Secunia OSI.
      • If you can access other websites but not the Secunia OSI, please refer to 16) below for instructions on how to submit errors to Secunia.
  2. For the items marked as "insecure", how do I upgrade to the new, secure versions?

    The purpose of the Secunia OSI is to identify insecure software versions, and recommend secure versions for upgrade or installation purposes. However, the actual information on maintenance and remediation of the software is the responsibility of the vendor.

  3. For the items marked as "insecure", do I need to uninstall the old version before updating?
  4. Upgrading rules are very much based on vendor specifications. It is recommended that you read the product documentation or contact vendor support to determine the best course of action.

  5. How do I uninstall items that are not in the "Add or Remove Programs" section?

    For programs that are not included in the programs list in the "Add or Remove Programs" section, you should contact the vendor, or refer to the software documentation, for instructions on how to remove the item. In addition, please note that some applications detected by the Secunia OSI may be components of, or bundled with, other applications. In this case, you should refer to support and documentation of the main application.

  6. Why do I have so many versions of Flash/Java?

    Old versions of Adobe Flash Player and Java among other programs, are not always automatically removed when installing a newer version. That is why the Secunia OSI informs you of the vulnerable version that is still present on your PC. To see for yourself exactly which file is detected and where it is located, you can follow the installation path provided in the scanning result. Right-clicking the detected file and choosing properties will show you its exact file version information.

    To uninstall old versions of Adobe Flash Player, please visit: http://kb2.adobe.com/cps/141/tn_14157.html

    If you are unable to uninstall an old version of a program you can contact the vendor of the program for advice. You are also welcome to visit our Community where many other users have dealt with these issues. Direct link: http://secunia.com/community/forum/

  7. Windows Update says my Windows files are up to date, but the Secunia OSI is still reporting my software as insecure. What should I do?

    Please check the "Installed on Your System in:" path of the detected insecure application. If the installation path begins with "C:\Windows\...", please send all relevant details (including screenshots, whenever possible) to support@secunia.com.

    However, please note that some Windows systems may have an "installation backup" folder located in your computer, which can be used to reinstall your copy of Windows programs in the absence of an installation disc. For example, a common "installation backup" folder is "C:\i386".

    The Secunia PSI may detect certain Windows programs in these "installation backup" folders as insecure. This may be because Windows Update installs patches only in the default installation folder of Windows, and not in "installation backup" folders. As a result, while your usable Windows files are patched, your backup Windows files may not be.

    Another possible explanation is that Microsoft develops files that can be used by third-party vendors (such as .DLL or Framework files). If a vulnerability is patched by Microsoft in the original file, third-party vendors should follow suit by providing updates for their products. However, this is sometimes not the case, and as a result, Microsoft-developed vulnerable files in third-party applications may be detected by the Secunia PSI as insecure if the non-Microsoft vendor fails to supply an update.

    You can check if the detected vulnerable file is in a third-party application by checking the "Installed on Your System in:". If the path is not "C:\Windows\..." or "C:\WINNT\...", then the vulnerable file is likely used by a third-party application, and should be addressed by the appropriate vendor.

  8. My software has an Automatic Update feature but the Secunia OSI is reporting the version as "insecure". What should I do?

    In this case, Secunia recommends that you update your software manually even if your program has an Auto Updating feature. If you verify that you are running the recommended latest secure version, but the Secunia OSI still marks it as "insecure", please see the Answer for 8) below.

  9. I've already (manually) updated my software version, but the Secunia Software Inspector is still reporting my software as insecure. What should I do?

    First, verify with the vendor if the product version that you have is indeed the latest. If the vendor agrees that you have the latest version, please send all relevant details (including screenshots, whenever possible) to support@secunia.com.

    Please take note that due to the large volume of emails, you will likely not receive a response. However, all reported issues are tracked, and detection rules are updated accordingly.

  10. What can happen if I choose not to upgrade or update my insecure or end-of-life software?

    Secunia recommends that you upgrade or update your insecure or end-of-life software to ensure that your system is protected against vulnerabilities located in these software. However, it is of course your prerogative not to upgrade or update as you see fit. In this case, it is important that you understand possible consequences of not performing the update. These include the possibility that your system may experience various malicious attacks (hacking attacks, automatic installation of malware in your system etc.) and, in the case of end-of-life software, the discontinued support of the vendor.

  11. The Secunia OSI detects my software as secure, but I know that there is a more recent version of the software. Does this mean that I am really secure?

    Software can be detected by the Secunia OSI as secure, even if the vendor has released a more recent version. This is because vendors release software updates not just to patch vulnerabilities, but also to fix software bugs or introduce software enhancements. These fixes and enhancements may be non-security related (for example, adding new functionality or features). Therefore, prior versions of software can be secure even if they are not the most recent ones, as long as no known vulnerabilities are reported in them.

    In these cases, Secunia recommends that you read the vendor release notes to determine if you prefer to install the update or not.

  12. I recently updated my vulnerable software to a BETA version, and now the Secunia OSI does not detect it anymore. What happened?

    The Secunia OSI does not monitor and detect BETA versions of software. However, the next stable release after the BETA version will, of course, be detected by the Secunia OSI.

  13. What is the difference between the Secunia OSI (Online Software Inspector) and the Secunia PSI (Personal Software Inspector)?

    The Secunia OSI identifies about 100 of the most common programs, while the Secunia PSI can identify practically any program. In addition, the Secunia OSI is run using the web browser, while the Secunia PSI is a program the user downloads and installs.

  14. What is the difference between the Secunia OSI (Online Software Inspector) and the Secunia CSI (Corporate Software Inspector)?

    The Secunia CSI is a commercial product designed to allow you to scan for practically any program in computers within a network (such as in an office environment), making it ideal for corporate users. For sales and pricing inquiries please contact sales@secunia.com.

    In contrast, the Secunia OSI is a browser-based application designed for private users. It scans for about 100 of the most common applications in the computer in which the application is run.

  15. The Secunia OSI and the Secunia PSI give different or conflicting results. What does that mean?

    Since the Secunia PSI can identify practically any program, while the Secunia OSI identifies about 100, it is recommended that you refer to the Secunia PSI for the most thorough results.

    If you think you have different or conflicting results after trying out both scans, we suggest that you take notice of the application name, version number, and installation path. Even though an application only has one name, different versions of it may be installed in your system; some of these versions may be secure while others are not.

    Pay special attention to the following:

    • Unless the checkbox “Enable thorough system inspection” in enabled during scanning with the Secunia OSI, only programs installed in their default installation path is detected. The Secunia PSI however always searches through all available drives and will detect programs even if they are not installed in their default installation path.
    • The Secunia PSI has a feature called “Show only Easy-to-Patch programs”. Using the advanced interface of the Secunia PSI this feature can be changed in the Settings-tab. With this feature enabled certain program that the Secunia staff has marked as difficult to patch will be removed from the interface of the Secunia PSI. So with this option enabled the Secunia OSI may detect certain programs that the Secunia PSI does not detect.

     

  16. How often do you update detection rules?

    Secunia Research develops new detection rules every time a vendor releases a security patch for any vulnerability in a product detected by the Secunia PSI and CSI. For example, new detection rules are created after every Microsoft Tuesday patch cycle, as this allows the Secunia PSI and CSI to check if your Windows systems patches are up to date or not. When a detection rule is updated for a program that is on the list of programs detected by the Secunia OSI, the scanning result for the Secunia OSI will reflect the new detection rules.

  17. How can I suggest a feature or report an error in the Secunia OSI?

    For feature requests, please submit all suggestions to support@secunia.com. In addition, for error inquiries, please send all relevant details (including screenshots, whenever possible) to support@secunia.com.

    Please take note that due to the large volume of emails, we cannot guarantee a reply to everyone. However, all reported issues are tracked, and detection rules are updated accordingly. Those feature requests that are accepted will be reflected on subsequent versions of the Secunia OSI.

Secunia OSI Forum
Tell a Friend




 Products Solutions Customers Partner Resources Company
 
 Corporate
Vulnerability Intelligence Manager (VIM)
Corporate Software Inspector (CSI)
Consumer
Personal Software Inspector (PSI)
Online Software Inspector (OSI)
 Industry
Compliance
Technology
Integration
 Customers
Testimonials
 VARS
MSSP
Technology Partners
References
 Factsheets
Reports & Papers
Webinars
Events
 About us
Careers
Memberships
Newsroom


 
© 2002-2012 Secunia ApS - Rued Langgaards Vej 8, 4th floor, DK-2300 Copenhagen, Denmark - +45 7020 5144
Terms & Conditions and Copyright - Privacy - Report Vulnerability