Some vulnerabilities and weaknesses have been fixed in the latest
Various errors have been fixed in Firefox's browser engine and Javascript engine, which can be exploited to cause a memory corruption and allow the execution of arbitrary code.
A weakness due to a design error within the focus handling and which can potentially be exploited to trick a user into uploading arbitrary files has also been fixed.
An error in the handling of images when a user leaves a page, which uses "designMode" frames, can be exploited to disclose the user's navigation history, forward navigation information, and to cause a memory corruption. Successful exploitation of this vulnerability may allow execution of arbitrary code.
A design error related to timer-enabled dialogs can be exploited to trick a user into unintentionally confirming a security dialog.
A problem in Firefox, which follows "302" redirects for stylesheets and allows reading the target URL via "element.sheet.href", can potentially be exploited to disclose sensitive URL parameters.
The vulnerabilities are reported in versions prior to 2.0.0.12. Users
are advised to download the updated version immediately.


<< Home