There's a bug in Mozilla Firefox 3.0.10 and SeaMonkey 1.1.16 that may allow an attacker to run hostile code via a bug in the way JavaScript handles chrome objects. This is rated as a critical bug - if you can't get the fix in Firefox 3.0.11 or SeaMonkey1.1.17, then you should disable JavaScript until you do. Security researcher moz_bug_r_a4 gets credit for finding this bug. Get the download via the Firefox Help>Check for Updates command.
Comments