Risk: High
Multiple vulnerabilities have been reported in Mozilla Firefox, which can be exploited by malicious people to conduct man-in-the-middle, spoofing and cross-site scripting attacks, and potentially compromise a user's system.
The flaws are due to a multitude of errors, including the handling of JavaScript regular expressions, verification of certain signatures in the bundled Network Security Services (NSS) library and cross-domain handling.
Firefox users are urged to update to version 2 immediately, which is packed full of new features and available at:
http://www.mozilla.com/firefox/