Risk: High
Mozilla has issued a security update addressing a variety of vulnerabilities that can result in Cross-Site Scripting, spoofing and system access.
A cookie flaw was discovered by an 'ethical hacker' from Poland, the details of which were posted on a security mailing list in February. Various other flaws were found by other security experts, including a Password Manager vulnerability that could facilitate phishing attacks, an error in the handling of the "locations.hostname" DOM property which could be exploited to bypass certain security restrictions, and a flaw that permitted an attacker to access locally saved files if a user could be tricked into following a malicious URL.
Firefox users should apply Mozilla's update or select 'check for updates' in the Firefox help menu as a matter of urgency.