Risk: High
Mozilla has published a new version of its Firefox web browser that fixes five security vulnerabilities, two of which it rates as critical.
Firefox version 3.0.2 fixes a memory corruption bug and a separate critical bug involving privilege escalation and the XPCnativeWrapper component of the browser. Both create possible mechanisms for hackers to inject hostile code into vulnerable systems using rigged websites.
The updates also fix three lesser flaws, two of which are rated as moderate and one of which earns a low risk rating.