Platform
Learning Storage Performance
- The remaining six bugs, which affect both browsers, are capable of the following: [list:b944283877]
- One of the flaws enables certain pop-ups can execute malicious code on a system if the user opens the pop-up.
- A bug in the way windows and tabs are handled can allow malicious code from an untrusted site to execute in the context of another site.
- A bug involving the URLs of "favicons" icons allows JavaScript code to execute with escalated privileges.
- A bug in installing search plug-ins can allow malicious code execution, but it requires that the user be tricked into installing a specially crafted search plug-in.
- Input validation errors in InstallTrigger and other XPInstall-related JavaScript objects could allow malicious code execution.
- A problem with the "chrome" user-interface code in validating DOM nodes allowed several exploits that could lead to malicious code execution or data theft; the exploits could be activated by trivial user actions, such as clicking on a link.
http://www.mozilla.org/news.html