A vulnerability has been discovered in Mozilla that allows remote
attackers to inject arbitrary Javascript from one page into the
frameset of another site.
CAN-2005-2260
The browser user interface does not properly distinguish between
user-generated events and untrusted synthetic events, which makes
it easier for remote attackers to perform dangerous actions that
normally could only be performed manually by the user.
CAN-2005-2261
XML scripts ran even when Javascript disabled.
CAN-2005-2263
It is possible for a remote attacker to execute a callback
function in the context of another domain (i.e. frame).
CAN-2005-2265
Missing input sanitising of InstallVersion.compareTo() can cause
the application to crash.
CAN-2005-2266
Remote attackers could steal sensitive information such as cookies
and passwords from web sites by accessing data in alien frames.
CAN-2005-2268
It is possible for a Javascript dialog box to spo...