Multiple Vulnerabilities were identified in Firefox, please update to - Firefox 3.5.2:
The first issue is caused by an error when handling a SOCKS5 proxy reply containing an overly long DNS name, which could be exploited to corrupt subsequent data stream in the response.
The second vulnerability has been identified in Mozilla Firefox, which could be exploited to conduct spoofing and phishing attacks. This issue is caused by an error when processing the URL while opening a new tab window, which could allow attackers to spoof the URL displayed in the address bar by tricking a user into following a link containing a specially crafted "window.open()" call.
The third issue is caused by memory corruption errors in the JavaScript and browser engines when parsing malformed data, which could be exploited by attackers to crash a vulnerable application or execute arbitrary code.
The fourth vulnerability is related to a broken functionality due to the window's global object receiving an incorrect security wrapper on pages that had a "Link:" HTTP header when an add-on implementing a Content Policy in JavaScript was installed, which could allow arbitrary JavaScript execution with chrome privileges.
http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2009-2470
http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2009-2654