Secunia has reported a window injection vulnerability. Details in URL.
Confirmed on Firefox 1.0
Upstream bug @ https://bugzilla.mozilla.org/show_bug.cgi?id=273699
The fix has landed (with collateral damage), and could appear in Moz 1.7.6 / 1.8a6 and FF 1.0.1.
Replaced by metabug 83267 *** This bug has been marked as a duplicate of 83267 ***