CVE-2008-2786 (http://nvd.nist.gov/nvd.cfm?cvename=CVE-2008-2786): Buffer overflow in Firefox 3.0 and 2.0.x has unknown impact and attack vectors. NOTE: due to lack of details as of 20080619, it is not clear whether this is the same issue as CVE-2008-2785. A CVE identifier has been assigned for tracking purposes.
It seems there is no public information available, I just opened this issue for tracking purposes.
That exploit published today could be related http://www.milw0rm.com/exploits/7554
It might still be 0day as the source for this was a "uh look I have an exploit for firefox 3 and this is the hash"-post on http://lists.grok.org.uk/pipermail/full-disclosure/2008-June/062832.html
we should probably contact upstream to sort this out.
Mozilla has nothing to do here.
Upstream's bug report: https://bugzilla.mozilla.org/show_bug.cgi?id=402735 The crash was caused due to a 3rd party extension (Download accelerator plus) and so it is invalid.