didier beck weblog

Tuesday, May 17, 2005

TOOLS: Firefox v1.0.4 

Firefox v1.0.4

Do not forget (as I ;-) to update your version of Firefox. The release 1.0.4 corrects three critical security vulnerabilities:
  • Privilege escalation via non-DOM property overrides

  • "Wrapped" javascript: urls bypass security checks

  • Code execution via javascript: IconURL.