Today, Mozilla made public bug #360493, which exposes Firefox’s Password Manager on many public sites. The flaw derives from Firefox’s willingness to supply the username and password stored on one page on a domain to another page on a domain. For example, username/password input tags on a Myspace user’s site will be unhelpfully propagated with the visitor’s Myspace.com credentials.
This is a rather serious bug that will hopefully get fixed quick. It’s not the fact that someone on your PC can get your password, but rather the fact that some pages can be coded in a way to steal the information without you being aware of it.