Firefox 2.0.0.5 was just released last week and already there is a vulnerability that you should be well aware of. It seems that the bug resides within the password management feature, eg: allowing Firefox to remember your login and password. If a website hosts certain JavaScript code, it will be able to steal all of your password information. heise Security has a proof-of-concept demo, which shows just how well the vulnerability works. If you visit trusted sites, you should be in the clear, but it’s wise to be careful when visiting sites that have the ability to execute JavaScript. No word on when a fix will be available.
Discussions between heise Security and Mozilla developers describe a debate among Mozilla developers over removing this feature, since “evil” server pages can steal passwords from browsers whether the user has opted for password management by Firefox or not. Apple’s Safari is vulnerable in the same way. Current workarounds include disabling JavaScript in Firefox or avoiding the use of Firefox password management on sites where users are allowed to post JavaScript pages.
Source: Linux.com