Mozilla Firefox is vulnerable to Spoofable Address Bar. A flaw was found in the way Firefox displays the address bar when window.open() is called in a certain way. An attacker could use this flaw to conceal a malicious URL, possibly tricking a user into believing they are viewing a trusted site.
blog.mozilla.com/security/2009/07/28/url-bar-spoofing-vulnerability/
es.geocities.com/jplopezy/firefoxspoofing.html
osvdb.org/56717
secunia.com/advisories/36001
secunia.com/advisories/36126
secunia.com/advisories/36141
secunia.com/advisories/36435
secunia.com/advisories/36669
secunia.com/advisories/36670
sunsolve.sun.com/search/document.do?assetkey=1-66-266148-1
www.debian.org/security/2009/dsa-1873
www.mozilla.org/security/announce/2009/mfsa2009-44.html
www.mozilla.org/security/known-vulnerabilities/firefox30.html#firefox3.0.14
www.redhat.com/security/updates/classification/#critical
www.redhat.com/support/errata/RHSA-2009-1430.html
www.redhat.com/support/errata/RHSA-2009-1431.html
www.redhat.com/support/errata/RHSA-2009-1432.html
www.securityfocus.com/archive/1/505242/30/0/threaded
www.securityfocus.com/archive/1/505265
www.securityfocus.com/bid/35803
www.securitytracker.com/id?1022603
www.vupen.com/english/advisories/2009/2006
www.vupen.com/english/advisories/2009/2142
access.redhat.com/errata/RHSA-2009:1430
bugzilla.mozilla.org/show_bug.cgi?id=451898
oval.cisecurity.org/repository/search/definition/oval%3Aorg.mitre.oval%3Adef%3A9686
usn.ubuntu.com/811-1/
www.redhat.com/archives/fedora-package-announce/2009-August/msg00198.html
www.redhat.com/archives/fedora-package-announce/2009-August/msg00261.html