Mozilla Firefox is vulnerable to validaiton bypass. does not properly handle overlong UTF-8 encoding, which makes it easier for remote attackers to bypass cross-site scripting (XSS) protection mechanisms via a crafted string, a different vulnerability than CVE-2010-1210.
hg.mozilla.org/releases/mozilla-1.9.2/rev/e42c563313a0
mozilla.com/en-US/firefox/3.6.4/releasenotes/
mozilla.com/en-US/firefox/3.6/releasenotes/
mozilla.org/security/known-vulnerabilities/firefox35.html
sirdarckcat.blogspot.com/2009/10/couple-of-unicode-issues-on-php-and.html
www.mozilla.org/security/known-vulnerabilities/firefox36.html#firefox3.6.4
www.redhat.com/security/updates/classification/#critical
access.redhat.com/errata/RHSA-2010:0500
bugzilla.mozilla.org/show_bug.cgi?id=511859
bugzilla.mozilla.org/show_bug.cgi?id=522634
bugzilla.redhat.com/show_bug.cgi?id=656287