Just in case you haven’t heard about this yet, there is a design error in Mozilla 1.7.3 and Firefox 1.0 that may allow an attacker to cause heap corruption, resulting in execution of arbitrary code.