http://searchsecurity.techtarget.com/originalContent/0,289142,sid14_gci995585,00.html-Snip-
A "moderately critical" vulnerability in Mozilla and Mozilla Firefox could allow malicious sites to abuse SSL certificates of other sites, according to Secunia. The Copenhagen, Denmark-based IT security firm said in its advisory that "It is possible to make the browser load a valid certificate from a trusted Web site by using a specially crafted 'onunload' event. The problem is that Mozilla loads the certificate from a trusted Web site and shows the 'secure padlock' while actually displaying the content of the malicious Web site." The vulnerability has been confirmed using Mozilla Firefox 0.9.2 and Mozilla 1.7.1 on Windows and Mozilla Firefox 0.9.1 on Linux. Other versions may also be affected. Secunia recommends users steer clear of untrusted Web sites and "verify the correct URL in the address bar with the one in the SSL certificate."
--------------------------------------------------------------------
Moderately critical
http://secunia.com/advisories/12160This has been confirmed using Mozilla Firefox 0.9.2 and Mozilla 1.7.1 on Windows and Mozilla Firefox 0.9.1 on Linux. Other versions may also be affected.