This is from the BBC web site.

The Mozilla Foundation has said it is "working aggressively" to fix two flaws in its open source Firefox browser.


The vulnerabilities, reported on Saturday, were identified as "very critical", but no cases had been reported of them being exploited.

Several security firms identified the flaws which could let websites run malicious code on a person's computer.

Mozilla has responded by changing its update service and says people should temporarily turn off JavaScript code.

Manual downloads

The first flaw reported fools the browser into thinking software is being installed by a legitimate, or safe, website.

The second flaw happens when the software installation trigger does not properly check icon web addresses which contain JavaScript code.

A hacker could potentially take advantage of the security flaws to secretly launch malicious code or programs.

Mozilla advised people to download add-ons to its software manually from the Foundation's site.

Danish security firm Secunia said called the flaws "extremely critical" because cookie and history information could be used to get access to personal information or gain access to sites previously visited.

The Mozilla Foundation, which developed the browser, said it was working hard to provide a comprehensive and more permanent fix for the problems.

Let's be careful out there......

WTF