just to add a little to this...

source Advisory

Workaround:

Use the latest version of Mozilla 1.1 Beta or disable JavaScript.

Vendor status:

The Mozilla security bug group was notified on 22 June 2002.
They have fixed the problem, and the fix will be included in Mozilla 1.0.1.
(The fix has already been included in the latest version of Mozilla 1.1 Beta.)
and the link:

Mozilla 1.1 Beta