A Mozilla Foundation Security Advisory reports:
Additional checks were added to make sure Javascript eval
and Script objects are run with the privileges of the
context that created them, not the potentially elevated
privilege of the context calling them in order to protect
against an additional variant of MFSA
The Mozilla Foundation Security Advisory MFSA 2005-41
moz_bug_r_a4 reported several exploits giving an attacker
the ability to install malicious code or steal data,
requiring only that the user do commonplace actions like
click on a link or open the context menu.