The XPConnect component in Mozilla Firefox before 2.0.0.17 allows remote attackers to "pollute XPCNativeWrappers" and execute arbitrary code with chrome privileges via vectors related to a SCRIPT element.
Weaknesses in this category are related to the management of permissions, privileges, and other security features that are used to perform access control.