Mozilla Firefox 2.x before 2.0.0.19 allows remote attackers to run arbitrary JavaScript with chrome privileges via vectors related to the feed preview, a different vulnerability than CVE-2008-3836.
Weaknesses in this category are related to the management of permissions, privileges, and other security features that are used to perform access control.