Double free vulnerability in the getRawDER function for nsIX509Cert in Firefox allows remote attackers to cause a denial of service (hang) and possibly execute arbitrary code via certain Javascript code.
https://oval.cisecurity.org/repository/search/definition/oval%3Aorg.mitre.oval%3Adef%3A11065
http://www.us.debian.org/security/2006/dsa-1191
http://www.ubuntu.com/usn/usn-361-1
http://www.redhat.com/support/errata/RHSA-2006-0611.html
http://www.redhat.com/support/errata/RHSA-2006-0610.html
http://www.redhat.com/support/errata/RHSA-2006-0594.html
http://www.redhat.com/support/errata/RHSA-2006-0578.html
http://www.mandriva.com/security/advisories?name=MDKSA-2006:145
http://www.mandriva.com/security/advisories?name=MDKSA-2006:143
http://www.debian.org/security/2006/dsa-1210
http://www.debian.org/security/2006/dsa-1192
http://secunia.com/advisories/22849
http://secunia.com/advisories/22342
http://secunia.com/advisories/22299
http://secunia.com/advisories/22247
http://secunia.com/advisories/21631
http://secunia.com/advisories/21532
http://secunia.com/advisories/21336
http://secunia.com/advisories/21270