Mozilla Firefox 3 before 3.0.1 on Mac OS X allows remote attackers to cause a denial of service (application crash) or possibly execute arbitrary code via a crafted GIF file that triggers a free of an uninitialized pointer.
https://exchange.xforce.ibmcloud.com/vulnerabilities/43850
http://www.ubuntu.com/usn/usn-626-1
http://www.mozilla.org/security/announce/2008/mfsa2008-36.html