Just an example - one of many bugs that become "public" within days of release. Now the hackers know:

>>> http://isc.sans.org/diary.html?storyid=2310
Last Updated: 2007-02-26 18:39:31 UTC …(Version: 2)
"…MSIE 7: http://nvd.nist.gov/nvd.cfm?cvename=CVE-2007-1091
'Microsoft Internet Explorer 7 allows remote attackers to prevent users from leaving a site, spoof the address bar, and conduct phishing and other attacks via onUnload Javascript handlers…'
Firefox: http://www.kb.cert.org/vuls/id/393921
Last Updated: 02/26/2007 ~ '…Mozilla Firefox fails to properly handle JavaScript onUnload events. Specifically, Firefox may not correctly handle freed data structures modified in the onUnload event handler possibly leading to memory corruption. By convincing a user to view a specially crafted HTML document (e.g., a web page or an HTML email message or attachment), an attacker may be able to execute arbitrary code with the privileges of the user… Firefox has addressed this issue in Firefox version 2.0.0.2* as well as Firefox 1.5.0.10*…'"
* http://www.mozilla.org/security/announce/2…fsa2007-08.html

- http://secunia.com/advisories/24205/
Release Date: 2007-02-24
Last Update: 2007-02-26
Critical: Highly critical
Impact: Security Bypass, Cross Site Scripting, Spoofing, Exposure of sensitive information, System access
Where: From remote
Solution Status: Vendor Patch
Software: Mozilla Firefox 1.x, Mozilla Firefox 2.0.x …
Solution: Update to version 2.0.0.2 or 1.5.0.10…"
- http://secunia.com/advisories/23014/
Release Date: 2007-02-23
Impact: Spoofing
Where: From remote
Solution Status: Unpatched
Software: Microsoft Internet Explorer 7.x… Other versions may also be affected…"
.