Both Apple and Mozilla issued updates late Wednesday to plug security holes in their Web browser software. The Mozilla update fixes a single critical vulnerability with the way Firefox handles “Javascript garbage collection.” Mozilla says this update was issued “primarily to address stability concerns. We have no demonstration that this particular crash is exploitable but are issuing this advisory because some crashes of this type have been shown to be exploitable in the past.” Mozilla does note, however, that its Thunderbird e-mail client shares the browser engine with Firefox and could be vulnerable if JavaScript were to be enabled in mail. “This is not the default setting and we strongly discourage users from running JavaScript in mail,” Mozilla warned. Apple’s patches fix at least four separate flaws in Safari. All four are present in the Windows version of Safari, while the version designed for Macs contain just two of the