
With or without extensions? 
 
Yes there are remote vulnerabilities caused by extensions and I am really laughing my ass off since I talked about this with people 2 years ago. Specifically I talked about these extensions as a broken security concept because a) everyone can upload them to mozdev even with malicious code with a fancy name (ok we have certificates now but that doesn't save you from bad code in extensions. Ok you can also have bugs in FF itself but I hope the code gets checked better than random extensions) and b) bugs introduced by extensions.
Q: Why is this attack possible?
A: The problem stems from design flaws, false assumptions, and a lack of solid developer documentation instructing extension authors on the best way to secure their code.
I am sorry if this sounds arrogant but in my opinion it was obvious that this will happen some time. And possible security flaws introduced by extensions really were just one reason for me in the past to not use Firefox.
Read more on: 
http://paranoia.dubfire.net/2007/05/remote-vulnerability-in-firefox.html.