The status bar as well as the address bar of the new site show
http://www.payp?l.com, so K-Meleon seems not to be vulnerable,
because the user can see the obvious error.
The "firescrolling" bug seems not to work with this mentioned
chrome because such as chrome does not exist in K.Meleon,
which has a different browser structure and is not cross platform
compatible (Windows only).
Also the tab bug is not working, K-Meleon has layers, not tabs.
For the bug, when you drag and drop a picture to the desktop, or
any other file, it is common sense to see it's danger, as a .gif or
any other ending does not make sure, what type of file it is.
You simply should never do that.
So up to now everything is still rather safe.