They are stored in a text file located at C:\Documents and Settings\your name\Application Data\Mozilla\Firefox\Profiles\default.xxx\signons.txt. When viewing the file, the website is given but the signon is a long string of seemingly random characters. The location would be different on every computer and the information is encrypted. I suppose someone could access it, but the effort involved wouldn't be worth it.
As a side note, Firefox by default doesn't encrypt secure pages.
Big Dawg #1254: G21 and G30
"If someone has a gun and is trying to kill you, it would be reasonable to shoot back with your own gun." — The Dalai Lama, (May 15, 2001, The Seattle Times) speaking in Portland, Oregon, when asked by a girl how to react when a shooter takes aim at a classmate