Before was in centosplus repository
http://mirror.centos.org/centos/4.3/centosplus/i386/RPMS/
But now 1.5.0.2 is last release, I know that never versions have security updates, but don't know if Linux versions of firefox was affected or not.
The upstream vendor pushed firefox 1.5.x into the base distro, so it's no longer a centosplus package. If you excluded firefox from the base or updates repository, you need to undo that.