CVE-2009-1711
WebKit in Apple Safari before 4.0 does not properly initialize memory for Attr DOM objects, which allows remote attackers to execute arbitrary code or cause a denial of service (application crash) via a crafted HTML document.
Date published : 2009-06-10
http://lists.apple.com/archives/security-announce/2009/jun/msg00002.html