CVE-2008-4216
The plug-in interface in WebKit in Apple Safari before 3.2 does not prevent plug-ins from accessing local URLs, which allows remote attackers to obtain sensitive information via vectors that "launch local files."
Date published : 2008-11-17
http://lists.apple.com/archives/security-announce//2008/Nov/msg00001.html
