WebKit in Apple Safari before 4.0 does not prevent remote loading of local Java applets, which allows remote attackers to execute arbitrary code, gain privileges, or obtain sensitive information via an APPLET or OBJECT element.
lists.apple.com/archives/security-announce/2009/jun/msg00002.html
lists.opensuse.org/opensuse-security-announce/2011-01/msg00006.html
osvdb.org/55022
secunia.com/advisories/35379
secunia.com/advisories/36790
secunia.com/advisories/37746
secunia.com/advisories/43068
securitytracker.com/id?1022345
support.apple.com/kb/HT3613
www.debian.org/security/2009/dsa-1950
www.securityfocus.com/bid/35260
www.securityfocus.com/bid/35350
www.ubuntu.com/usn/USN-836-1
www.ubuntu.com/usn/USN-857-1
www.vupen.com/english/advisories/2009/1522
www.vupen.com/english/advisories/2011/0212
exchange.xforce.ibmcloud.com/vulnerabilities/51266