CFNetwork in Apple Safari before 5.0.6 on Windows does not properly handle an untrusted attribute of a system root certificate, which allows remote web servers to bypass intended SSL restrictions via a certificate signed by a blacklisted certification authority.
Vulnerability in Apple Safari, which allows remote attackers to bypass the Same Origin Policy, and modify the rendering of text from arbitrary web sites