Apple plugs dangerous Safari security holes
Apple has released Safari 4.0.2 to fix a pair of security flaws that could lead to cross-site scripting or remote code execution attacks.
The vulnerabilities affect Safari for Windows (XP and Vista) and Mac OS X.
Here are the raw details:
CVE-2009-1724: An issue in WebKit’s handling of the parent and top objects may result in a cross-site [...]