JavaScriptCore in WebKit allows malicious users to cause a denial of service (out-of-bounds heap read) via a crafted Javascript file.
webkit webkit -