One of the critical advisories covers a vulnerability in the "javascript: URL" function that could allow attackers to bypass the JavaScript sandbox and execute malicious scripts with elevated privileges.
The link for this article located at Network World is no longer available.