The Javascript engine in Safari 1.2 and earlier allows remote attackers to cause a denial of service (segmentation fault) by creating a new Array object with a large size value, then writing into that array.
https://exchange.xforce.ibmcloud.com/vulnerabilities/15413
https://euvd.enisa.europa.eu/vulnerability/EUVD-2004-0361
http://www.securityfocus.com/bid/9815