CVE-2009-1710 (http://nvd.nist.gov/nvd.cfm?cvename=CVE-2009-1710): WebKit in Apple Safari before 4.0 allows remote attackers to spoof the browser's display of (1) the host name, (2) security indicators, and unspecified other UI elements via a custom cursor in conjunction with a modified CSS3 hotspot property.
Presumably all affected versions are gone from tree. Closing as discussed with keytoaster.