Apple Safari 1.0 through 1.2.3 allows remote attackers to spoof the URL displayed in the status bar via TABLE tags.
https://exchange.xforce.ibmcloud.com/vulnerabilities/17909
http://www.kb.cert.org/vuls/id/925430
http://secunia.com/advisories/13047/
http://lists.apple.com/archives/security-announce/2004/Dec/msg00000.html