KDE Konqueror 3.5.1 and earlier allows remote attackers to cause a denial of service (application crash) by calling the replaceChild method on a DOM object, which triggers a null dereference, as demonstrated by calling document.replaceChild with a 0 (zero) argument.
https://exchange.xforce.ibmcloud.com/vulnerabilities/27744
http://www.vupen.com/english/advisories/2006/2812
http://www.ubuntu.com/usn/usn-322-1
http://www.mandriva.com/security/advisories?name=MDKSA-2006:130