CoreText in Apple Mac OS X 10.4 through 10.4.10 allows attackers to cause a denial of service (application crash) and possibly execute arbitrary code via crafted text content that triggers an access of an uninitialized object pointer.
https://exchange.xforce.ibmcloud.com/vulnerabilities/38465
http://www.kb.cert.org/vuls/id/498105
http://lists.apple.com/archives/security-announce/2007/Nov/msg00002.html