WebCore, as used in Apple Safari before 3.1, does not properly mask the password field when reverse conversion is used with the Kotoeri input method, which allows physically proximate attackers to read the password.
https://exchange.xforce.ibmcloud.com/vulnerabilities/41329
http://www.vupen.com/english/advisories/2008/0920/references
http://www.us-cert.gov/cas/techalerts/TA08-079A.html
http://www.securitytracker.com/id?1019656
http://www.securityfocus.com/bid/28326
http://www.securityfocus.com/bid/28290
http://secunia.com/advisories/29393
http://lists.apple.com/archives/security-announce/2008/Mar/msg00000.html