The Drupal filter_xss_admin function in 5.x before 5.8 and 6.x before 6.3 does not "prevent use of the object HTML tag in administrator input," which has unknown impact and attack vectors, probably related to an insufficient cross-site scripting (XSS) protection mechanism.
https://www.redhat.com/archives/fedora-package-announce/2008-July/msg00551.html
https://www.redhat.com/archives/fedora-package-announce/2008-July/msg00527.html
https://www.redhat.com/archives/fedora-package-announce/2008-August/msg00016.html
https://exchange.xforce.ibmcloud.com/vulnerabilities/43701
https://bugzilla.redhat.com/show_bug.cgi?id=454849
http://www.securityfocus.com/bid/30168
http://www.openwall.com/lists/oss-security/2008/07/10/3