rendering/RenderBox.cpp in WebCore in WebKit before r86862, as used in Google Chrome before 11.0.696.71, does not properly render floats, which allows remote attackers to cause a denial of service or possibly have unspecified other impact via unknown vectors that lead to a "stale pointer."
https://oval.cisecurity.org/repository/search/definition/oval%3Aorg.mitre.oval%3Adef%3A13992
http://www.securityfocus.com/bid/47965
http://trac.webkit.org/changeset/86862
http://googlechromereleases.blogspot.com/2011/05/stable-channel-update_24.html