http://www.feedparser.org/docs/html-sanitization.html
I'm not convinced it's possible to stop a browser executing code, because there are so many possible ways a browser can be given code to execute. Not only do you have to read all the specs for all the versions of the browsers, you've got to find all the bugs in them too.
Case in point: An earlier version of this code didn't remove javascript from CSS expressions, making it possible to get past it in IE6 and 7.
I gave up trying to sanitize HTML, and instead used a library to render it to plain text and stuck it in a <pre> element with usual HTML escaping. But I need to take a very paranoid approach in my app.
EDIT to add: I think this is probably one of the better java implementation, and has a good whitelisting approach to HTML. However, it's let down by taking a blacklist approach to CSS.