A flaw was found in the way the Hotspot component of OpenJDK generated class code. An untrusted Java application or applet could potentially use this flaw to bypass Java sandbox restrictions.
It was discovered that the computeNextExponential() method in the Libraries component of OpenJDK failed to comply with the documentation, returning sometimes negative numbers.