It was discovered that the JAXP (Java API for XML Processing) component of OpenJDK failed to properly handle Unicode surrogate pairs used as part of the XML attribute values. A specially-crafted XML input could cause a Java application to use an excessive amount of memory when parsed.
It was discovered that the Security component of OpenJDK failed to properly check DSA (Digital Signature Algorithm) parameters. The use of keys with incorrect parameters could lead to disclosure of sensitive data.