Unspecified vulnerability in the Java Runtime Environment (JRE) component in Oracle Java SE 7 through Update 11, 6 through Update 38, 5.0 through Update 38, and 1.4.240 and earlier, and OpenJDK 6 and 7, allows remote attackers to affect confidentiality, integrity, and availability via vectors related to CORBA, a different vulnerability than CVE-2013-0441 and CVE-2013-1475. NOTE: the previous information is from the February 2013 CPU. Oracle has not commented on claims from another vendor that this issue allows remote attackers to bypass Java sandbox restrictions via "certain value handler constructors."
Unspecified vulnerability in the Java Runtime Environment (JRE) component in Oracle Java SE 6 through Update 38, 5.0 through Update 38, and 1.4.240 and earlier allows remote attackers to affect confidentiality, integrity, and availability via unknown vectors related to Sound.
A flaw was found in the image parser of the Java AWT component. Insufficient validation of raster parameters could lead to Java Virtual Machine memory corruption, possibly allowing untrusted Java application or applet to execute arbitrary code with the virtual machine privileges.
External Reference:
http://www.oracle.com/technetwork/topics/security/javacpufeb2013-1841061.html
A flaw was found in the image parser of the Java 2D component. Insufficient validation of raster parameters could lead to Java Virtual Machine memory corruption, possibly allowing untrusted Java application or applet to execute arbitrary code with the virtual machine privileges.
External Reference:
http://www.oracle.com/technetwork/topics/security/javacpufeb2013-1841061.html
Unspecified vulnerability in the Java Runtime Environment (JRE) component in Oracle Java SE 7 Update 7 and earlier, 6 Update 35 and earlier, 5.0 Update 36 and earlier, and 1.4.238 and earlier; and JavaFX 2.2 and earlier; allows remote attackers to affect confidentiality, integrity, and availability via unknown vectors related to 2D.
Security Explorations security and vulnerability research company reported: [1] http://seclists.org/bugtraq/2012/Sep/109
presence of a new security flaw, affecting recent Oracle Java SE 5 Update 22, Oracle Java SE 6 Update 35, and Oracle Java SE 7 Update 7 versions of Oracle Java SE software. This flaw is reported to allow complete Java security sandbox bypass.
References: [2] http://www.security-explorations.com/en/SE-2012-01.html