Hacker Newsnew | past | comments | ask | show | jobs | submitlogin

I can think of a few:

* Bug in the default XML parsing library that exposes local files, existence of local files, or even allows a user-supplied XML to open a socket to a remote server? * Vulnerability in SecurityManager that allows a sandboxed jar more privileges than it is supposed to have? * Allowing a default RMI-JMX configuration to provide an attack vector to authenticated clients whereby they can upload arbitrary code that executes outside of a SecurityManager?



Guidelines | FAQ | Lists | API | Security | Legal | Apply to YC | Contact

Search: