Red Hat Bugzilla – Bug 436299
CVE-2008-1195 Java-API calls in untrusted Javascript allow network privilege escalation
Last modified: 2011-09-29 21:13:22 EDT
A vulnerability in the Java Runtime Environment may allow JavaScript code that is downloaded by a browser to make connections to network services on the system that the browser runs on, through Java APIs. This may allow files (that are accessible through these network services) or vulnerabilities (that exist on these network services) which are not otherwise normally accessible to be accessed or exploited.