Security Advisory
CVE-2008-3638
CVE vulnerability detail - eXtreme Datacenter Security Operations
Description
Java on Apple Mac OS X 10.5.4 and 10.5.5 does not prevent applets from accessing file:// URLs, which allows remote attackers to execute arbitrary programs.