Can provide full access to the compromised computer.
Sun has released new versions of Java Runtime Environment (JRE) and Java Developer Kit (JDK) that removes a number of vulnerabilities and other weaknesses.
The most serious of the vulnerabilities allows for remote execution of arbitrary code on the vulnerable system, which can give attackers access to a computer with the same privileges as the logged-in user has.
Many of the vulnerabilities, this time related to the processing of audio and video files.
In most cases it is JRE 6 Update 17 which now should be downloaded and installed, but vulnerabilities have also been removed in earlier editions. All are available from this page.
End Of Post