JComboBox makes for nice security vulnerability under X11?

I noticed a couple years ago that when I set a breakpoint inside a JComboBox state change event handler on a Java application or applet running under X11, the entire desktop would hang. Back then, I checked the Swing bug database and found an issue regarding this, but it was closed with an evaluation that pretty much simply said that the developer didn't know how to fix it.
When I brought this up in the netbeans mailing list, someone suggested that this could be a security issue if someone intentionally/programmatically stopped all processing from within this event handler (perhaps from an applet). Perhaps, as a security vulnerability this bug would get more attention!
Well, it's been over a year and the latest JDK 1.6b10 (build 25) still has this problem. So, obviously it's not bothering anyone, except me, enough to do anything about it. I could try to file this bug under Swing again (probably with same outcome) or try filing it as a security bug. What are people's thoughts?

Hi
Try going here:
http://europe.nokia.com/A4423034
Or alternatively : find the product pages for the 5700 by going to www.nokia.com/phones, then pick out 5700, then dip into "PC software" and "Music"
Cheers

Similar Messages

  • Firefox is not remembering passwords for sites that i visit regularly. Ihave checked the box "remember passwords for sites" in the security tab under tools, but the passwords are not being remembered when I return to the sites.

    Firefox is not remembering passwords for sites that i visit regularly. Ihave checked the box "remember passwords for sites" in the security tab under tools, but the passwords are not being remembered when I return to the sites. I am running v 3.6.18

    Websites remembering you and automatically log you in is stored in a cookie.
    * Create an allow cookie exception (Tools > Options > Privacy > Cookies: Exceptions) to keep such a cookie, especially for secure websites and if cookies expire when Firefox is closed.
    Make sure that you do not run Firefox in Private Browsing mode.
    * https://support.mozilla.com/kb/Private+Browsing
    * In [[Private Browsing]] mode all cookies are session cookies that expire if that session is ended, so websites won't remember you.
    * Do not use [[Clear Recent History]] to clear the "Cookies" and the "Site Preferences"
    Clearing "Site Preferences" clears all exceptions for cookies, images, pop-up windows, software installation, and passwords.
    * http://kb.mozillazine.org/Cookies

  • HT5312 im trying to make a purchase on itunes and its asking for my security question and i dont remember them its been years since i made this account how can i reset them

    im trying to make a purchase on itunes and its asking for my security question and i dont remember them its been years since i made this account how can i reset them

    You need to ask Apple to reset your security questions; ways of contacting them include clicking here and picking a method for your country, phoning AppleCare and asking for the Account Security team, and filling out and submitting this form.
    (98991)

  • Having lost my password, et al., I obtained a new one successfully, but now when I tried to make a purchase, I was asked for my Security Code. How do I obtain a new one since I have lost all my iPad documentation?

    Having lost my password, et al., I obtained a new one successfully, but now when I tried to make a purchase, I was asked for my Security Code.  How do I obtain a new Security Code since I have lost all my iPad documentation?   Thank you,    Dzurek123

    That refers to the 3 digit security code on the back of your credt card, not a security code for the iPad.

  • I'm trying to make a payment on my iPhone to AppStore but it keeps asking me for my security code from my card and now it just tells me to come here for support

    I'm trying to make a payment on my iPhone to AppStore but it keeps asking me for my security code from my card and now it just tells me to come here for support

    The "backup password" refers to a password you created when you elected to encrypt your iPhone's backup.  If you cannot remember the encryption password, you will not be able to access the backup.

  • One important feature of Desktop options - "Security devices" under Advance tab had been removed in Firefox for Mobile, anyone knows why?

    One important feature of Desktop options - "Security devices" under Advance tab had been removed in Firefox for Mobile, anyone knows why?

    - ability to choose deletion of an email on handset only
    - desktop software working with all older BB's allowing drag and drop type of transferring data, contacts etc. (BB link doesn't recognize my old Storm) 
    - auto power on/off
    - contacts syncing with yahoo & Outlook (almost two weeks trying to work around it and no luck)

  • I have Nortons security suite under the old version the Idenity protection worked I kept all my passwords under this which used a master pasword I did not save passwords any were else and now can not get it to work supplying passwords for my l0gon site.

    I have Norton's security suite under the old version the Idenity protection worked. I kept all my passwords under this which used a master pasword I did not save my passwords any were else and now can not get it to work supplying passwords for my logon site.

    Symantec need to correct a mistake they made with their add-ons. They originally updated their add-ons after quite a delay to work with Firefox 4.0 as shown here - http://community.norton.com/t5/Norton-Internet-Security-Norton/Firefox-4-compatibility-hotfix-is-now-available/td-p/428894
    They made an error with the update in only listing it as compatible with Firefox 4.0, so they will not install on Firefox 4.0.1 and subsequent Firefox security updates. Symantec have indicated they will be releasing an update to correct their error soon, for details see http://community.norton.com/t5/Norton-Internet-Security-Norton/Norton-Toolbar-not-compatible-with-FF-4-0-1/td-p/442788/page/12

  • Hi, My OS X is Leopard v10.5.8, w/Safari v5.0.6. I am considering downloading ClickToFlash 2.9.2 for general security reasons. I'm assuming this a good fit, being that Apple endorses this extension on their site. Does this mean i can download it w/out hav

    Hi, My OS X is Leopard v10.5.8, w/Safari v5.0.6. I am considering downloading ClickToFlash 2.9.2 for general security reasons. I’m assuming this a good fit, being that Apple endorses this extension on their site. Does this mean i can download it w/out having to worry about any conflicts?,.. that its coming from a safe source, etc? Does it have any downsides? Is it easy to install?, ..or uninstall if i dont like it?
       ALSO~ I’m assuming i dont need ClickToPlugin, because when on internet i always have “Enable Plugins” ~ DISABLED.
        Thanks for any advice,...  Jean in NJ

    I dont really understand~  When i open my Flash Player pane, click on Advanced tab, the heading "Updates" reads~ "Not updating may leave this computer vulnerable to security threats." The reason for my concern is that Adobe no longer offers FP updates for my OS [10.5.8],not even archived. So my original question probably should have read~ When visiting a web site does Flash automatically load onto safari.  If so, can using Click to Flash;... and NOT clicking to flash, prevent Flash from loading, and possibly carrying  a "security threat" [virus?], into Safari or my Mac?  Not trying to beat a dead horse,..just trying to understand what makes him run,   Thanks

  • Could not see Security Node under Global Explorer.

    Hi All,
    Could not see Security Node under Global Explorer, can some one guide is there any I can make changes to the setup to see the Security node.
    Thanks in Advance.
    --Satish                                                                                                                                                                                                                                                                                                                                                                                   

    Hi
    Is OWBUSER the repository owner? If not then log on as the repository owner. Otherwise it may be you have killed the panel and it has disappeared, see post here for resetting layout.
    You can have as many target users that you deploy into as you want.
    Cheers
    David

  • HT202802 What "security vulnerability" will be opened by using this signing technique?

    Regarding article: HT202802
    OS X: Using AppleScript with Accessibility and Security features in Mavericks - Apple Support
    The article says:
    Important: Signing an applet using the following method introduces a security vulnerability that could allow malicious software to use Accessibility without user permission.
    1. What "security vulnerability" will be opened by using this signing technique?
    2. Does signing this way only make the App its applied to vulnerable only? and then the whole computer vulnerable depending on how extensive the app's reach is to the rest of the computer?
    3. More information: My app only relates to the Reminders app and bunch of Finder items....nothing internet based, etc.  That being said, is this still a vulnerability to my computer?
    "Note: If you have your own signing identity, you may use that identity in place of “-” for the -s option." 
    1. What is "my own signing identity?" and if I don't have one, would it add security to get one and use it here?
    Thanks for the help in advance!

    1) There are a few system features, including accessibility, that will override any and all other security protections on you machine. This is the vulnerability. In giving the script the ability to control your machine, you give control of your machine to the script.
    2) By signing the script, that control is permanent. If the app doesn't do anything malicious, there is no problem. But malicious apps sometimes don't manifest until later.
    3) Did you write the app? If so, then there is nothing to worry about. If not, then how much do you trust the author of the app?
    Generally, this isn't too big a deal. Apple is very protective, but most people generally hand over their passwords to anyone. They shouldn't, of course, but generally they do. They don't realize the extent to which they have handed over control of their machine and all of their data. Apple is trying to point that out.

  • Upgrade to GnuTLS 3.2.12 to Avoid Security Vulnerability

    Per ArsTechnica, RedHat discovered a security vulnerability in GnuTLS and published an alert on March 3. Thanks to andyrtr, the safe version (3.2.12-1) was pushed into extra on March 3 (i.e., same day).
    You might consider updating GnuTLS.
    Further details
    http://arstechnica.com/security/2014/03 … sdropping/
    Last edited by snakeroot (2014-03-04 23:53:21)

    nourathar wrote:
    nomorewindows wrote:pacman -Qi gnutls would give this for installed applications that use it.
    Hi nomorewindows,
    $ pacman -Qi gnutls
    Name : gnutls
    Version : 3.2.12-1
    Description : A library which provides a secure layer over a reliable transport layer
    Architecture : x86_64
    URL : http://www.gnutls.org/
    Licenses : GPL3 LGPL2.1
    Groups : None
    Provides : None
    Depends On : gcc-libs libtasn1 readline zlib nettle p11-kit
    Optional Deps : None
    Required By : ffmpeg filezilla glib-networking gnome-vfs gst-plugins-bad libimobiledevice smbclient
    Optional For : None
    Conflicts With : None
    Replaces : None
    Installed Size : 4703.00 KiB
    Packager : Andreas Radke <[email protected]>
    Build Date : Mon 03 Mar 2014 04:09:47 PM CET
    Install Date : Tue 04 Mar 2014 11:24:30 PM CET
    Install Reason : Installed as a dependency for another package
    Install Script : Yes
    Validated By : Signature
    the output is very different though and in my case  it lists only 7 packages.
    It makes me really wonder what 'whoneeds' actually does ?
    I suppose 'whoneeds' lists all the packages I have installed that require one of these 7 and so recursively on ?
    ciao,
    J.
    Notice it said 49 of his 495 packages.  And also notice that the same ones listed in your output are also in his output above.

  • Better activation solution for F-Secure Freedome

    From the forum posts, internet posts, and user reviews it seems that one thing is very apparent. There is a major need for a better activation solution for F-Secure Freedome. Currently, if your HDD crashes, or you need to re-install Windows, or you upgrade to Windows 10 (coming up in July), or even if an F-Secure Freedome update fails and you need to re-install it, you lose the code and/or license. Currently, it is not possibly to free it up per se'. Evaluation periods make a huge difference on whether or not I decide to purchase a product. A 90 day trial is very helpful so that I know I am making a good purchase, since it incorporates different network protocols especially. If you un-install Freedome, you lose the code. Period. This is counterproductive. You end up losing potential users. For those with a paid license, there is a problem that the license server shows that even though Freedome has been uninstalled or is no longer used, the license is not "freed up" by the server. The server or whatever mechanism currently in place lacks the functionality to recognize these changes. I am actually about to re-install my OS, possibly add hardware and get a new HDD. I am also in the market for a new PC. F-Secure SAFE was a bit of a disappointment for me (no offense), and used a good bit of resources. - I do respect the people, and the company who makes it though. They make significant efforts, especially with the marketing of Freedome. The solution should be productive, but not cumbersome or overzealous (like Microsoft or worse). It is a good way to: 1) Expose customers to your products2) Get them to purchase them3) Retain that customer It costs more to gain a new customer than to retain a current one. I am not complaining, nor do I feel entitled. I am just trying to make a suggestion on how to improve the product, and its workflow. I don't intend to rant or to create a flood of posts. This was meant to be constructive, and to see what I could do/could be done about solving my licensing issue.I am sure that others also have some questions as well. I am satisfied with the initial install experience of Freedome, and the GUI is nice, I will say that .

    Hello infosec,
    Thank you for your honest the feedback. We really appreciate it. I'll pass it on.
    We are aware that currently the subscription management is not optimal and our development team is working hard to bring a better solution to subscription reset and reinstalaltion scenario. Unfortunately for the time being you'll need to post on this community if you are  reinstallating too many times your subscription.

  • Asha 501 Security Vulnerability

    Where can i report a Security Vulnerability in nokia asha 501...??Its Vulnerability bypasses lock code to access call logs as well as make calls. even if its locked wih security code.

    I think that's a feature rather than a bug.
    To reproduce you just set up a lock code for when you lock the screen, then type any number on the unlock screen, press the SOS button, then the green phone button and you're sent to the recent calls log.
    One thing that a locked out user shouldn't be able to do is set or unset a contact as favourite imo. You can do this by tapping any entry on the call log, then tapping the name of the contact that appears at the top and then the star at the right. You shouldn't be able to see more info about the contact other than the number and the call info when the phone is locked up (that is, nothing should happen the first time you tap on the contact's name).

  • When I go to buy something it makes me answer security questions I don't remember and when I try to reset them it doesn't email me a link?

    I got a $25 itunes card and loaded it onto my account no problem, then I go to buy some music and it makes me answer security questions I don't remember so I requested for the link to reset them (I've done it numerous times many days in a row) and the link never sends. I've also done many things on the apple website and tried using the itunes store on my laptop and nothing is working. Help?

    You need to ask Apple to reset your security questions. To do this, click here and pick a method; if that page doesn't list one for your country or you're unable to call, fill out and submit this form.
    They wouldn't be security questions if they could be bypassed without Apple verifying your identity.
    (115562)

  • HT201363 whenever i want to download an app, they ask me for 3 security questions.  I answer them and then it says "session has timed out".  And then the whole process repeats itself.  How can I download a free app if this keeps coming up?

    Whenever I want to download a free app, it asks me for 3 security questions.  I answer them.  Then it says "session has timed out".  Then the whole process starts over.  How can I get around this?

    Hey everyone in Apple world!
    I figured out how to fix the flashing yellow screen problem that I've been having on my MBP!  Yessssss!!!
    I found this super handy website with the golden answer: http://support.apple.com/kb/HT1379
    I followed the instructions on this page and here's what I did:
    Resetting NVRAM / PRAM
    Shut down your Mac.
    Locate the following keys on the keyboard: Command (⌘), Option, P, and R. You will need to hold these keys down simultaneously in step 4.
    Turn on the computer.
    Press and hold the Command-Option-P-R keys before the gray screen appears.
    Hold the keys down until the computer restarts and you hear the startup sound for the second time.
    Release the keys.
    I went through the 6 steps above twice, just to make sure I got rid of whatever stuff was holding up my bootup process.  Since I did that, my MBP boots up just like normal.  No flashing yellow screen anymore!!   
    (Note that I arrived at this solution when I first saw this page: http://support.apple.com/kb/TS2570?viewlocale=en_US)
    Let me know if this works for you!
    Elaine

Maybe you are looking for

  • Remove HTML from Interactive report download

    I have interactive reports where the column link on a specific column has to be dynamic, that means, it cannot be hard coded in the column link attributes. The following is an example of one such report query: case when d.object_type_description ='Bu

  • Replacing the letters in a string

    I have an odd set of fields for properties for my client. Some have multiple letters which correspond to a code table. How can I loop through the string and replace the letters with words For example A = central air B = ceiling fan C = A/C Unit If th

  • Fusion Middleware vs other middleware tools benchmark ?

    Hi All, Do we have any benchmark data as compared to other middleware available in the market like webmethods ? Thanks, Kamleshwar

  • QR codes launching ADOBE FLASH PROFESSIONAL CS5.5 apps

    Hello I'm considering buying Adobe Flash Professional CS5.5 to write android and apple apps but I have a couple of quesries that I hope someone can help me on: 1. Can I launch an app from a scanned QR code and, if so, soes anyone know how (perhaps ha

  • Why won't my iPad connect wirelessly to all my iMac apps on Lion?

    So I've been having an issue that I can't seems to find the answers to in any forums or in any articles online. I've got both an iPad 2 and a brand new iMac with lion 10.7.3. Everything is up to date, but here's the problem, I can access some things