A memory corruption flaw exists in Oracle Java SE's 2D component. The 'nTblSize' variable within the cmm.dll library fails to sanitize user-supplied input when parsing the A-to-B curve data multi-function resulting in memory corruption. With a specially crafted request, a remote attacker can cause a denial of service or potentially execute arbitrary code.
Currently, there are no known workarounds or upgrades to correct this issue. However, Oracle has released a patch to address this vulnerability. Check the vendor advisory in the references section.