Heap-based buffer overflow in Netscape and Mozilla allows remote attackers to execute arbitrary code via a jar: URL that references a malformed .jar file, which overflows a buffer during decompression.
https://exchange.xforce.ibmcloud.com/vulnerabilities/10636
http://www.securityfocus.com/bid/6185
http://www.redhat.com/support/errata/RHSA-2003-163.html
http://www.redhat.com/support/errata/RHSA-2003-162.html