Security Explorations . Those issues included the two zero-day -- unpatched -- vulnerabilities that to infect computers with malware, Gowdiak said Wednesday via email.
The company continued to report Java 7 vulnerabilities to Oracle in the following months until the total number reached 29. "We demonstrated 16 full Java SE 7 sandbox compromises with the use of our bugs," Gowdiak said.
According to security researchers from security firm Immunity, the Java exploit and integrated into the Blackhole attack toolkit makes use of two Java vulnerabilities not one, as it was previously believed.
"The first bug was used to get a reference to sun.awt.SunToolkit class that is restricted to applets while the second bug invokes the getField public static method on SunToolkit using reflection with a trusted immediate caller bypassing a security check," Immunity developer Esteban Guillardoy said Tuesday in a .
While both of those vulnerabilities, one in the ClassFinder class and one in the MethodFinder class, were found and reported by Security Explorations in April, supplied by the company to Oracle combined them with other bugs, not together, Gowdiak said.