IcedTea6 prior to 1.7.4 allow unsigned apps to read and write arbitrary files, related to Extended JNLP Services.
redhat icedtea6