This is a very interesting article, nice work.
I would recommend you add *exact* versions of the various API's being used.
At the very least, all of your Java samples do indeed check out against Java 1.5_0_16 on Windows.
Have you reported these issues to Sun/Microsoft?
-Nathanael
- JimBreaking the Bank (Vulnerabilities in Numeric Processing within Financial Applications)
By Adam Boulton, Stephen De Vries, Kevin O'Reilly, July 15, 2008
---------------------------------------------------------------------------- Join us on IRC: irc.freenode.net #webappsec
Join WASC on LinkedIn http://www.linkedin.com/e/gis/83336/4B20E4374DBA