A .desktop file in the Debian openjdk-7 package 7u79-2.5.5-1~deb8u1 includes a MIME type registration that is added to /etc/mailcap by mime-support, which allows remote attackers to execute arbitrary code via a JAR file.
https://euvd.enisa.europa.eu/vulnerability/EUVD-2014-8703
http://www.securityfocus.com/bid/76019
http://www.openwall.com/lists/oss-security/2015/07/18/2