A Java applet can trick the user into doing something stupid such as revealing their root password though there are efforts to avoid this. A Java applet can also send this information back to the applet's server.

Finally an applet can display pictures or text or play sounds which the user may find annoying or offensive, but this hardly qualifies as a security flaw and is not unique to Java enabled browsers.

Posted in: Java

