An authenticated server-side request forgery in Nextcloud server 16.0.1 allowed to detect local and remote services when adding a new subscription in the calendar application.
Moxilla Firefox allows remote attackers to bypass the Same Origin Policy to read arbitrary files or gain privileges.
Bodo Möller, Thai Duong and Krzysztof Kotowicz of Google discovered a flaw in the design of SSL version 3.0 that would allow an attacker to calculate the plaintext of secure connections, allowing, for example, secure HTTP cookies to be stolen.
References: http://googleonlinesecurity.blogspot.com/2014/10/this-poodle-bites-exploiting-ssl-30.html https://www.openssl.org/~bodo/ssl-poodle.pdf
A flaw was found in in the Linux kernel's USB device management code which could cause a crash when a device which required sndusbaudio driver. The kernel would panic causing null pointer dereference attempting to access non existent endpoints.
Product bugs:
https://bugzilla.redhat.com/showbug.cgi?id=1283355 https://bugzilla.redhat.com/showbug.cgi?id=1283358
Unspecified vulnerability in the Java SE, Java SE Embedded, JRockit component in Oracle Java SE 5.0u75, 6u85, 7u72, and 8u25; Java SE Embedded 7u71 and 8u6; and JRockit R27.8.4 and R28.3.4 allows remote attackers to affect availability via unknown vectors related to Security.
Kernel crash occurs when presented a buggy USB device which requires wacom driver, causing null pointer dereference.
Product bugs:
https://bugzilla.redhat.com/showbug.cgi?id=1283375 https://bugzilla.redhat.com/showbug.cgi?id=1283377