Moxilla Firefox allows remote attackers to bypass the Same Origin Policy to read arbitrary files or gain privileges.
Bodo Möller, Thai Duong and Krzysztof Kotowicz of Google discovered a flaw in the design of SSL version 3.0 that would allow an attacker to calculate the plaintext of secure connections, allowing, for example, secure HTTP cookies to be stolen.
References: http://googleonlinesecurity.blogspot.com/2014/10/this-poodle-bites-exploiting-ssl-30.html https://www.openssl.org/~bodo/ssl-poodle.pdf
A flaw was found in in the Linux kernel's USB device management code which could cause a crash when a device which required sndusbaudio driver. The kernel would panic causing null pointer dereference attempting to access non existent endpoints.
Product bugs:
https://bugzilla.redhat.com/showbug.cgi?id=1283355 https://bugzilla.redhat.com/showbug.cgi?id=1283358
Kernel crash occurs when presented a buggy USB device which requires wacom driver, causing null pointer dereference.
Product bugs:
https://bugzilla.redhat.com/showbug.cgi?id=1283375 https://bugzilla.redhat.com/showbug.cgi?id=1283377