The JSST and the Joomla! Security Center report:
[20151201] - Core - Remote Code Execution Vulnerability
Browser information is not filtered properly while saving the
session values into the database which leads to a Remote Code
Execution vulnerability.
[20151202] - Core - CSRF Hardening
Add additional CSRF hardening in com_templates.
[20151203] - Core - Directory Traversal
Failure to properly sanitize input data from the XML install file
located within an extension's package archive allows for directory
traversal.
[20151204] - Core - Directory Traversal
Inadequate filtering of request data leads to a Directory Traversal
vulnerability.