CVE-2015-4050 fixes unauthorized access when using ESI.
CVE-2015-2308 is about possible code injections via the ESI framework.
CVE-2015-2309 fixes some unsafe methods in the Request class.
CVE-2014-6061 is about a potential security issue when parsing the Authorization header.
CVE-2014-6072 is about fixing a CSRF vulnerability in the Web Profiler.
CVE-2014-5245 is about being able to access ESI URLs even behind a trusted proxy.
CVE-2014-5244 is about a potential denial of service with a malicious HTTP Host header.
Symfony 2.3.18, 2.4.8, and 2.5.2 have just been released; they contain a security fix for the Translator class provided by FrameworkBundle (CVE-2014-4931).
Symfony 2.0.25, 2.1.13, 2.2.9, and 2.3.6 have just been released; they contain a security fix for the Security component (CVE-2013-5958).
A security issue has been discovered in FOSUserBundle (CVE-2013-5750).