Vulnerabilities in RED HAT
2,148 resultsVexday analysis
Red Hat apresenta footprint mínimo na base Vexday com apenas 1 CVE registrado, sem incidentes sob exploração ativa no momento. A vulnerabilidade identificada relaciona-se a deficiências em armazenamento de credenciais (CWE-522), mas não figura entre as críticas e permanece sem atividade recente de ataque.
CVE-2026-78409HIGHUtil-linux: util-linux: x-mount.subdir detached-tree resolution can escape via intermediate symlinksEPSS 0.2%CVE-2026-4367MEDIUMLibxpm: libxpm: denial of service via out-of-bounds read in xpm file parsingEPSS 0.2%CVE-2026-0665MEDIUMQemu-kvm: heap off-by-one in kvm xen physdevop_map_pirqEPSS 0.2%CVE-2026-6861MEDIUMEmacs: emacs: memory corruption vulnerability when processing svg cssEPSS 0.2%CVE-2025-13327MEDIUMUv: uv: specially crafted zip archives lead to arbitrary code execution due to parsing differentialsEPSS 0.2%CVE-2025-8860LOWQemu-kvm: uefi-vars: information disclosure vulnerability in uefi_vars_write callbackEPSS 0.2%CVE-2025-2157LOWForeman: disclosure of executed commands and outputs in foreman / red hat satelliteEPSS 0.2%CVE-2026-81893MEDIUMGdk-pixbuf: gdk-pixbuf: invalid write in jpeg icc profile parser on error recoveryEPSS 0.2%CVE-2026-18938MEDIUMP11-kit: integer overflow in rpc attribute-array length calculation can under-allocate nested attribute storage on 32 bit systemsEPSS 0.2%CVE-2026-4897MEDIUMPolkit: polkit: denial of service via unbounded input processing through standard inputEPSS 0.2%CVE-2026-93653MEDIUMPoppler: poppler: unbounded cpu loop in splashoutputdev::tilingpatternfill via unvalidated tiling-pattern repeat count (denial of service)EPSS 0.2%CVE-2026-87766HIGHBubblewrap: bubblewrap: symlink traversal via /oldroot allows writing files outside sandbox during setupEPSS 0.2%CVE-2026-15003MEDIUMBinutils: gnu binutils: heap-buffer-overflow in linker leads to information disclosure and denial of serviceEPSS 0.2%CVE-2026-90463MEDIUMSssd: local oob read in nss service request parsers (`sss_nss_protocol_parse_svc_name` / `sss_nss_protocol_parse_svc_port`)EPSS 0.1%CVE-2026-13316MEDIUMForeman: ssrf to cloud metada service through unvalidated test_url parameters in foreman configEPSS 0.1%CVE-2026-92768MEDIUMCockpit-machines: cockpit-machines: sensitive data exposure via command-line argumentsEPSS 0.1%CVE-2026-96283LOWFlatpak: flatpak: flatpak-system-helper cross-user cancelpull orphans another user's ongoing pullEPSS 0.1%CVE-2026-4105MEDIUMSystemd: systemd: privilege escalation via improper access control in registermachine d-bus methodEPSS 0.1%CVE-2026-6245MEDIUMSssd: out-of-bounds read in the sssdEPSS 0.1%CVE-2026-73434MEDIUMGstreamer1-plugins-good: gstreamer: out-of-bounds read in avidemux vprp video field descriptor parsingEPSS 0.1%