Vulnerabilities in RED HAT

2,153 results
Vexday analysis

Red Hat apresenta footprint mínimo na base Vexday com apenas 1 CVE registrado, sem incidentes sob exploração ativa no momento. A vulnerabilidade identificada relaciona-se a deficiências em armazenamento de credenciais (CWE-522), mas não figura entre as críticas e permanece sem atividade recente de ataque.

CVE-2026-1765MEDIUMLocalsearch: tracker-miners: gnome localsearch mp3 extractor: denial of service and potential information disclosure via crafted mp3 filesEPSS 0.1%CVE-2026-13218MEDIUMKubevirt: kubevirt: symlink following in writetocachedfile allows host file overwrite from virt-launcherEPSS 0.1%CVE-2026-11569MEDIUMQuay: quay: stored xss via filedrop svg uploadEPSS 0.1%CVE-2026-84042HIGHCrun: crun: rootful krun with passt executes container payload as host rootEPSS 0.1%CVE-2026-87872MEDIUMCommunity.general: community.general: ocapi module_utils (ocapi_command, ocapi_info) hardcode validate_certs=false with no override, enabling tls man-in-the-middle and credential disclosureEPSS 0.1%CVE-2026-63623MEDIUMLibvirt: information disclosure via world-readable storage volume images during clone/convertEPSS 0.1%CVE-2026-84718MEDIUMAutomation-controller: automation-controller: client ip spoofing in audit/access logs via unrestricted x-forwarded-for trustEPSS 0.1%CVE-2026-92382MEDIUMUsbredir: usbredir: unbounded iso_packet_desc[] index in usbredirhost_iso_packet() leads to heap out-of-bounds writeEPSS 0.1%CVE-2026-19685HIGHNetworkmanager: networkmanager: 802-1x ca-path and phase2-ca-path bypass private_user restriction, allowing wpa-enterprise server validation bypass (incomplete fix for cve-2025-9615)EPSS 0.1%CVE-2025-14010MEDIUMAnsible-collection-community-general: ansible-collection-community-general: keycloak user module leaks credentials in verbose outputEPSS 0.1%CVE-2026-97846MEDIUMKeycloak-services: keycloak-services: standard token exchange v2 bypasses mtls holder-of-key bindingEPSS 0.1%CVE-2025-6017MEDIUMRhacm: users with clusterreader role can see credentials from managed-clustersEPSS 0.1%CVE-2026-54228HIGHAbrt: toctou race condition in abrt-dbus setelement allows arbitrary file writes to dump directoriesEPSS 0.1%CVE-2026-13322LOWKubevirt: virt-handler-rhel9: kubevirt: unbounded virtio-serial readline in virt-handler causes oom denial of serviceEPSS 0.1%CVE-2026-19411LOWShim/dp.c library: null-pointer dereference in is_removable_media_path() when devicepathtostr() returns nullEPSS 0.1%CVE-2026-68744LOWSssd: sssd: nss responder uninitialized heap disclosure in initgroups replyEPSS 0.1%CVE-2026-68743MEDIUMSssd: sssd: pam responder out-of-bounds read via unchecked auth_token_length in protocol v1EPSS 0.1%CVE-2026-97185HIGHGimp: gimp: out-of-bounds write in gimpressionist plugin via crafted preset fileEPSS 0.1%CVE-2026-96512HIGHSudo: sudo: tz environment variable allows bypass of notbefore/notafter time-based authorizationEPSS 0.1%CVE-2026-91786MEDIUMGnome-shell: gnome-shell: out-of-bounds read in remote search icon rendering due to unvalidated icon-data buffer sizeEPSS 0.1%