Vulnerabilities in RED HAT
2,124 resultsVexday analysis
Red Hat apresenta footprint mínimo na base Vexday com apenas 1 CVE registrado, sem incidentes sob exploração ativa no momento. A vulnerabilidade identificada relaciona-se a deficiências em armazenamento de credenciais (CWE-522), mas não figura entre as críticas e permanece sem atividade recente de ataque.
CVE-2025-5987HIGHLibssh: invalid return code for chacha20 poly1305 with openssl backendEPSS 1.5%CVE-2019-3894MEDIUMIt was discovered that the ElytronManagedThread in Wildfly's Elytron subsystem in versions from 11 to 16 stores a SecurityIdentity to run thEPSS 1.5%CVE-2017-2658LOWIt was discovered that the Dashbuilder login page as used in Red Hat JBoss BPM Suite before 6.4.2 and Red Hat JBoss Data Virtualization & SeEPSS 1.5%CVE-2017-2632MEDIUMA logic error in valid_role() in CloudForms role validation before 5.7.1.3 could allow a tenant administrator to create groups with a higherEPSS 1.5%CVE-2011-1594MEDIUMSpacewalk: spacewalk: open redirect vulnerability enables phishing attacks via url parameterEPSS 1.5%CVE-2011-2927MEDIUMSpacewalk: spacewalk and red hat network satellite: cross-site scripting vulnerability via search formsEPSS 1.5%CVE-2011-3344MEDIUMSpacewalk: spacewalk: cross-site scripting via uri in lookup login/password formEPSS 1.5%CVE-2023-6356MEDIUMKernel: null pointer dereference in nvmet_tcp_build_iovecEPSS 1.5%CVE-2019-14872MEDIUMThe _dtoa_r function of the newlib libc library, prior to version 3.3.0, performs multiple memory allocations without checking their return EPSS 1.5%CVE-2023-38200HIGHKeylime: registrar is subject to a dos against ssl connectionsEPSS 1.4%CVE-2016-8647LOWAn input validation vulnerability was found in Ansible's mysql_user module before 2.2.1.0, which may fail to correctly change a password in EPSS 1.4%CVE-2023-39180MEDIUMKernel: ksmbd: read request memory leak denial-of-service vulnerabilityEPSS 1.4%CVE-2023-4853HIGHQuarkus: http security policy bypassEPSS 1.4%CVE-2019-3895MEDIUMAn access-control flaw was found in the Octavia service when the cloud platform was deployed using Red Hat OpenStack Platform Director. An aEPSS 1.4%CVE-2026-5121HIGHLibarchive: libarchive: arbitrary code execution via integer overflow in iso9660 image processingEPSS 1.4%CVE-2025-3891HIGHMod_auth_openidc: dos via empty post in mod_auth_openidc with oidcpreservepost enabledEPSS 1.4%CVE-2024-21886HIGHXorg-x11-server: heap buffer overflow in disabledeviceEPSS 1.4%CVE-2024-0567HIGHGnutls: rejects certificate chain with distributed trustEPSS 1.4%CVE-2024-21885HIGHXorg-x11-server: heap buffer overflow in xisenddevicehierarchyeventEPSS 1.4%CVE-2024-3154HIGHCri-o: arbitrary command injection via pod annotationEPSS 1.4%