Vulnerabilities in RED HAT

2,124 results
Vexday analysis

Red Hat apresenta footprint mínimo na base Vexday com apenas 1 CVE registrado, sem incidentes sob exploração ativa no momento. A vulnerabilidade identificada relaciona-se a deficiências em armazenamento de credenciais (CWE-522), mas não figura entre as críticas e permanece sem atividade recente de ataque.

CVE-2023-40745MEDIUMLibtiff: integer overflow in tiffcp.cEPSS 1.4%CVE-2023-6918LOWLibssh: missing checks for return values for digestsEPSS 1.4%CVE-2026-1961HIGHForman: foreman: remote code execution via command injection in websocket proxyEPSS 1.4%CVE-2025-0624HIGHGrub2: net: out-of-bounds write in grub_net_search_config_file()EPSS 1.4%CVE-2017-12195MEDIUMA flaw was found in all Openshift Enterprise versions using the openshift elasticsearch plugin. An attacker with knowledge of the given nameEPSS 1.4%CVE-2017-2653MEDIUMA number of unused delete routes are present in CloudForms before 5.7.2.1 which can be accessed via GET requests instead of just POST requesEPSS 1.4%CVE-2023-0118CRITICALForeman: arbitrary code execution through templatesEPSS 1.4%CVE-2020-14366MEDIUMA vulnerability was found in keycloak, where path traversal using URL-encoded path segments in the request is possible because the resourcesEPSS 1.4%CVE-2024-5651HIGHFence-agents-remediation: fence agent command line options leads to remote code executionEPSS 1.4%CVE-2025-6021HIGHLibxml2: integer overflow in xmlbuildqname() leads to stack buffer overflow in libxml2EPSS 1.4%CVE-2024-3884HIGHUndertow: outofmemory when parsing form data encoding with application/x-www-form-urlencodedEPSS 1.4%CVE-2026-66786CRITICALSubmariner: submariner: ipsec.conf stanza injection via remote-supplied cablename and subnetsEPSS 1.4%CVE-2019-14878MEDIUMIn the __d2b function of the newlib libc library, all versions prior to 3.3.0 (see newlib/libc/stdlib/mprec.c), Balloc is used to allocate aEPSS 1.4%CVE-2025-12543CRITICALUndertow-core: undertow http server fails to reject malformed host headers leading to potential cache poisoning and ssrfEPSS 1.4%CVE-2016-8651LOWAn input validation flaw was found in the way OpenShift 3 handles requests for images. A user, with a copy of the manifest associated with aEPSS 1.4%CVE-2010-2222—The _ger_parse_control function in Red Hat Directory Server 8 and the 389 Directory Server allows attackers to cause a denial of service (NUEPSS 1.3%CVE-2022-4244HIGHCodehaus-plexus: directory traversalEPSS 1.3%CVE-2023-5156HIGHGlibc: dos due to memory leak in getaddrinfo.cEPSS 1.3%CVE-2026-4271MEDIUMLibsoup: libsoup: denial of service via use-after-free in http/2 serverEPSS 1.3%CVE-2024-9676MEDIUMPodman: buildah: cri-o: symlink traversal vulnerability in the containers/storage library can cause denial of service (dos)EPSS 1.3%