Vulnerabilities in RED HAT
2,141 resultsVexday analysis
Red Hat apresenta footprint mínimo na base Vexday com apenas 1 CVE registrado, sem incidentes sob exploração ativa no momento. A vulnerabilidade identificada relaciona-se a deficiências em armazenamento de credenciais (CWE-522), mas não figura entre as críticas e permanece sem atividade recente de ataque.
CVE-2023-3773MEDIUMKernel: xfrm: out-of-bounds read of xfrma_mtimer_thresh nlattrEPSS 0.3%CVE-2023-4459MEDIUMKernel: vmxnet3: null pointer dereference in vmxnet3_rq_cleanup()EPSS 0.2%CVE-2025-7365HIGHKeycloak: phishing attack via email verification step in first login flowEPSS 0.2%CVE-2024-12125HIGH3scale-porta: readonly fields not validated server-sideEPSS 0.2%CVE-2024-0443MEDIUMKernel: blkio memory leakage due to blkcg and some blkgs are not freed after they are made offline.EPSS 0.2%CVE-2024-6519HIGHQemu: scsi: lsi53c895a: use-after-free local privilege escalation vulnerabilityEPSS 0.2%CVE-2023-3899HIGHSubscription-manager: inadequate authorization of com.redhat.rhsm1 d-bus interface allows local users to modify configurationEPSS 0.2%CVE-2025-6242HIGHVllm: server side request forgery (ssrf) in mediaconnectorEPSS 0.2%CVE-2023-4065MEDIUMOperator: plaintext password in operator logEPSS 0.2%CVE-2025-46399MEDIUMXfig: transfig: fig2dev segmentation fault vulnerabilityEPSS 0.2%CVE-2026-1767MEDIUMLocalsearch: tracker-miners: gnome localsearch mp3 extractor: heap buffer overflow leading to denial of service or information disclosure via malformed mp3 id3 tagsEPSS 0.2%CVE-2025-4437MEDIUMCri-o: large /etc/passwd file may lead to denial of serviceEPSS 0.2%CVE-2025-46400MEDIUMXfig: fig2dev segmentation fault in read_arcobjectEPSS 0.2%CVE-2020-1706HIGHIt has been found that in openshift-enterprise version 3.11 and openshift-enterprise versions 4.1 up to, including 4.3, multiple containers EPSS 0.2%CVE-2026-74247MEDIUMQuay: ssrf via build archive_url in quay build apiEPSS 0.2%CVE-2019-19355HIGHAn insecure modification vulnerability in the /etc/passwd file was found in the openshift/ocp-release-operator-sdk. An attacker with access EPSS 0.2%CVE-2026-97311MEDIUMKeycloak-services: keycloak-services: admin rest api role-groups endpoint discloses groups without authorizationEPSS 0.2%CVE-2024-45777MEDIUMGrub2: grub-core/gettext: integer overflow leads to heap oob write.EPSS 0.2%CVE-2026-11611MEDIUM389-ds-base: 389-ds-base: content sync plugin unbounded queue growth and race conditionsEPSS 0.2%CVE-2026-13434MEDIUMVirt-controller-rhel9: kubevirt: kubevirt: multus default-network annotation injection via unvalidated tenant networkname when externalnetresourceinjection is enabledEPSS 0.2%