Vulnerabilidades en RED HAT

2125 resultados
Análisis Vexday

Red Hat apresenta footprint mínimo na base Vexday com apenas 1 CVE registrado, sem incidentes sob exploração ativa no momento. A vulnerabilidade identificada relaciona-se a deficiências em armazenamento de credenciais (CWE-522), mas não figura entre as críticas e permanece sem atividade recente de ataque.

CVE-2024-1725MEDIUMKubevirt-csi: persistentvolume allows access to hcp's root nodeEPSS 0.6%CVE-2023-6393MEDIUMQuarkus: potential invalid reuse of context when @cacheresult on a uni is usedEPSS 0.6%CVE-2026-64611HIGHLibcupsfilters: cups-filters: libcupsfilters: cpu exhaustion via infinite loop in cfieee1284normalizemakemodel()EPSS 0.6%CVE-2026-49329HIGHOpenshift/oauth-server: openshift/oauth-server: quadratic-time dos via accept-language header underscore bypass on unauthenticated login endpointsEPSS 0.6%CVE-2005-4890—There is a possible tty hijacking in shadow 4.x before 4.1.5 and sudo 1.x before 1.7.4 via "su - user -c program". The user session can be eEPSS 0.6%CVE-2023-4958MEDIUMStackrox: missing http security headers allows for clickjacking in web uiEPSS 0.6%CVE-2026-52719HIGHGstreamer1-plugins-bad-free: gstreamer: out-of-bounds read via jpeg segment length validation in va decoderEPSS 0.6%CVE-2026-73267HIGHClusterclaims-controller: managedcluster deletion keyed solely on clusterclaim.spec.namespace with no local ownership checkEPSS 0.6%CVE-2024-0564MEDIUMKernel: max page sharing of kernel samepage merging (ksm) may cause memory deduplicationEPSS 0.6%CVE-2026-46579HIGHOpenshift/router: openshift/router: mtls client certificate spoofing via unstripped x-ssl-client headers on http frontendEPSS 0.6%CVE-2026-66794CRITICALCluster-proxy-addon: cluster-proxy-addon: unauthenticated ssrf to arbitrary managed-cluster services via public routeEPSS 0.6%CVE-2026-3184LOWUtil-linux: util-linux: access control bypass due to improper hostname canonicalizationEPSS 0.6%CVE-2023-5574HIGHXorg-x11-server: use-after-free bug in damagedestroyEPSS 0.6%CVE-2023-5367HIGHXorg-x11-server: out-of-bounds write in xichangedeviceproperty/rrchangeoutputpropertyEPSS 0.6%CVE-2019-3884LOWA vulnerability exists in the garbage collection mechanism of atomic-openshift. An attacker able spoof the UUID of a valid object from anothEPSS 0.6%CVE-2026-67567CRITICALMulticloud-operators-subscription: multicloud-operators-subscription: helmrelease chart applied with controller sa without gvk or namespace restrictionEPSS 0.6%CVE-2026-3118MEDIUMRhdh: graphql injection leading to platform-wide denial of service (dos) in rh developer hub orchestrator pluginEPSS 0.6%CVE-2026-0719HIGHLibsoup: signed to unsigned conversion error leading to stack-based buffer overflow in libsoup ntlm authenticationEPSS 0.6%CVE-2026-84502CRITICALAutomation-controller: automation-controller-container: automation-controller: project scm_url argument injection into `git ls-remote --upload-pack` yields rce on the controller-task control-plane podEPSS 0.6%CVE-2026-77680MEDIUMLibsoup3: libsoup: quadratic cpu denial of service in http range coalescing after cve-2025-32907 fixEPSS 0.6%