Vulnerabilidades en RED HAT

2146 resultados
Análisis Vexday

Red Hat apresenta footprint mínimo na base Vexday com apenas 1 CVE registrado, sem incidentes sob exploração ativa no momento. A vulnerabilidade identificada relaciona-se a deficiências em armazenamento de credenciais (CWE-522), mas não figura entre as críticas e permanece sem atividade recente de ataque.

CVE-2026-3012HIGHSamba: group policy certificate enrollment uses http:// without validationEPSS 0.2%CVE-2026-93999MEDIUMKeycloak-services: keycloak-services: token refresh continues issuing tokens for disabled audience clientsEPSS 0.2%CVE-2026-14612MEDIUMFreeipa: ipa: idm: freeipa: off-by-one buffer overflows in ipa-otpd oauth2.c during oauth2 device authorizationEPSS 0.2%CVE-2024-1141MEDIUMGlance-store: glance store access key logged in debug log levelEPSS 0.2%CVE-2025-9820MEDIUMGnutls: stack-based buffer overflow in gnutls_pkcs11_token_init() functionEPSS 0.2%CVE-2026-12528MEDIUM389-ds-base: 389-ds-base: heap-buffer-overflows in __aclp__normalize_acltxt()EPSS 0.2%CVE-2026-1940MEDIUMGstreamer: incomplete fix of cve-2026-1940EPSS 0.2%CVE-2026-90948HIGHGimp: gimp: heap-based buffer overflow in ico loader via integer overflow in embedded png dimensionsEPSS 0.2%CVE-2024-0775MEDIUMKernel: use-after-free while changing the mount option in __ext4_remount leadingEPSS 0.2%CVE-2024-45782HIGHGrub2: fs/hfs: strcpy() using the volume name (fs/hfs.c:382)EPSS 0.2%CVE-2026-18369MEDIUMDogtag-pki: pki-core: redhat-pki: pki: acme http-01 validation ssrf via ip literal identifiers and unvalidated redirectsEPSS 0.2%CVE-2024-13484HIGHOpenshift-gitops-operator-container: namespace isolation breakEPSS 0.2%CVE-2023-6531HIGHKernel: gc's deletion of an skb races with unix_stream_read_generic() leading to uafEPSS 0.2%CVE-2026-6855HIGHInstructlab: instructlab: path traversal allows arbitrary directory creation and file writeEPSS 0.2%CVE-2026-12515MEDIUMKatello: missing repository authorization in content_uploads exposes cross-product content existenceEPSS 0.2%CVE-2023-4910MEDIUM3scale-admin-portal: logged out users tokens can be accessedEPSS 0.2%CVE-2025-3528HIGHMirror-registry: local privilege escalation due to incorrect permissions in mirror-registryEPSS 0.2%CVE-2026-0967LOWLibssh: libssh: denial of service via inefficient regular expression processingEPSS 0.2%CVE-2026-40916MEDIUMGimp: gimp: denial of service due to stack buffer overflow in tim image loaderEPSS 0.2%CVE-2026-40917MEDIUMGimp: gimp: application crashes or information disclosure via crafted icns image filesEPSS 0.2%