Vulnerabilidades em RED HAT

2.127 resultados
Análise Vexday

Red Hat apresenta footprint mínimo na base Vexday com apenas 1 CVE registrado, sem incidentes sob exploração ativa no momento. A vulnerabilidade identificada relaciona-se a deficiências em armazenamento de credenciais (CWE-522), mas não figura entre as críticas e permanece sem atividade recente de ataque.

CVE-2024-0560MEDIUMApicast: use_3scale_oidc_issuer_endpoint of token introspection policy isn't compatible with rh-sso 7.5 or later versionsEPSS 0.5%CVE-2026-11610HIGH389-ds-base: 389-ds-base: heap buffer overflow in sasl_io_recv() via padded sasl unbindEPSS 0.5%CVE-2026-2239LOWGimp: gimp: application crash (dos) via crafted psd file due to heap-buffer-overflowEPSS 0.5%CVE-2025-8556LOWGithub.com/cloudflare/circl: circl-fourq: missing and wrong validation can lead to incorrect resultsEPSS 0.5%CVE-2023-3384MEDIUMQuay: stored cross site scriptingEPSS 0.5%CVE-2017-7513MEDIUMIt was found that Satellite 5 configured with SSL/TLS for the PostgreSQL backend failed to correctly validate X.509 server certificate host EPSS 0.5%CVE-2026-19729MEDIUMKeycloak-services: keycloak-services: incomplete fix for arbitrary filesystem path probing via keystore parametersEPSS 0.5%CVE-2023-1636MEDIUMIncomplete container isolationEPSS 0.5%CVE-2026-66878HIGHMulticloud-operators-subscription: multicloud-operators-subscription: fetchchannelreferences honours channel.spec.secretref.namespace enabling cross-namespace secret exfiltrationEPSS 0.5%CVE-2026-4636HIGHKeycloak: keycloak: uma policy bypass allows authenticated users to gain unauthorized access to victim-owned resources.EPSS 0.5%CVE-2026-3099MEDIUMLibsoup: libsoup: authentication bypass via digest authentication replay attackEPSS 0.5%CVE-2026-73122HIGHMulticloud-operators-channel: multicloud-operators-channel: auto-generated role grants every managed-cluster agent secrets:get,list,watch in channel namespacesEPSS 0.5%CVE-2026-19843HIGH389-ds-base: 389-ds-base: command injection via unescaped ldap dn in cockpit 389 console ldap editorEPSS 0.5%CVE-2026-18573MEDIUMKeycloak-services: keycloak-services: client access-type policy condition bypass during client updateEPSS 0.5%CVE-2025-0689HIGHGrub2: udf: heap based buffer overflow in grub_udf_read_block() may lead to arbitrary code executionEPSS 0.5%CVE-2026-15588MEDIUMGdbusserver: glib2: gdbusserver pre-authentication dos via unbounded sasl line bufferingEPSS 0.5%CVE-2025-47712MEDIUMNbd: nbdkit: integer overflow triggers an assertion resulting in denial of serviceEPSS 0.5%CVE-2024-6875MEDIUMInfinispan: infinispan: rest compare api has buffer leakEPSS 0.5%CVE-2026-77176HIGHKata-containers: insufficient validation of createcontainer mount and storage rules in genpolicyEPSS 0.5%CVE-2026-18620HIGHData-sciences-pipeline: user-controlled serviceaccount for workflow pods without authorization check — confused deputyEPSS 0.5%