Vulnerabilidades em RED HAT
2.141 resultadosAnálise Vexday
Red Hat apresenta footprint mínimo na base Vexday com apenas 1 CVE registrado, sem incidentes sob exploração ativa no momento. A vulnerabilidade identificada relaciona-se a deficiências em armazenamento de credenciais (CWE-522), mas não figura entre as críticas e permanece sem atividade recente de ataque.
CVE-2023-4385MEDIUMKernel: jfs: null pointer dereference in dbfree()EPSS 0.2%CVE-2026-18967MEDIUMKeycloak-services: keycloak-services: saml onetimeuse assertion replay in idp-initiated broker flowEPSS 0.2%CVE-2026-14935LOWGstreamer1-plugins-bad-free: gstreamer: webrtcbin accepts remote sdp without a=fingerprint due to inverted presence checkEPSS 0.2%CVE-2023-3180MEDIUMHeap buffer overflow in virtio_crypto_sym_op_helper()EPSS 0.2%CVE-2025-66286MEDIUMWebkitgtk: authorization bypass through webpage::send-request signal handlerEPSS 0.2%CVE-2025-5962HIGHRhel-lightspeed: improper access control in lightspeed history management allows local privilege manipulationEPSS 0.2%CVE-2026-66757MEDIUMGimp: signed integer overflow in file-sgi (sgi-lib) causes the plugin to crash on rle sgi imagesEPSS 0.2%CVE-2023-1476HIGHKpatch: mm/mremap.c: incomplete fix for cve-2022-41222EPSS 0.2%CVE-2025-48798HIGHGimp: multiple use after free in xcf parserEPSS 0.2%CVE-2024-11029MEDIUMFreeipa: administrative user data leaked through systemd journalEPSS 0.2%CVE-2023-4133MEDIUMKernel: cxgb4: use-after-free in ch_flower_stats_cb()EPSS 0.2%CVE-2026-11861CRITICALFreeipa: idm: ipa: freeipa: obtaining tgs with impersonating cname through trust relationshipsEPSS 0.2%CVE-2026-94368HIGHNoobaa-core: noobaa-core: presigned put url escalation to copyobject via unsigned x-amz-copy-source headerEPSS 0.2%CVE-2026-74244MEDIUMQuay: stripe webhook accepts forged events without signature verification in quayEPSS 0.2%CVE-2026-10533MEDIUMOpenshift: openshift: non-admin user can bypass resourcequota and flood etcd with events causing cluster-wide api degradationEPSS 0.2%CVE-2026-14324MEDIUMPipewire: raop rtsp null derefEPSS 0.2%CVE-2024-5891MEDIUMQuay: unauthorized user may authenticate via oauth application tokenEPSS 0.2%CVE-2023-3863MEDIUMUse-after-free in nfc_llcp_find_loca in net/nfc/llcp_core.cEPSS 0.2%CVE-2024-1312MEDIUMKernel: race condition leads to use after free during vma lock in lock_vma_under_rcuEPSS 0.2%CVE-2024-0217LOWPackagekitd: use-after-free in idle function callbackEPSS 0.2%