Vulnerabilidades em RED HAT

2.143 resultados
Análise Vexday

Red Hat apresenta footprint mínimo na base Vexday com apenas 1 CVE registrado, sem incidentes sob exploração ativa no momento. A vulnerabilidade identificada relaciona-se a deficiências em armazenamento de credenciais (CWE-522), mas não figura entre as críticas e permanece sem atividade recente de ataque.

CVE-2025-8114MEDIUMLibssh: null pointer dereference in libssh kex session id calculationEPSS 0.2%CVE-2026-40917MEDIUMGimp: gimp: application crashes or information disclosure via crafted icns image filesEPSS 0.2%CVE-2026-86320HIGHFlatpak-builder: host code execution via `git am` hook execution in patch source extraction (`use-git-am`)EPSS 0.2%CVE-2026-85013HIGHEnvironment-modules: command injection in environment-modules bash completion via malicious module names containing shell metacharactersEPSS 0.2%CVE-2026-50259HIGHXorg-x11-server: xorg-x11-server-xwayland: xorg-x11-server: stack buffer overflow in xkb setmap request via mapwidths indexingEPSS 0.2%CVE-2026-50258HIGHXorg-x11-server: xorg-x11-server-xwayland: xorg-x11-server: stack buffer overflow in xkb key types due to unchecked shift levelsEPSS 0.2%CVE-2026-10840HIGHOpenshift-pipelines-operator-rh: openshift-pipelines-operator: tekton-scheduler-rolebinding grants system:authenticated write access to kueue and cert-manager resourcesEPSS 0.2%CVE-2026-43961HIGHVim: vimscript injection via unescaped filename in netrw s:netrwmarkfile() filter() expression allows arbitrary code executionEPSS 0.2%CVE-2025-7195MEDIUMOperator-sdk: privilege escalation due to incorrect permissions of /etc/passwdEPSS 0.2%CVE-2026-84270MEDIUMGvfs: mtp: out-of-bounds read in do_read()EPSS 0.2%CVE-2023-4394MEDIUMMemory leak in btrfs_get_dev_args_from_path()EPSS 0.2%CVE-2026-71460MEDIUMAutomation-controller: automation-controller-container: automation-controller: any authenticated user reads red hat subscription/license details via /config/EPSS 0.2%CVE-2026-12112HIGHForeman-mcp-server: mcp server: active session hijacking via insecure session state reuseEPSS 0.2%CVE-2025-7738MEDIUMPython3.11-django-ansible-base: sensitive authenticator secrets returned in clear text via api in aapEPSS 0.2%CVE-2025-0736MEDIUMOrg.infinispan-infinispan-parent: exposure of sensitive information in application logsEPSS 0.2%CVE-2026-0810HIGHGix-date: gix-date: undefined behavior due to invalid string generationEPSS 0.2%CVE-2023-3674LOWKeylime: attestation failure when the quote's signature does not validateEPSS 0.2%CVE-2025-5417MEDIUMRhdh: red hat developer hub user permissionsEPSS 0.2%CVE-2022-3466MEDIUMCri-o: security regression of cve-2022-27652EPSS 0.2%CVE-2025-25209MEDIUMRhcl: sharedsecretref can be used to leak secrets severityEPSS 0.2%