Vulnerabilidades em Red Hat

2.071 resultados
Análise Vexday

Com 1.477 CVEs catalogadas e 232 surgidas apenas nos últimos 90 dias, o volume de vulnerabilidades associadas ao Red Hat exige monitoramento contínuo. A taxa de exploração ativa está abaixo da média geral do catálogo, com apenas 1 CVE confirmada no CISA KEV — a CVE-2023-4911, que apresenta EPSS de 0,7861, indicando probabilidade elevada de exploração e merecendo atenção prioritária de equipes de resposta. Das 34 vulnerabilidades de severidade crítica, 18 contam com prova de conceito pública disponível, o que reduz a barreira técnica para exploração e aumenta o risco operacional. O tipo de falha mais recorrente é CWE-125 (leitura fora dos limites), padrão que frequentemente viabiliza vazamento de dados ou corrupção de memória e deve orientar revisões de hardening e priorização de patches.

CVE-2017-2658LOWIt was discovered that the Dashbuilder login page as used in Red Hat JBoss BPM Suite before 6.4.2 and Red Hat JBoss Data Virtualization & SeEPSS 1.5%CVE-2017-2632MEDIUMA logic error in valid_role() in CloudForms role validation before 5.7.1.3 could allow a tenant administrator to create groups with a higherEPSS 1.5%CVE-2011-2927MEDIUMSpacewalk: spacewalk and red hat network satellite: cross-site scripting vulnerability via search formsEPSS 1.5%CVE-2011-3344MEDIUMSpacewalk: spacewalk: cross-site scripting via uri in lookup login/password formEPSS 1.5%CVE-2011-1594MEDIUMSpacewalk: spacewalk: open redirect vulnerability enables phishing attacks via url parameterEPSS 1.5%CVE-2023-6356MEDIUMKernel: null pointer dereference in nvmet_tcp_build_iovecEPSS 1.5%CVE-2019-14872MEDIUMThe _dtoa_r function of the newlib libc library, prior to version 3.3.0, performs multiple memory allocations without checking their return EPSS 1.5%CVE-2023-38200HIGHKeylime: registrar is subject to a dos against ssl connectionsEPSS 1.4%CVE-2016-8647LOWAn input validation vulnerability was found in Ansible's mysql_user module before 2.2.1.0, which may fail to correctly change a password in EPSS 1.4%CVE-2023-39180MEDIUMKernel: ksmbd: read request memory leak denial-of-service vulnerabilityEPSS 1.4%CVE-2023-4853HIGHQuarkus: http security policy bypassEPSS 1.4%CVE-2019-3895MEDIUMAn access-control flaw was found in the Octavia service when the cloud platform was deployed using Red Hat OpenStack Platform Director. An aEPSS 1.4%CVE-2025-3891HIGHMod_auth_openidc: dos via empty post in mod_auth_openidc with oidcpreservepost enabledEPSS 1.4%CVE-2024-21886HIGHXorg-x11-server: heap buffer overflow in disabledeviceEPSS 1.4%CVE-2024-21885HIGHXorg-x11-server: heap buffer overflow in xisenddevicehierarchyeventEPSS 1.4%CVE-2024-0567HIGHGnutls: rejects certificate chain with distributed trustEPSS 1.4%CVE-2024-3154HIGHCri-o: arbitrary command injection via pod annotationEPSS 1.4%CVE-2023-40745MEDIUMLibtiff: integer overflow in tiffcp.cEPSS 1.4%CVE-2023-6918LOWLibssh: missing checks for return values for digestsEPSS 1.4%CVE-2026-1961HIGHForman: foreman: remote code execution via command injection in websocket proxyEPSS 1.4%