Vulnerabilidades em Red Hat

2.071 resultados
Análise Vexday

Com 1.477 CVEs catalogadas e 232 surgidas apenas nos últimos 90 dias, o volume de vulnerabilidades associadas ao Red Hat exige monitoramento contínuo. A taxa de exploração ativa está abaixo da média geral do catálogo, com apenas 1 CVE confirmada no CISA KEV — a CVE-2023-4911, que apresenta EPSS de 0,7861, indicando probabilidade elevada de exploração e merecendo atenção prioritária de equipes de resposta. Das 34 vulnerabilidades de severidade crítica, 18 contam com prova de conceito pública disponível, o que reduz a barreira técnica para exploração e aumenta o risco operacional. O tipo de falha mais recorrente é CWE-125 (leitura fora dos limites), padrão que frequentemente viabiliza vazamento de dados ou corrupção de memória e deve orientar revisões de hardening e priorização de patches.

CVE-2025-0624HIGHGrub2: net: out-of-bounds write in grub_net_search_config_file()EPSS 1.4%CVE-2017-12195MEDIUMA flaw was found in all Openshift Enterprise versions using the openshift elasticsearch plugin. An attacker with knowledge of the given nameEPSS 1.4%CVE-2017-2653MEDIUMA number of unused delete routes are present in CloudForms before 5.7.2.1 which can be accessed via GET requests instead of just POST requesEPSS 1.4%CVE-2023-0118CRITICALForeman: arbitrary code execution through templatesEPSS 1.4%CVE-2019-14863HIGHThere is a vulnerability in all angular versions before 1.5.0-beta.0, where after escaping the context of the web application, the web appliEPSS 1.4%CVE-2020-14366MEDIUMA vulnerability was found in keycloak, where path traversal using URL-encoded path segments in the request is possible because the resourcesEPSS 1.4%CVE-2024-5651HIGHFence-agents-remediation: fence agent command line options leads to remote code executionEPSS 1.4%CVE-2025-6021HIGHLibxml2: integer overflow in xmlbuildqname() leads to stack buffer overflow in libxml2EPSS 1.4%CVE-2024-3884HIGHUndertow: outofmemory when parsing form data encoding with application/x-www-form-urlencodedEPSS 1.4%CVE-2025-12543CRITICALUndertow-core: undertow http server fails to reject malformed host headers leading to potential cache poisoning and ssrfEPSS 1.4%CVE-2016-8651LOWAn input validation flaw was found in the way OpenShift 3 handles requests for images. A user, with a copy of the manifest associated with aEPSS 1.4%CVE-2010-2222The _ger_parse_control function in Red Hat Directory Server 8 and the 389 Directory Server allows attackers to cause a denial of service (NUEPSS 1.3%CVE-2022-4244HIGHCodehaus-plexus: directory traversalEPSS 1.3%CVE-2019-14878MEDIUMIn the __d2b function of the newlib libc library, all versions prior to 3.3.0 (see newlib/libc/stdlib/mprec.c), Balloc is used to allocate aEPSS 1.3%CVE-2023-5156HIGHGlibc: dos due to memory leak in getaddrinfo.cEPSS 1.3%CVE-2024-9676MEDIUMPodman: buildah: cri-o: symlink traversal vulnerability in the containers/storage library can cause denial of service (dos)EPSS 1.3%CVE-2026-42009HIGHGnutls: gnutls: denial of service via dtls packet reordering vulnerabilityEPSS 1.3%CVE-2016-7047MEDIUMA flaw was found in the CloudForms API before 5.6.3.0, 5.7.3.1 and 5.8.1.2. A user with permissions to use the MiqReportResults capability wEPSS 1.3%CVE-2023-34968MEDIUMSamba: spotlight server-side share path disclosureEPSS 1.3%CVE-2019-14876MEDIUMIn the __lshift function of the newlib libc library, all versions prior to 3.3.0 (see newlib/libc/stdlib/mprec.c), Balloc is used to allocatEPSS 1.3%