Vulnerabilidades em Red Hat

2.073 resultados
Análise Vexday

Com 1.477 CVEs catalogadas e 232 surgidas apenas nos últimos 90 dias, o volume de vulnerabilidades associadas ao Red Hat exige monitoramento contínuo. A taxa de exploração ativa está abaixo da média geral do catálogo, com apenas 1 CVE confirmada no CISA KEV — a CVE-2023-4911, que apresenta EPSS de 0,7861, indicando probabilidade elevada de exploração e merecendo atenção prioritária de equipes de resposta. Das 34 vulnerabilidades de severidade crítica, 18 contam com prova de conceito pública disponível, o que reduz a barreira técnica para exploração e aumenta o risco operacional. O tipo de falha mais recorrente é CWE-125 (leitura fora dos limites), padrão que frequentemente viabiliza vazamento de dados ou corrupção de memória e deve orientar revisões de hardening e priorização de patches.

CVE-2019-14876MEDIUMIn the __lshift function of the newlib libc library, all versions prior to 3.3.0 (see newlib/libc/stdlib/mprec.c), Balloc is used to allocatEPSS 1.3%CVE-2019-14877MEDIUMIn the __mdiff function of the newlib libc library, all versions prior to 3.3.0 (see newlib/libc/stdlib/mprec.c), Balloc is used to allocateEPSS 1.3%CVE-2025-12548CRITICALGithub.com/che-incubator/che-code: eclipse che — unauthenticated rce and secret exfiltration via tcp/3333EPSS 1.3%CVE-2024-8176HIGHLibexpat: expat: improper restriction of xml entity expansion depth in libexpatEPSS 1.3%CVE-2026-1584HIGHGnutls: gnutls: remote denial of service via crafted clienthello with invalid psk binderEPSS 1.3%CVE-2019-19337MEDIUMA flaw was found in Red Hat Ceph Storage version 3 in the way the Ceph RADOS Gateway daemon handles S3 requests. An authenticated attacker cEPSS 1.3%CVE-2017-2664MEDIUMCloudForms Management Engine (cfme) before 5.7.3 and 5.8.x before 5.8.1 lacks RBAC controls on certain methods in the rails application portEPSS 1.3%CVE-2023-6134MEDIUMKeycloak: reflected xss via wildcard in oidc redirect_uriEPSS 1.3%CVE-2012-4549MEDIUMJboss enterprise application platform: org.jboss.as.ejb3: jboss enterprise application platform: access restriction bypass via improper ejb method authorizationEPSS 1.3%CVE-2023-3637MEDIUMOpenstack-neutron: unrestricted creation of security groups (fix for cve-2022-3277)EPSS 1.3%CVE-2023-3269HIGHDistros-[dirtyvma] privilege escalation via non-rcu-protected vma traversalEPSS 1.3%CVE-2019-14873MEDIUMIn the __multadd function of the newlib libc library, prior to versions 3.3.0 (see newlib/libc/stdlib/mprec.c), Balloc is used to allocate aEPSS 1.3%CVE-2017-2674MEDIUMJBoss BRMS 6 and BPM Suite 6 before 6.4.3 are vulnerable to a stored XSS via several lists in Business Central. The flaw is due to lack of sEPSS 1.3%CVE-2023-41175MEDIUMLibtiff: potential integer overflow in raw2tiff.cEPSS 1.3%CVE-2025-32988MEDIUMGnutls: vulnerability in gnutls othername san exportEPSS 1.3%CVE-2019-14875MEDIUMIn the __multiply function of the newlib libc library, all versions prior to 3.3.0 (see newlib/libc/stdlib/mprec.c), Balloc is used to allocEPSS 1.3%CVE-2024-12243MEDIUMGnutls: gnutls impacted by inefficient der decoding in libtasn1 leading to remote dosEPSS 1.3%CVE-2025-32989MEDIUMGnutls: vulnerability in gnutls sct extension parsingEPSS 1.3%CVE-2018-10841MEDIUMglusterfs is vulnerable to privilege escalation on gluster server nodes. An authenticated gluster client via TLS could use gluster cli with EPSS 1.3%CVE-2023-1973HIGHUndertow: unrestricted request storage leads to memory exhaustionEPSS 1.3%