Vulnerabilidades em Red Hat

2.112 resultados
Análise Vexday

Com 1.477 CVEs catalogadas e 232 surgidas apenas nos últimos 90 dias, o volume de vulnerabilidades associadas ao Red Hat exige monitoramento contínuo. A taxa de exploração ativa está abaixo da média geral do catálogo, com apenas 1 CVE confirmada no CISA KEV — a CVE-2023-4911, que apresenta EPSS de 0,7861, indicando probabilidade elevada de exploração e merecendo atenção prioritária de equipes de resposta. Das 34 vulnerabilidades de severidade crítica, 18 contam com prova de conceito pública disponível, o que reduz a barreira técnica para exploração e aumenta o risco operacional. O tipo de falha mais recorrente é CWE-125 (leitura fora dos limites), padrão que frequentemente viabiliza vazamento de dados ou corrupção de memória e deve orientar revisões de hardening e priorização de patches.

CVE-2018-14658MEDIUMA flaw was found in JBOSS Keycloak 3.2.1.Final. The Redirect URL for both Login and Logout are not normalized in org.keycloak.protocol.oidc.EPSS 1.1%CVE-2019-14887HIGHA flaw was found when an OpenSSL security provider is used with Wildfly, the 'enabled-protocols' value in the Wildfly configuration isn't hoEPSS 1.1%CVE-2023-4639HIGHUndertow: cookie smuggling/spoofingEPSS 1.1%CVE-2024-2002HIGHLibdwarf: crashes randomly on fuzzed objectEPSS 1.1%CVE-2025-9566HIGHPodman: podman kube play command may overwrite host filesEPSS 1.1%CVE-2019-14855MEDIUMA flaw was found in the way certificate signatures could be forged using collisions found in the SHA-1 algorithm. An attacker could use thisEPSS 1.1%CVE-2023-39418LOWPostgresql: merge fails to enforce update or select row security policiesEPSS 1.1%CVE-2018-10937MEDIUMA cross site scripting flaw exists in the tetonic-console component of Openshift Container Platform 3.11. An attacker with the ability to crEPSS 1.1%CVE-2023-1194HIGHUse-after-free in parse_lease_state()EPSS 1.1%CVE-2023-6544MEDIUMKeycloak: authorization bypassEPSS 1.1%CVE-2026-5121HIGHLibarchive: libarchive: arbitrary code execution via integer overflow in iso9660 image processingEPSS 1.1%CVE-2026-5201HIGHGdk-pixbuf: gdk-pixbuf: denial of service via heap-based buffer overflow when processing a specially crafted jpeg imageEPSS 1.1%CVE-2024-1300MEDIUMIo.vertx:vertx-core: memory leak when a tcp server is configured with tls and sni supportEPSS 1.1%CVE-2014-3585redhat-upgrade-tool: Does not check GPG signatures when upgrading versionsEPSS 1.1%CVE-2025-6018HIGHPam-config: lpe from unprivileged to allow_active in pamEPSS 1.1%CVE-2026-42010HIGHGnutls: gnutls: authentication bypass via nul character in usernameEPSS 1.1%CVE-2026-23537CRITICALFeast: unauthenticated arbitrary file writeEPSS 1.0%CVE-2023-1193MEDIUMUse-after-free in setup_async_work()EPSS 1.0%CVE-2025-2251MEDIUMOrg.jboss.eap:wildfly-ejb3: improper deserialization in jboss marshalling allows remote code executionEPSS 1.0%CVE-2022-1415HIGHDrools: unsafe data deserialization in streamutilsEPSS 1.0%