Vulnerabilidades em Red Hat

2.117 resultados
Análise Vexday

Com 1.477 CVEs catalogadas e 232 surgidas apenas nos últimos 90 dias, o volume de vulnerabilidades associadas ao Red Hat exige monitoramento contínuo. A taxa de exploração ativa está abaixo da média geral do catálogo, com apenas 1 CVE confirmada no CISA KEV — a CVE-2023-4911, que apresenta EPSS de 0,7861, indicando probabilidade elevada de exploração e merecendo atenção prioritária de equipes de resposta. Das 34 vulnerabilidades de severidade crítica, 18 contam com prova de conceito pública disponível, o que reduz a barreira técnica para exploração e aumenta o risco operacional. O tipo de falha mais recorrente é CWE-125 (leitura fora dos limites), padrão que frequentemente viabiliza vazamento de dados ou corrupção de memória e deve orientar revisões de hardening e priorização de patches.

CVE-2026-5136HIGHForeman: foreman: privilege escalation to administrator-level access via usergroup role assignment manipulationEPSS 0.6%CVE-2023-39327MEDIUMOpenjpeg: malicious files can cause the program to enter a large loopEPSS 0.6%CVE-2026-4775HIGHLibtiff: libtiff: arbitrary code execution or denial of service via signed integer overflow in tiff file processingEPSS 0.6%CVE-2024-3447MEDIUMQemu: sdhci: heap buffer overflow in sdhci_write_dataport()EPSS 0.6%CVE-2026-15560HIGHOpenjdk-orb: unauthed class loading via iiop in eapEPSS 0.6%CVE-2026-12856HIGHVscode-java: vscode: command injection vulnerability in the javadoc hover provider of the vscode-java extensionEPSS 0.5%CVE-2026-93568HIGHIo.netty/netty-codec-http2: io.netty/netty-codec-http3: netty: http/2 and http/3 extended connect requests are downgraded as regular connect requestsEPSS 0.5%CVE-2026-15711HIGHLibsoup: soupwebsocketconnection: libsoup: websocket remote denial of service via oversized control frame protocol violationEPSS 0.5%CVE-2023-4956MEDIUMQuay: clickjacking on config-editor page severityEPSS 0.5%CVE-2023-4586HIGHHotrod-client: hot rod client does not enable hostname validation when using tls that lead to a mitm attackEPSS 0.5%CVE-2026-9165HIGHStackrox: stackrox: unbounded graphql query depth allows authenticated denial of serviceEPSS 0.5%CVE-2024-4540HIGHKeycloak: exposure of sensitive information in pushed authorization requests (par) kc_restart cookieEPSS 0.5%CVE-2026-18982HIGHOdh-training-operator-rhel9: rhoai fork aggregates training job create onto native edit/admin clusterrolesEPSS 0.5%CVE-2025-32051MEDIUMLibsoup: segmentation fault when parsing malformed data uriEPSS 0.5%CVE-2024-3056HIGHPodman: kernel: containers in shared ipc namespace are vulnerable to denial of service attackEPSS 0.5%CVE-2026-58016HIGHGlib: integer underflow in gio/gdbusintrospection.c via "g_dbus_node_info_new_for_xml"EPSS 0.5%CVE-2023-5764HIGHAnsible: template injectionEPSS 0.5%CVE-2025-14523HIGHLibsoup: libsoup: duplicate host header handling causes host-parsing discrepancy (first- vs last-value wins)EPSS 0.5%CVE-2025-49521HIGHEvent-driven-ansible: template injection via git branch and refspec in eda projectsEPSS 0.5%CVE-2023-5384HIGHInfinispan: credentials returned from configuration as clear textEPSS 0.5%