Vulnerabilidades em Red Hat

2.118 resultados
Análise Vexday

Com 1.477 CVEs catalogadas e 232 surgidas apenas nos últimos 90 dias, o volume de vulnerabilidades associadas ao Red Hat exige monitoramento contínuo. A taxa de exploração ativa está abaixo da média geral do catálogo, com apenas 1 CVE confirmada no CISA KEV — a CVE-2023-4911, que apresenta EPSS de 0,7861, indicando probabilidade elevada de exploração e merecendo atenção prioritária de equipes de resposta. Das 34 vulnerabilidades de severidade crítica, 18 contam com prova de conceito pública disponível, o que reduz a barreira técnica para exploração e aumenta o risco operacional. O tipo de falha mais recorrente é CWE-125 (leitura fora dos limites), padrão que frequentemente viabiliza vazamento de dados ou corrupção de memória e deve orientar revisões de hardening e priorização de patches.

CVE-2023-4001MEDIUMGrub2: bypass the grub password protection featureEPSS 0.5%CVE-2017-15097MEDIUMPrivilege escalation flaws were found in the Red Hat initialization scripts of PostgreSQL. An attacker with access to the postgres user accoEPSS 0.5%CVE-2026-15567HIGHWildfly: wildfly-iiop: wildfly-jacorb: wildfly: pre-auth denial of service on the iiop listenerEPSS 0.5%CVE-2023-4692HIGHGrub2: out-of-bounds write at fs/ntfs.c may lead to unsigned code executionEPSS 0.5%CVE-2025-4574MEDIUMCrossbeam-channel: crossbeam-channel vulnerable to double free on dropEPSS 0.5%CVE-2018-16859MEDIUMExecution of Ansible playbooks on Windows platforms with PowerShell ScriptBlock logging and Module logging enabled can allow for 'become' paEPSS 0.5%CVE-2020-1751MEDIUMAn out-of-bounds write vulnerability was found in glibc before 2.31 when handling signal trampolines on PowerPC. Specifically, the backtraceEPSS 0.5%CVE-2026-15218HIGHModels-as-a-service: red hat openshift ai: maas-api and maas-controller serviceaccounts with excessive permissions lead to privilege escalationEPSS 0.5%CVE-2025-13033HIGHNodemailer: nodemailer: email to an unintended domain can occur due to interpretation conflictEPSS 0.5%CVE-2026-44189HIGHAnsible-lightspeed: visual studio code ansible lightspeed extension: arbitrary code execution via malicious playbook filenameEPSS 0.5%CVE-2025-2586HIGHOls: unauthenticated metrics flooding in openshift lightspeed service leading to resource exhaustionEPSS 0.5%CVE-2026-15562HIGHJboss-remoting: jboss-remoting: integer overflow in messagereader leads to pre-authentication denial of serviceEPSS 0.5%CVE-2010-0737A missing permission check was found in The CLI in JBoss Operations Network before 2.3.1 does not properly check permissions, which allows JEPSS 0.5%CVE-2026-11807CRITICALEda-server: websocket missing authorization allows credential theft via activation_id spoofingEPSS 0.5%CVE-2023-32256HIGHKernel: ksmbd race issue from smb2 close and logoff with multichannelEPSS 0.5%CVE-2025-4373MEDIUMGlib: buffer underflow on glib through glib/gstring.c via function g_string_insert_unicharEPSS 0.5%CVE-2026-85150HIGHGstreamer1-plugins-base: gstreamer: null/invalid-pointer dereference in gst_rtsp_message_parse_auth_credentials() when parsing a crafted digest authorization/www-authenticate headerEPSS 0.5%CVE-2025-5351MEDIUMLibssh: double free vulnerability in libssh key export functionsEPSS 0.5%CVE-2026-92574HIGHCri-o: cri-o checkpoint restore bypasses destination security contextEPSS 0.5%CVE-2024-3049MEDIUMBooth: specially crafted hash can lead to invalid hmac being accepted by booth serverEPSS 0.5%