Vulnerabilidades em Red Hat

2.067 resultados
Análise Vexday

Com 1.477 CVEs catalogadas e 232 surgidas apenas nos últimos 90 dias, o volume de vulnerabilidades associadas ao Red Hat exige monitoramento contínuo. A taxa de exploração ativa está abaixo da média geral do catálogo, com apenas 1 CVE confirmada no CISA KEV — a CVE-2023-4911, que apresenta EPSS de 0,7861, indicando probabilidade elevada de exploração e merecendo atenção prioritária de equipes de resposta. Das 34 vulnerabilidades de severidade crítica, 18 contam com prova de conceito pública disponível, o que reduz a barreira técnica para exploração e aumenta o risco operacional. O tipo de falha mais recorrente é CWE-125 (leitura fora dos limites), padrão que frequentemente viabiliza vazamento de dados ou corrupção de memória e deve orientar revisões de hardening e priorização de patches.

CVE-2026-3238HIGHSamba: denial of service against ad dc wins serverEPSS 2.7%CVE-2020-10696HIGHA path traversal flaw was found in Buildah in versions before 1.14.5. This flaw allows an attacker to trick a user into building a maliciousEPSS 2.7%CVE-2024-7885HIGHUndertow: improper state management in proxy protocol parsing causes information leakageEPSS 2.6%CVE-2025-1244HIGHEmacs: shell injection vulnerability in gnu emacs via custom "man" uri schemeEPSS 2.6%CVE-2023-32250CRITICALSession race condition remote code execution vulnerabilityEPSS 2.6%CVE-2020-1714HIGHA flaw was found in Keycloak before version 11.0.0, where the code base contains usages of ObjectInputStream without type checks. This flaw EPSS 2.6%CVE-2018-10926HIGHA flaw was found in RPC request using gfs3_mknod_req supported by glusterfs server. An authenticated attacker could use this flaw to write fEPSS 2.6%CVE-2023-5870LOWPostgresql: role pg_signal_backend can signal certain superuser processes.EPSS 2.6%CVE-2023-32258HIGHSession race condition remote code execution vulnerabilityEPSS 2.5%CVE-2026-4408CRITICALSamba: remote code execution in samrEPSS 2.5%CVE-2016-9578HIGHA vulnerability was discovered in SPICE before 0.13.90 in the server's protocol handling. An attacker able to connect to the SPICE server coEPSS 2.5%CVE-2018-16876LOWansible before versions 2.5.14, 2.6.11, 2.7.5 is vulnerable to a information disclosure flaw in vvv+ mode with no_log on that can lead to leEPSS 2.5%CVE-2019-14812HIGHA flaw was found in all ghostscript versions 9.x before 9.50, in the .setuserparams2 procedure where it did not properly secure its privilegEPSS 2.5%CVE-2016-8614MEDIUMA flaw was found in Ansible before version 2.2.0. The apt_key module does not properly verify key fingerprints, allowing remote adversary toEPSS 2.5%CVE-2017-2582MEDIUMIt was found that while parsing the SAML messages the StaxParserUtil class of keycloak before 2.5.1 replaces special strings for obtaining aEPSS 2.5%CVE-2018-10914MEDIUMIt was found that an attacker could issue a xattr request via glusterfs FUSE to cause gluster brick process to crash which will result in a EPSS 2.4%CVE-2020-10749MEDIUMA vulnerability was found in all versions of containernetworking/plugins before version 0.8.6, that allows malicious containers in KuberneteEPSS 2.4%CVE-2016-0750MEDIUMThe hotrod java client in infinispan before 9.1.0.Final automatically deserializes bytearray message contents in certain events. A maliciousEPSS 2.4%CVE-2023-3961CRITICALSamba: smbd allows client access to unix domain sockets on the file system as rootEPSS 2.4%CVE-2023-32257HIGHSession race condition remote code execution vulnerabilityEPSS 2.4%