Vulnerabilidades em Red Hat

2.125 resultados
Análise Vexday

Com 1.477 CVEs catalogadas e 232 surgidas apenas nos últimos 90 dias, o volume de vulnerabilidades associadas ao Red Hat exige monitoramento contínuo. A taxa de exploração ativa está abaixo da média geral do catálogo, com apenas 1 CVE confirmada no CISA KEV — a CVE-2023-4911, que apresenta EPSS de 0,7861, indicando probabilidade elevada de exploração e merecendo atenção prioritária de equipes de resposta. Das 34 vulnerabilidades de severidade crítica, 18 contam com prova de conceito pública disponível, o que reduz a barreira técnica para exploração e aumenta o risco operacional. O tipo de falha mais recorrente é CWE-125 (leitura fora dos limites), padrão que frequentemente viabiliza vazamento de dados ou corrupção de memória e deve orientar revisões de hardening e priorização de patches.

CVE-2025-5918LOWLibarchive: reading past eof may be triggered for piped file streamsEPSS 0.4%CVE-2023-43788MEDIUMLibxpm: out of bounds read in xpmcreatexpmimagefrombuffer()EPSS 0.4%CVE-2024-2494MEDIUMLibvirt: negative g_new0 length can lead to unbounded memory allocationEPSS 0.4%CVE-2022-4900MEDIUMPotential buffer overflow in php_cli_server_startup_workersEPSS 0.4%CVE-2026-53701MEDIUMGstreamer1-plugins-bad-free: gstreamer: out-of-bounds write in h.266/vvc pps picture partition parserEPSS 0.4%CVE-2026-1467MEDIUMLibsoup: libsoup: http header injection via specially crafted urls when an http proxy is configuredEPSS 0.4%CVE-2017-2663HIGHIt was found that subscription-manager's DBus interface before 1.19.4 let unprivileged user access the com.redhat.RHSM1.Facts.GetFacts and cEPSS 0.4%CVE-2026-4633LOWKeycloak: keycloak: user enumeration via differential error messagesEPSS 0.4%CVE-2024-11218HIGHPodman: buildah: container breakout by using --jobs=2 and a race condition when building a malicious containerfileEPSS 0.4%CVE-2020-1737HIGHA flaw was found in Ansible 2.7.17 and prior, 2.8.9 and prior, and 2.9.6 and prior when using the Extract-Zip function from the win_unzip moEPSS 0.4%CVE-2026-75887HIGHOpenshift/console: openshift/console: unauthenticated path traversal in i18n locale handlerEPSS 0.4%CVE-2026-66782MEDIUMSubmariner-operator: operator clusterrole grants cluster-wide create/update on all configmapsEPSS 0.4%CVE-2026-95619HIGHGcc: libstdc++ integer overflow in `new` operatorEPSS 0.4%CVE-2025-2786MEDIUMTempo-operator: serviceaccount token exposure leading to token and subject access reviews in openshift tempo operatorEPSS 0.4%CVE-2026-16529HIGHPcp: pcp: denial of service due to signed integer overflowEPSS 0.4%CVE-2020-1739LOWA flaw was found in Ansible 2.7.16 and prior, 2.8.8 and prior, and 2.9.5 and prior when a password is set with the argument "password" of svEPSS 0.4%CVE-2024-7079MEDIUMOpenshift-console: unauthenticated installation of helm chartsEPSS 0.4%CVE-2026-96275HIGHFlatpak: flatpak: arbitrary write access as root via extra-data extractionEPSS 0.4%CVE-2020-10691MEDIUMAn archive traversal flaw was found in all ansible-engine versions 2.9.x prior to 2.9.7, when running ansible-galaxy collection install. WheEPSS 0.4%CVE-2023-38253MEDIUMW3m: out of bounds read in growbuf_to_str() at w3m/indep.cEPSS 0.4%