Vulnerabilidades em Red Hat

2.125 resultados
Análise Vexday

Com 1.477 CVEs catalogadas e 232 surgidas apenas nos últimos 90 dias, o volume de vulnerabilidades associadas ao Red Hat exige monitoramento contínuo. A taxa de exploração ativa está abaixo da média geral do catálogo, com apenas 1 CVE confirmada no CISA KEV — a CVE-2023-4911, que apresenta EPSS de 0,7861, indicando probabilidade elevada de exploração e merecendo atenção prioritária de equipes de resposta. Das 34 vulnerabilidades de severidade crítica, 18 contam com prova de conceito pública disponível, o que reduz a barreira técnica para exploração e aumenta o risco operacional. O tipo de falha mais recorrente é CWE-125 (leitura fora dos limites), padrão que frequentemente viabiliza vazamento de dados ou corrupção de memória e deve orientar revisões de hardening e priorização de patches.

CVE-2020-10684HIGHA flaw was found in Ansible Engine, all versions 2.7.x, 2.8.x and 2.9.x prior to 2.7.17, 2.8.9 and 2.9.6 respectively, when using ansible_faEPSS 0.3%CVE-2023-25586MEDIUMLocal variable `ch_type` in function `bfd_init_section_decompress_status` can be uninitializedEPSS 0.3%CVE-2026-1484MEDIUMGlib: integer overflow leading to buffer underflow and out-of-bounds write in glib g_base64_encode()EPSS 0.3%CVE-2024-10573MEDIUMMpg123: buffer overflow when writing decoded pcm samplesEPSS 0.3%CVE-2013-0261HIGHPackstack: packstack: arbitrary file overwrite via symlink attackEPSS 0.3%CVE-2026-17615HIGHResteasy-core: resteasy sourceprovider remote unauthenticated file readEPSS 0.3%CVE-2019-10194MEDIUMSensitive passwords used in deployment and configuration of oVirt Metrics, all versions. were found to be insufficiently protected. PasswordEPSS 0.3%CVE-2025-3576MEDIUMKrb5: kerberos rc4-hmac-md5 checksum vulnerability enabling message spoofing via md5 collisionsEPSS 0.3%CVE-2026-16103MEDIUMKeycloak-services: keycloak-services: incomplete fix for ciba brute-force lockout bypass at token redemptionEPSS 0.3%CVE-2026-19278MEDIUMStackrox: stackrox: privilege escalation via unanchored regular expressions in auth m2m role mappingsEPSS 0.3%CVE-2025-14777MEDIUMKeycloak: keycloak idor in realm client creating/deletingEPSS 0.3%CVE-2026-15554HIGHUndertow-core: undertow: authentication bypass via ajp ssl_cert/is_ssl forgeryEPSS 0.3%CVE-2023-3812HIGHKernel: tun: bugs for oversize packet when napi frags enabled in tun_napi_alloc_fragsEPSS 0.3%CVE-2026-92904MEDIUMRubygem-foreman_remote_execution: job output readable without object-level view_job_invocations checkEPSS 0.3%CVE-2023-33951MEDIUMKernel: vmwgfx: race condition leading to information disclosure vulnerabilityEPSS 0.3%CVE-2024-5742MEDIUMNano: running `chmod` and `chown` on the filename allows malicious user to replace the emergency file with a malicious symlink to a root-owned fileEPSS 0.3%CVE-2026-6695MEDIUMGimp: gimp: remote code execution via crafted paa fileEPSS 0.3%CVE-2026-79654MEDIUMKetello: katello content view history api cross-organization authorization bypassEPSS 0.3%CVE-2026-18208MEDIUMKeycloak-services: keycloak-services: inactive out-of-audience token introspection leaks signed jwt claimEPSS 0.3%CVE-2025-4382MEDIUMGrub2: grub allow access to encrypted device through cli once root device is unlocked via tpmEPSS 0.3%