Vulnerabilidades em Red Hat

2.067 resultados
Análise Vexday

Com 1.477 CVEs catalogadas e 232 surgidas apenas nos últimos 90 dias, o volume de vulnerabilidades associadas ao Red Hat exige monitoramento contínuo. A taxa de exploração ativa está abaixo da média geral do catálogo, com apenas 1 CVE confirmada no CISA KEV — a CVE-2023-4911, que apresenta EPSS de 0,7861, indicando probabilidade elevada de exploração e merecendo atenção prioritária de equipes de resposta. Das 34 vulnerabilidades de severidade crítica, 18 contam com prova de conceito pública disponível, o que reduz a barreira técnica para exploração e aumenta o risco operacional. O tipo de falha mais recorrente é CWE-125 (leitura fora dos limites), padrão que frequentemente viabiliza vazamento de dados ou corrupção de memória e deve orientar revisões de hardening e priorização de patches.

CVE-2012-5571MEDIUMOpenstack keystone: openstack keystone: authorization bypass via improper ec2 token handlingEPSS 2.1%CVE-2019-14862MEDIUMThere is a vulnerability in knockout before version 3.5.0-beta, where after escaping the context of the web application, the web applicationEPSS 2.1%CVE-2024-3183HIGHFreeipa: user can obtain a hash of the passwords of all domain users and perform offline brute forceEPSS 2.1%CVE-2011-2920MEDIUMSpacewalk: spacewalk: cross-site scripting vulnerability allows arbitrary web script execution.EPSS 2.0%CVE-2024-8698HIGHKeycloak-saml-core: improper verification of saml responses leading to privilege escalation in keycloakEPSS 2.0%CVE-2023-5157HIGHMariadb: node crashes with transport endpoint is not connected mysqld got signal 6EPSS 2.0%CVE-2020-10700MEDIUMA use-after-free flaw was found in the way samba AD DC LDAP servers, handled 'Paged Results' control is combined with the 'ASQ' control. A mEPSS 2.0%CVE-2024-0565MEDIUMKernel: cifs filesystem decryption improper input validation remote code execution vulnerability in function receive_encrypted_standard of clientEPSS 2.0%CVE-2025-4404CRITICALFreeipa: idm: privilege escalation from host to domain admin in freeipaEPSS 2.0%CVE-2020-1695HIGHA flaw was found in all resteasy 3.x.x versions prior to 3.12.0.Final and all resteasy 4.x.x versions prior to 4.6.0.Final, where an impropeEPSS 2.0%CVE-2019-10158MEDIUMA flaw was found in Infinispan through version 9.4.14.Final. An improper implementation of the session fixation protection in the Spring SesEPSS 2.0%CVE-2018-14632HIGHAn out of bound write can occur when patching an Openshift object using the 'oc patch' functionality in OpenShift Container Platform before EPSS 2.0%CVE-2016-8653MEDIUMIt was found that the JMX endpoint of Red Hat JBoss Fuse 6, and Red Hat A-MQ 6 deserializes the credentials passed to it. An attacker could EPSS 1.9%CVE-2023-4813MEDIUMGlibc: potential use-after-free in gaih_inet()EPSS 1.9%CVE-2026-23536HIGHFeast: unauthenticated arbitrary file readEPSS 1.9%CVE-2023-3255MEDIUMQemu: vnc: infinite loop in inflate_buffer() leads to denial of serviceEPSS 1.9%CVE-2019-10135HIGHA flaw was found in the yaml.load() function in the osbs-client versions since 0.46 before 0.56.1. Insecure use of the yaml.load() function EPSS 1.9%CVE-2018-10924MEDIUMIt was discovered that fsync(2) system call in glusterfs client code leaks memory. An authenticated attacker could use this flaw to launch aEPSS 1.9%CVE-2019-14864MEDIUMAnsible, versions 2.9.x before 2.9.1, 2.8.x before 2.8.7 and Ansible versions 2.7.x before 2.7.15, is not respecting the flag no_log set it EPSS 1.9%CVE-2019-10217MEDIUMA flaw was found in ansible 2.8.0 before 2.8.4. Fields managing sensitive data should be set as such by no_log feature. Some of these fieldsEPSS 1.9%