Vulnerabilidades em Red Hat

2.125 resultados
Análise Vexday

Com 1.477 CVEs catalogadas e 232 surgidas apenas nos últimos 90 dias, o volume de vulnerabilidades associadas ao Red Hat exige monitoramento contínuo. A taxa de exploração ativa está abaixo da média geral do catálogo, com apenas 1 CVE confirmada no CISA KEV — a CVE-2023-4911, que apresenta EPSS de 0,7861, indicando probabilidade elevada de exploração e merecendo atenção prioritária de equipes de resposta. Das 34 vulnerabilidades de severidade crítica, 18 contam com prova de conceito pública disponível, o que reduz a barreira técnica para exploração e aumenta o risco operacional. O tipo de falha mais recorrente é CWE-125 (leitura fora dos limites), padrão que frequentemente viabiliza vazamento de dados ou corrupção de memória e deve orientar revisões de hardening e priorização de patches.

CVE-2019-19335MEDIUMDuring installation of an OpenShift 4 cluster, the `openshift-install` command line tool creates an `auth` directory, with `kubeconfig` and EPSS 0.3%CVE-2026-90949HIGHGimp: gimp: heap-based buffer overflow in psp loader due to selection-channel geometry mismatchEPSS 0.3%CVE-2026-12726MEDIUMAwx: automation-controller: awx: github webhook second-order ssrf via unvalidated statuses_url exfiltrates pat credentialEPSS 0.3%CVE-2024-45619MEDIUMLibopensc: incorrect handling length of buffers or files in libopenscEPSS 0.3%CVE-2025-25208MEDIUMRhcl: authorino denial of service through authpolicy with sharedsecretref severityEPSS 0.3%CVE-2024-49394MEDIUMMutt: neomutt: in-reply-to email header field it not protected by cryptograpic signingEPSS 0.3%CVE-2024-4693MEDIUMQemu-kvm: virtio-pci: improper release of configure vector leads to guest triggerable crashEPSS 0.3%CVE-2026-58384HIGHGimp: gimp: integer overflow in read_rle_channel()EPSS 0.3%CVE-2026-11873MEDIUMPki-core: dogtag-pki: empty request to dogtag /ca/rest/certrequests causes http 500, java exception, and stacktrace disclosureEPSS 0.3%CVE-2026-58380HIGHGimp: gimp: stack buffer overflow in pnmscanner_gettoken()EPSS 0.3%CVE-2025-49180HIGHXorg-x11-server-xwayland: xorg-x11-server: tigervnc: integer overflow in x resize, rotate and reflect (randr) extensionEPSS 0.3%CVE-2025-6170LOWLibxml2: stack buffer overflow in xmllint interactive shell command handlingEPSS 0.3%CVE-2025-13601HIGHGlib: integer overflow in in g_escape_uri_string()EPSS 0.3%CVE-2023-38472MEDIUMReachable assertion in avahi_rdata_parseEPSS 0.3%CVE-2023-38473MEDIUMReachable assertion in avahi_alternative_host_nameEPSS 0.3%CVE-2023-38469MEDIUMReachable assertion in avahi_dns_packet_append_recordEPSS 0.3%CVE-2026-10579CRITICALPicketlink-federation: auth bypass in picketlink saml unsolicited-responseEPSS 0.3%CVE-2025-4374MEDIUMQuay: incorrect privilege assignmentEPSS 0.3%CVE-2023-38470MEDIUMReachable assertion in avahi_escape_labelEPSS 0.3%CVE-2024-1488HIGHUnbound: unrestricted reconfiguration enabled to anyone that may lead to local privilege escalationEPSS 0.3%