Vulnerabilidades em Red Hat

2.125 resultados
Análise Vexday

Com 1.477 CVEs catalogadas e 232 surgidas apenas nos últimos 90 dias, o volume de vulnerabilidades associadas ao Red Hat exige monitoramento contínuo. A taxa de exploração ativa está abaixo da média geral do catálogo, com apenas 1 CVE confirmada no CISA KEV — a CVE-2023-4911, que apresenta EPSS de 0,7861, indicando probabilidade elevada de exploração e merecendo atenção prioritária de equipes de resposta. Das 34 vulnerabilidades de severidade crítica, 18 contam com prova de conceito pública disponível, o que reduz a barreira técnica para exploração e aumenta o risco operacional. O tipo de falha mais recorrente é CWE-125 (leitura fora dos limites), padrão que frequentemente viabiliza vazamento de dados ou corrupção de memória e deve orientar revisões de hardening e priorização de patches.

CVE-2026-9799MEDIUMKeycloak: keycloak: unauthorized access to resources via uma permission ticket bypassEPSS 0.3%CVE-2024-45778MEDIUMGrub2: fs/bfs: integer overflow in the bfs parser.EPSS 0.3%CVE-2026-83596HIGHWebkitgtk: validate the full featurelist array once in opentypeverticaldata findfeatureEPSS 0.3%CVE-2026-93578MEDIUMIo.netty/netty-handler-ssl-ocsp: netty: missing extended key usage (eku) check in ocsp client allows certificate revocation bypassEPSS 0.3%CVE-2026-84714HIGHAutomation-controller: automation-controller: incomplete sanitize_jinja() regex allows jinja template injection into ad-hoc module_args, machine-credential fields, and host names, reaching ansible-core templating in the execution environmentEPSS 0.3%CVE-2020-10737MEDIUMA race condition was found in the mkhomedir tool shipped with the oddjob package in versions before 0.34.5 and 0.34.6 wherein, during the hoEPSS 0.3%CVE-2023-3106MEDIUMKernel: netlink socket crash (null pointer deref) in netlink_dump functionEPSS 0.3%CVE-2022-3261MEDIUMPlain-text passwords saved in /var/log/messagesEPSS 0.3%CVE-2026-80185MEDIUMBluez: sdp-xml: bluez 5.86: unprivileged-local and adjacent-le-peer leads to arbitrary code execution as rootEPSS 0.3%CVE-2023-0657LOWKeycloak: impersonation via logout token exchangeEPSS 0.3%CVE-2026-93561MEDIUMIo.netty/netty-codec-memcache: netty: memcache binary codec signed/unsigned type mismatch causes frame desynchronization and response smugglingEPSS 0.3%CVE-2024-45775MEDIUMGrub2: commands/extcmd: missing check for failed allocationEPSS 0.3%CVE-2024-45779MEDIUMGrub2: fs/bfs: integer overflow leads to heap oob read in the bfs parserEPSS 0.3%CVE-2026-74240MEDIUMQuay: jwt claim validation bypasses in quay federated robot and sso authenticationEPSS 0.3%CVE-2026-11790MEDIUM389-ds-base: 389-ds-base: pbkdf2 password storage plugin unbounded iteration count denial of serviceEPSS 0.3%CVE-2019-14886MEDIUMA vulnerability was found in business-central, as shipped in rhdm-7.5.1 and rhpam-7.5.1, where encoded passwords are stored in errai_securitEPSS 0.3%CVE-2019-3875MEDIUMA vulnerability was found in keycloak before 6.0.2. The X.509 authenticator supports the verification of client certificates through the CRLEPSS 0.3%CVE-2026-84724MEDIUMAutomation-controller: automation-controller: systemjob extra_vars.days argument injection into uncontainerized control-plane awx-manage processEPSS 0.3%CVE-2023-6238MEDIUMKernel: nvme: memory corruption via unprivileged user passthroughEPSS 0.3%CVE-2022-4318HIGHCri-o: /etc/passwd tampering privescEPSS 0.3%