Vulnerabilidades em Red Hat

2.125 resultados
Análise Vexday

Com 1.477 CVEs catalogadas e 232 surgidas apenas nos últimos 90 dias, o volume de vulnerabilidades associadas ao Red Hat exige monitoramento contínuo. A taxa de exploração ativa está abaixo da média geral do catálogo, com apenas 1 CVE confirmada no CISA KEV — a CVE-2023-4911, que apresenta EPSS de 0,7861, indicando probabilidade elevada de exploração e merecendo atenção prioritária de equipes de resposta. Das 34 vulnerabilidades de severidade crítica, 18 contam com prova de conceito pública disponível, o que reduz a barreira técnica para exploração e aumenta o risco operacional. O tipo de falha mais recorrente é CWE-125 (leitura fora dos limites), padrão que frequentemente viabiliza vazamento de dados ou corrupção de memória e deve orientar revisões de hardening e priorização de patches.

CVE-2026-40918MEDIUMGimp: gimp: denial of service via crafted pvr image fileEPSS 0.3%CVE-2026-71462MEDIUMAutomation-controller: automation-controller-container: automation-controller: custom_venv_path setting provides filesystem path-existence oracle on control podEPSS 0.3%CVE-2025-5988MEDIUMAap-gateway: csrf origin checking is disabledEPSS 0.3%CVE-2024-45781MEDIUMGrub2: fs/ufs: oob write in the heapEPSS 0.3%CVE-2020-10744MEDIUMAn incomplete fix was found for the fix of the flaw CVE-2020-1733 ansible: insecure temporary directory when running become_user from becomeEPSS 0.3%CVE-2019-19351HIGHAn insecure modification vulnerability in the /etc/passwd file was found in the container openshift/jenkins. An attacker with access to the EPSS 0.3%CVE-2026-12548MEDIUMLibsoup: heap out-of-bounds read in libsoup due to integer truncationEPSS 0.3%CVE-2023-4641MEDIUMShadow-utils: possible password leak during passwd(1) changeEPSS 0.3%CVE-2026-16615MEDIUMLibrest: weak random number generation in pkce implementationEPSS 0.3%CVE-2024-0562HIGHKernel: use-after-free after removing device in wb_inode_writeback_end in mm/page-writeback.cEPSS 0.3%CVE-2025-0577MEDIUMGlibc: vdso getrandom acceleration may return predictable randomnessEPSS 0.3%CVE-2024-2496MEDIUMLibvirt: null pointer dereference in udevconnectlistallinterfaces()EPSS 0.3%CVE-2026-75886HIGHOpenshift/console: openshift/console: unauthenticated reverse proxy to in-cluster catalogd service with session token forwardingEPSS 0.3%CVE-2023-4132MEDIUMKernel: smsusb: use-after-free caused by do_submit_urb()EPSS 0.3%CVE-2023-4237HIGHPlatform: ec2_key module prints out the private key directly to the standard outputEPSS 0.3%CVE-2026-10118HIGHPoppler: integer overflow in poppler splashoutputdev::tilingpatternfill leads to heap buffer overflow via unchecked dimension multiplicationEPSS 0.3%CVE-2023-4389HIGHKernel: btrfs: double free in btrfs_get_root_ref()EPSS 0.3%CVE-2026-6383MEDIUMKubevirt: kubevirt: unauthorized subresource access due to improper rbac evaluationEPSS 0.3%CVE-2026-18393MEDIUMFfmpeg: ffmpeg: heap buffer overflow in tdsc_load_cursor() via cur_fmt_mono cursorEPSS 0.3%CVE-2023-6176MEDIUMKernel: local dos vulnerability in scatterwalk_copychunksEPSS 0.3%