Vulnerabilidades em Red Hat

2.068 resultados
Análise Vexday

Com 1.477 CVEs catalogadas e 232 surgidas apenas nos últimos 90 dias, o volume de vulnerabilidades associadas ao Red Hat exige monitoramento contínuo. A taxa de exploração ativa está abaixo da média geral do catálogo, com apenas 1 CVE confirmada no CISA KEV — a CVE-2023-4911, que apresenta EPSS de 0,7861, indicando probabilidade elevada de exploração e merecendo atenção prioritária de equipes de resposta. Das 34 vulnerabilidades de severidade crítica, 18 contam com prova de conceito pública disponível, o que reduz a barreira técnica para exploração e aumenta o risco operacional. O tipo de falha mais recorrente é CWE-125 (leitura fora dos limites), padrão que frequentemente viabiliza vazamento de dados ou corrupção de memória e deve orientar revisões de hardening e priorização de patches.

CVE-2022-2127MEDIUMSamba: out-of-bounds read in winbind auth_crapEPSS 1.7%CVE-2019-14837CRITICALA flaw was found in keycloack before version 8.0.0. The owner of 'placeholder.org' domain can setup mail server on this domain and knowing oEPSS 1.7%CVE-2025-5318MEDIUMLibssh: out-of-bounds read in sftp_handle()EPSS 1.7%CVE-2024-1459MEDIUMUndertow: directory traversal vulnerabilityEPSS 1.7%CVE-2017-12148HIGHA flaw was found in Ansible Tower's interface before 3.1.5 and 3.2.0 with SCM repositories. If a Tower project (SCM repository) definition dEPSS 1.7%CVE-2017-7530HIGHIn CloudForms Management Engine (cfme) before 5.7.3 and 5.8.x before 5.8.1, it was found that privilege check is missing when invoking arbitEPSS 1.7%CVE-2024-6162HIGHUndertow: url-encoded request path information can be broken on ajp-listenerEPSS 1.7%CVE-2016-8609LOWIt was found that the keycloak before 2.3.0 did not implement authentication flow correctly. An attacker could use this flaw to construct a EPSS 1.7%CVE-2023-39417HIGHPostgresql: extension script @substitutions@ within quoting allow sql injectionEPSS 1.7%CVE-2017-3139A denial of service flaw was found in the way BIND handled DNSSEC validation. A remote attacker could use this flaw to make named exit unexpEPSS 1.7%CVE-2018-10923HIGHIt was found that the "mknod" call derived from mknod(2) can create files pointing to devices on a glusterfs server node. An authenticated aEPSS 1.7%CVE-2023-4527MEDIUMGlibc: stack read overflow in getaddrinfo in no-aaaa modeEPSS 1.7%CVE-2023-6121MEDIUMKernel: nvme: info leak due to out-of-bounds read in nvmet_ctrl_find_getEPSS 1.7%CVE-2024-1023MEDIUMIo.vertx/vertx-core: memory leak due to the use of netty fastthreadlocal data structures in vertxEPSS 1.7%CVE-2012-0059MEDIUMSpacewalk-backend: spacewalk-backend: information disclosure via cleartext passwords in error messagesEPSS 1.6%CVE-2020-10753MEDIUMA flaw was found in the Red Hat Ceph Storage RadosGW (Ceph Object Gateway). The vulnerability is related to the injection of HTTP headers viEPSS 1.6%CVE-2023-6478HIGHXorg-x11-server: out-of-bounds memory read in rrchangeoutputproperty and rrchangeproviderpropertyEPSS 1.6%CVE-2024-0553HIGHGnutls: incomplete fix for cve-2023-5981EPSS 1.6%CVE-2023-3354HIGHImproper i/o watch removal in tls handshake can lead to remote unauthenticated denial of serviceEPSS 1.6%CVE-2023-4806MEDIUMGlibc: potential use-after-free in getaddrinfo()EPSS 1.6%