Vulnerabilidades em Red Hat

2.130 resultados
Análise Vexday

Com 1.477 CVEs catalogadas e 232 surgidas apenas nos últimos 90 dias, o volume de vulnerabilidades associadas ao Red Hat exige monitoramento contínuo. A taxa de exploração ativa está abaixo da média geral do catálogo, com apenas 1 CVE confirmada no CISA KEV — a CVE-2023-4911, que apresenta EPSS de 0,7861, indicando probabilidade elevada de exploração e merecendo atenção prioritária de equipes de resposta. Das 34 vulnerabilidades de severidade crítica, 18 contam com prova de conceito pública disponível, o que reduz a barreira técnica para exploração e aumenta o risco operacional. O tipo de falha mais recorrente é CWE-125 (leitura fora dos limites), padrão que frequentemente viabiliza vazamento de dados ou corrupção de memória e deve orientar revisões de hardening e priorização de patches.

CVE-2026-10079HIGHStackrox: stackrox: deploy-time policy enforcement and visibility bypass via label injectionEPSS 0.2%CVE-2026-1784HIGHOse-cluster-ingress-operator: remote code execution through haproxy configuration injectionEPSS 0.2%CVE-2025-12789MEDIUMRhsso: open redirectEPSS 0.2%CVE-2026-81320MEDIUMHawtio-operator: hawtio-operator: tls private key written to operator log at debug levelEPSS 0.2%CVE-2026-90947HIGHGimp: gimp: out-of-bounds write in lighting effects plugin via crafted preset fileEPSS 0.2%CVE-2026-54231MEDIUMAbrt: unsanitized systemd journal content written to dump directory files enables content injectionEPSS 0.2%CVE-2023-1633MEDIUMInsecure barbican configuration file leaking credentialEPSS 0.2%CVE-2025-14104MEDIUMUtil-linux: util-linux: heap buffer overread in setpwnam() when processing 256-byte usernamesEPSS 0.2%CVE-2026-81627HIGHQemu-kvm: vapic writable rom alias can escape the option-rom window and expose locked smramEPSS 0.2%CVE-2025-5915MEDIUMLibarchive: heap buffer over read in copy_from_lzss_window() at archive_read_support_format_rar.cEPSS 0.2%CVE-2025-7519MEDIUMPolkit: xml policy file with a large number of nested elements may lead to out-of-bounds writeEPSS 0.2%CVE-2026-95503MEDIUMKeycloak-services: keycloak-services: potential kdc spoofing bypass when kerberos password authentication is enabledEPSS 0.2%CVE-2026-42170HIGHGimp: gimp dds plug-in heap-based buffer overflow via bpp mismatch in load_layer() (ddsread.c)EPSS 0.2%CVE-2026-81666MEDIUMCorosync: corosync: integer overflow in check_memb_commit_token_sanity may bypass message length validation on 32-bit systemsEPSS 0.2%CVE-2026-3442MEDIUMBinutils: gnu binutils: information disclosure or denial of service via out-of-bounds read in bfd linkerEPSS 0.2%CVE-2026-42169HIGHGimp: gimp apng loader heap-buffer-overflow when fctl width exceeds ihdr width (file-png.c)EPSS 0.2%CVE-2026-3441MEDIUMBinutils: gnu binutils: information disclosure via specially crafted xcoff object fileEPSS 0.2%CVE-2026-34001HIGHXorg: xwayland: x.org x server: use-after-free vulnerability leads to server crash and potential memory corruptionEPSS 0.2%CVE-2026-43958HIGHRrdtool: rrdtool: stack buffer overflow allows local code execution or denial of serviceEPSS 0.2%CVE-2025-57848MEDIUMContainer-native-virtualization: privilege escalation via excessive /etc/passwd permissionsEPSS 0.2%