Vulnerabilities in Red Hat

1,698 results
Vexday analysis

Com 1.477 CVEs catalogadas e 232 surgidas apenas nos últimos 90 dias, o volume de vulnerabilidades associadas ao Red Hat exige monitoramento contínuo. A taxa de exploração ativa está abaixo da média geral do catálogo, com apenas 1 CVE confirmada no CISA KEV — a CVE-2023-4911, que apresenta EPSS de 0,7861, indicando probabilidade elevada de exploração e merecendo atenção prioritária de equipes de resposta. Das 34 vulnerabilidades de severidade crítica, 18 contam com prova de conceito pública disponível, o que reduz a barreira técnica para exploração e aumenta o risco operacional. O tipo de falha mais recorrente é CWE-125 (leitura fora dos limites), padrão que frequentemente viabiliza vazamento de dados ou corrupção de memória e deve orientar revisões de hardening e priorização de patches.

CVE-2024-6387HIGHOpenssh: regresshion - race condition in ssh allows rce/dosEPSS 99.5%CVE-2018-1111HIGHDHCP packages in Red Hat Enterprise Linux 6 and 7, Fedora 28, and earlier are vulnerable to a command injection flaw in the NetworkManager iEPSS 98.0%CVE-2023-46847HIGHSquid: denial of service in http digest authenticationEPSS 88.4%CVE-2024-3094CRITICALXz: malicious code in distributed sourceEPSS 86.0%CVE-2023-4911HIGHGlibc: buffer overflow in ld.so leading to privilege escalationEPSS 81.4%KEVCVE-2024-12084CRITICALRsync: heap buffer overflow in rsync due to improper checksum length handlingEPSS 72.1%CVE-2023-1183MEDIUMArbitrary file writeEPSS 64.6%CVE-2023-34966HIGHSamba: infinite loop in mdssvc rpc service for spotlightEPSS 62.1%CVE-2023-34967MEDIUMSamba: type confusion in mdssvc rpc service for spotlightEPSS 60.9%CVE-2025-26466MEDIUMOpenssh: denial-of-service in opensshEPSS 39.8%CVE-2025-10230CRITICALSamba: command injection in wins server hook scriptEPSS 39.7%CVE-2024-6409HIGHOpenssh: possible remote code execution due to a race condition in signal handling affecting red hat enterprise linux 9EPSS 27.9%CVE-2019-14901HIGHA heap overflow flaw was found in the Linux kernel, all versions 3.x.x and 4.x.x before 4.18.0, in Marvell WiFi chip driver. The vulnerabiliEPSS 16.9%CVE-2026-4631CRITICALCockpit: cockpit: unauthenticated remote code execution due to ssh command-line argument injectionEPSS 15.5%CVE-2026-4480CRITICALSamba: samba: remote code execution in printing subsystem via unescaped job descriptionEPSS 13.9%CVE-2024-0582HIGHKernel: io_uring: page use-after-free vulnerability via buffer ring mmapEPSS 12.8%CVE-2025-3155HIGHYelp: arbitrary file readEPSS 12.6%CVE-2023-46848HIGHSquid: denial of service in ftpEPSS 10.2%CVE-2023-5178HIGHKernel: use after free in nvmet_tcp_free_crypto in nvmeEPSS 9.1%CVE-2019-14896HIGHA heap-based buffer overflow vulnerability was found in the Linux kernel, version kernel-2.6.32, in Marvell WiFi chip driver. A remote attacEPSS 8.7%