Sudo project kayıtları
sudo project üreticisine ait 24 yayımlanmış kayıt.
Araştırmacı profili
- KEV’e giren
- 2 · %8,3
- Silahlaştırılmış
- 3 · %12,5
- Pre-auth RCE
- 0
- Düzeltme kaydı olan
- %91,7
- Yayından KEV’e ortanca
- 263 gün
Tekrar eden sınıflar
- CWE-362 Concurrent Execution using Shared Resource with Improper Synchronization ('Race Condition')3
- CWE-116 Improper Encoding or Escaping of Output2
- CWE-269 Improper Privilege Management2
- CWE-59 Improper Link Resolution Before File Access ('Link Following')2
- CWE-20 Improper Input Validation2
- CWE-200 Exposure of Sensitive Information to an Unauthorized Actor1
Bu üreticide en sık görülen zafiyet sınıfları: nereye bakmalı.
CWETüm kayıtlar
24 kayıt| Aksiyon | CVE | Zafiyet | Ciddiyet | KEV | EPSS | Yayın |
|---|---|---|---|---|---|---|
91Hemen | CVE-2021-3156Silahlaştırılmış | Sudo before 1.9.5p2 contains an off-by-one error that can result in a heap-based buffer overflow, which allows privilege escalation to root sudo project · sudo · CWE-193 | Yüksek7,8 | KEV | %100,0 | 26 Oca 2021 |
79Bu hafta | CVE-2025-32463Silahlaştırılmış | Sudo before 1.9.17p1 allows local users to obtain root access because /etc/nsswitch.conf from a user-controlled directory is used with the -sudo project · sudo · CWE-829 | Yüksek7,8 | KEV | %61,0 | 30 Haz 2025 |
54Planlayın | CVE-2019-14287Kavram kanıtı | In Sudo before 1.8.28, an attacker with access to a Runas ALL sudoer account can bypass certain policy blacklists and session PAM modules, asudo project · sudo · CWE-755 | Yüksek8,8 | — | %63,8 | 17 Eki 2019 |
48Planlayın | CVE-2023-22809Silahlaştırılmış | In Sudo before 1.9.12p2, the sudoedit (aka -e) feature mishandles extra arguments passed in the user-provided environment variables (SUDO_EDsudo project · sudo · CWE-269 | Yüksek7,8 | — | %55,4 | 18 Oca 2023 |
37İzleyin | CVE-2019-18634Kavram kanıtı | In Sudo before 1.8.26, if pwfeedback is enabled in /etc/sudoers, users can trigger a stack-based buffer overflow in the privileged sudo procsudo project · sudo · CWE-787 | Yüksek7,8 | — | %19,4 | 29 Oca 2020 |
36İzleyin | CVE-2025-32462Kavram kanıtı | Sudo before 1.9.17p1, when used with a sudoers file that specifies a host that is neither the current host nor ALL, allows listed users to esudo project · sudo · CWE-863 | Yüksek8,8 | — | %4,4 | 30 Haz 2025 |
35İzleyin | CVE-2023-7090İstismar yok | Sudo: improper handling of ipa_hostname leads to privilege mismanagementsudo project · sudo · CWE-269 | Yüksek8,8 | — | %0,7 | 23 Ara 2023 |
32İzleyin | CVE-2017-1000368İstismar yok | Todd Miller's sudo version 1.8.20p1 and earlier is vulnerable to an input validation (embedded newlines) in the get_process_ttyname() functisudo project · sudo · CWE-20 | Yüksek8,2 | — | %0,6 | 5 Haz 2017 |
31İzleyin | CVE-2002-0184Kavram kanıtı | Sudo before 1.6.6 contains an off-by-one error that can result in a heap-based buffer overflow that may allow local users to gain root privisudo project · sudo · CWE-131 | Yüksek7,8 | — | %1,2 | 16 May 2002 |
31İzleyin | CVE-2021-23240İstismar yok | selinux_edit_copy_tfiles in sudoedit in Sudo before 1.9.5 allows a local unprivileged user to gain file ownership and escalate privileges bysudo project · sudo · CWE-59 | Yüksek7,8 | — | %1,1 | 12 Oca 2021 |
31İzleyin | CVE-2005-4890İstismar yok | There is a possible tty hijacking in shadow 4.x before 4.1.5 and sudo 1.x before 1.7.4 via "su - user -c program".debian · shadow · CWE-20 | Yüksek7,8 | — | %0,6 | 4 Kas 2019 |
31İzleyin | CVE-2016-7076İstismar yok | sudo before version 1.8.18p1 is vulnerable to a bypass in the sudo noexec restriction if application run via sudo executed wordexp() C librasudo project · sudo · CWE-184 | Yüksek7,8 | — | %0,5 | 29 May 2018 |
31İzleyin | CVE-2026-35535İstismar yok | In Sudo through 1.9.17p2 before 3e474c2, a failure of a setuid, setgid, or setgroups call, during a privilege drop before running the mailersudo project · sudo · CWE-271 | Yüksek7,8 | — | %0,2 | 2 Nis 2026 |
28İzleyin | CVE-2023-27320İstismar yok | Sudo before 1.9.13p2 has a double free in the per-command chroot feature.sudo project · sudo · CWE-415 | Yüksek7,2 | — | %1,7 | 28 Şub 2023 |
28İzleyin | CVE-2015-5602Kavram kanıtı | sudoedit in Sudo before 1.8.15 allows local users to gain privileges via a symlink attack on a file whose full path is defined using multiplsudo project · sudo · CWE-264 | Yüksek7,2 | — | %1,5 | 17 Kas 2015 |
28İzleyin | CVE-2015-8239Kavram kanıtı | The SHA-2 digest support in the sudoers plugin in sudo after 1.8.7 allows local users with write permissions to parts of the called command sudo project · sudo · CWE-362 | Yüksek7,0 | — | %0,5 | 10 Eki 2017 |
28İzleyin | CVE-2023-42465İstismar yok | Sudo before 1.9.15 might allow row hammer attacks (for authentication bypass or privilege escalation) because application logic sometimes issudo project · sudo | Yüksek7,0 | — | %0,5 | 22 Ara 2023 |
28İzleyin | CVE-2019-18684İstismar yok | Sudo through 1.8.29 allows local users to escalate to root if they have write access to file descriptor 3 of the sudo process.sudo project · sudo · CWE-362 | Yüksek7,0 | — | %0,3 | 4 Kas 2019 |
28İzleyin | CVE-2022-43995İstismar yok | Sudo 1.8.0 through 1.9.12, with the crypt() password backend, contains a plugins/sudoers/auth/passwd.c array-out-of-bounds error that can resudo project · sudo · CWE-125 | Yüksek7,1 | — | %0,3 | 2 Kas 2022 |
27İzleyin | CVE-2017-1000367Kavram kanıtı | Todd Miller's sudo version 1.8.20 and earlier is vulnerable to an input validation (embedded spaces) in the get_process_ttyname() function rsudo project · sudo · CWE-362 | Orta6,4 | — | %8,0 | 5 Haz 2017 |
21İzleyin | CVE-2023-28487İstismar yok | Sudo before 1.9.13 does not escape control characters in sudoreplay output.sudo project · sudo · CWE-116 | Orta5,3 | — | %1,0 | 15 Mar 2023 |
21İzleyin | CVE-2023-28486İstismar yok | Sudo before 1.9.13 does not escape control characters in log messages.sudo project · sudo · CWE-116 | Orta5,3 | — | %0,9 | 15 Mar 2023 |
13İzleyin | CVE-2014-9680İstismar yok | sudo before 1.8.12 does not ensure that the TZ environment variable is associated with a zoneinfo file, which allows local users to open arbsudo project · sudo · CWE-200 | Düşük3,3 | — | %0,5 | 24 Nis 2017 |
10İzleyin | CVE-2021-23239İstismar yok | The sudoedit personality of Sudo before 1.9.5 may allow a local unprivileged user to perform arbitrary directory-existence tests by winning sudo project · sudo · CWE-59 | Düşük2,5 | — | %1,0 | 12 Oca 2021 |
- CVE-2021-315691Hemen
Sudo before 1.9.5p2 contains an off-by-one error that can result in a heap-based buffer overflow, which allows privilege escalation to root
YüksekCVSS 7,8KEVSilahlaştırılmışEPSS %100sudo project · sudo26 Oca 2021
- CVE-2025-3246379Bu hafta
Sudo before 1.9.17p1 allows local users to obtain root access because /etc/nsswitch.conf from a user-controlled directory is used with the -
YüksekCVSS 7,8KEVSilahlaştırılmışEPSS %61sudo project · sudo30 Haz 2025
- CVE-2019-1428754Planlayın
In Sudo before 1.8.28, an attacker with access to a Runas ALL sudoer account can bypass certain policy blacklists and session PAM modules, a
YüksekCVSS 8,8Kavram kanıtıEPSS %64sudo project · sudo17 Eki 2019
- CVE-2023-2280948Planlayın
In Sudo before 1.9.12p2, the sudoedit (aka -e) feature mishandles extra arguments passed in the user-provided environment variables (SUDO_ED
YüksekCVSS 7,8SilahlaştırılmışEPSS %55sudo project · sudo18 Oca 2023
- CVE-2019-1863437İzleyin
In Sudo before 1.8.26, if pwfeedback is enabled in /etc/sudoers, users can trigger a stack-based buffer overflow in the privileged sudo proc
YüksekCVSS 7,8Kavram kanıtıEPSS %19sudo project · sudo29 Oca 2020
- CVE-2025-3246236İzleyin
Sudo before 1.9.17p1, when used with a sudoers file that specifies a host that is neither the current host nor ALL, allows listed users to e
YüksekCVSS 8,8Kavram kanıtıEPSS %4sudo project · sudo30 Haz 2025
- CVE-2023-709035İzleyin
Sudo: improper handling of ipa_hostname leads to privilege mismanagement
YüksekCVSS 8,8İstismar yokEPSS %1sudo project · sudo23 Ara 2023
- CVE-2017-100036832İzleyin
Todd Miller's sudo version 1.8.20p1 and earlier is vulnerable to an input validation (embedded newlines) in the get_process_ttyname() functi
YüksekCVSS 8,2İstismar yokEPSS %1sudo project · sudo5 Haz 2017
- CVE-2002-018431İzleyin
Sudo before 1.6.6 contains an off-by-one error that can result in a heap-based buffer overflow that may allow local users to gain root privi
YüksekCVSS 7,8Kavram kanıtıEPSS %1sudo project · sudo16 May 2002
- CVE-2021-2324031İzleyin
selinux_edit_copy_tfiles in sudoedit in Sudo before 1.9.5 allows a local unprivileged user to gain file ownership and escalate privileges by
YüksekCVSS 7,8İstismar yokEPSS %1sudo project · sudo12 Oca 2021
- CVE-2005-489031İzleyin
There is a possible tty hijacking in shadow 4.x before 4.1.5 and sudo 1.x before 1.7.4 via "su - user -c program".
YüksekCVSS 7,8İstismar yokEPSS %1debian · shadow4 Kas 2019
- CVE-2016-707631İzleyin
sudo before version 1.8.18p1 is vulnerable to a bypass in the sudo noexec restriction if application run via sudo executed wordexp() C libra
YüksekCVSS 7,8İstismar yokEPSS %0sudo project · sudo29 May 2018
- CVE-2026-3553531İzleyin
In Sudo through 1.9.17p2 before 3e474c2, a failure of a setuid, setgid, or setgroups call, during a privilege drop before running the mailer
YüksekCVSS 7,8İstismar yokEPSS %0sudo project · sudo2 Nis 2026
- CVE-2023-2732028İzleyin
Sudo before 1.9.13p2 has a double free in the per-command chroot feature.
YüksekCVSS 7,2İstismar yokEPSS %2sudo project · sudo28 Şub 2023
- CVE-2015-560228İzleyin
sudoedit in Sudo before 1.8.15 allows local users to gain privileges via a symlink attack on a file whose full path is defined using multipl
YüksekCVSS 7,2Kavram kanıtıEPSS %1sudo project · sudo17 Kas 2015
- CVE-2015-823928İzleyin
The SHA-2 digest support in the sudoers plugin in sudo after 1.8.7 allows local users with write permissions to parts of the called command
YüksekCVSS 7,0Kavram kanıtıEPSS %1sudo project · sudo10 Eki 2017
- CVE-2023-4246528İzleyin
Sudo before 1.9.15 might allow row hammer attacks (for authentication bypass or privilege escalation) because application logic sometimes is
YüksekCVSS 7,0İstismar yokEPSS %1sudo project · sudo22 Ara 2023
- CVE-2019-1868428İzleyin
Sudo through 1.8.29 allows local users to escalate to root if they have write access to file descriptor 3 of the sudo process.
YüksekCVSS 7,0İstismar yokEPSS %0sudo project · sudo4 Kas 2019
- CVE-2022-4399528İzleyin
Sudo 1.8.0 through 1.9.12, with the crypt() password backend, contains a plugins/sudoers/auth/passwd.c array-out-of-bounds error that can re
YüksekCVSS 7,1İstismar yokEPSS %0sudo project · sudo2 Kas 2022
- CVE-2017-100036727İzleyin
Todd Miller's sudo version 1.8.20 and earlier is vulnerable to an input validation (embedded spaces) in the get_process_ttyname() function r
OrtaCVSS 6,4Kavram kanıtıEPSS %8sudo project · sudo5 Haz 2017
- CVE-2023-2848721İzleyin
Sudo before 1.9.13 does not escape control characters in sudoreplay output.
OrtaCVSS 5,3İstismar yokEPSS %1sudo project · sudo15 Mar 2023
- CVE-2023-2848621İzleyin
Sudo before 1.9.13 does not escape control characters in log messages.
OrtaCVSS 5,3İstismar yokEPSS %1sudo project · sudo15 Mar 2023
- CVE-2014-968013İzleyin
sudo before 1.8.12 does not ensure that the TZ environment variable is associated with a zoneinfo file, which allows local users to open arb
DüşükCVSS 3,3İstismar yokEPSS %0sudo project · sudo24 Nis 2017
- CVE-2021-2323910İzleyin
The sudoedit personality of Sudo before 1.9.5 may allow a local unprivileged user to perform arbitrary directory-existence tests by winning
DüşükCVSS 2,5İstismar yokEPSS %1sudo project · sudo12 Oca 2021