İçeriğe atla
Noroxi

Sudo project kayıtları

sudo project üreticisine ait 24 yayımlanmış kayıt.

Tüm kayıtlar

24 kayıt
  • Sudo before 1.9.5p2 contains an off-by-one error that can result in a heap-based buffer overflow, which allows privilege escalation to root

    YüksekCVSS 7,8KEVSilahlaştırılmışEPSS %100

    sudo project · sudo26 Oca 2021

  • CVE-2025-32463
    79Bu hafta

    Sudo before 1.9.17p1 allows local users to obtain root access because /etc/nsswitch.conf from a user-controlled directory is used with the -

    YüksekCVSS 7,8KEVSilahlaştırılmışEPSS %61

    sudo project · sudo30 Haz 2025

  • CVE-2019-14287
    54Planlayın

    In Sudo before 1.8.28, an attacker with access to a Runas ALL sudoer account can bypass certain policy blacklists and session PAM modules, a

    YüksekCVSS 8,8Kavram kanıtıEPSS %64

    sudo project · sudo17 Eki 2019

  • CVE-2023-22809
    48Planlayın

    In Sudo before 1.9.12p2, the sudoedit (aka -e) feature mishandles extra arguments passed in the user-provided environment variables (SUDO_ED

    YüksekCVSS 7,8SilahlaştırılmışEPSS %55

    sudo project · sudo18 Oca 2023

  • CVE-2019-18634
    37İzleyin

    In Sudo before 1.8.26, if pwfeedback is enabled in /etc/sudoers, users can trigger a stack-based buffer overflow in the privileged sudo proc

    YüksekCVSS 7,8Kavram kanıtıEPSS %19

    sudo project · sudo29 Oca 2020

  • CVE-2025-32462
    36İzleyin

    Sudo before 1.9.17p1, when used with a sudoers file that specifies a host that is neither the current host nor ALL, allows listed users to e

    YüksekCVSS 8,8Kavram kanıtıEPSS %4

    sudo project · sudo30 Haz 2025

  • CVE-2023-7090
    35İzleyin

    Sudo: improper handling of ipa_hostname leads to privilege mismanagement

    YüksekCVSS 8,8İstismar yokEPSS %1

    sudo project · sudo23 Ara 2023

  • Todd Miller's sudo version 1.8.20p1 and earlier is vulnerable to an input validation (embedded newlines) in the get_process_ttyname() functi

    YüksekCVSS 8,2İstismar yokEPSS %1

    sudo project · sudo5 Haz 2017

  • CVE-2002-0184
    31İzleyin

    Sudo before 1.6.6 contains an off-by-one error that can result in a heap-based buffer overflow that may allow local users to gain root privi

    YüksekCVSS 7,8Kavram kanıtıEPSS %1

    sudo project · sudo16 May 2002

  • CVE-2021-23240
    31İzleyin

    selinux_edit_copy_tfiles in sudoedit in Sudo before 1.9.5 allows a local unprivileged user to gain file ownership and escalate privileges by

    YüksekCVSS 7,8İstismar yokEPSS %1

    sudo project · sudo12 Oca 2021

  • CVE-2005-4890
    31İzleyin

    There is a possible tty hijacking in shadow 4.x before 4.1.5 and sudo 1.x before 1.7.4 via "su - user -c program".

    YüksekCVSS 7,8İstismar yokEPSS %1

    debian · shadow4 Kas 2019

  • CVE-2016-7076
    31İzleyin

    sudo before version 1.8.18p1 is vulnerable to a bypass in the sudo noexec restriction if application run via sudo executed wordexp() C libra

    YüksekCVSS 7,8İstismar yokEPSS %0

    sudo project · sudo29 May 2018

  • CVE-2026-35535
    31İzleyin

    In Sudo through 1.9.17p2 before 3e474c2, a failure of a setuid, setgid, or setgroups call, during a privilege drop before running the mailer

    YüksekCVSS 7,8İstismar yokEPSS %0

    sudo project · sudo2 Nis 2026

  • CVE-2023-27320
    28İzleyin

    Sudo before 1.9.13p2 has a double free in the per-command chroot feature.

    YüksekCVSS 7,2İstismar yokEPSS %2

    sudo project · sudo28 Şub 2023

  • CVE-2015-5602
    28İzleyin

    sudoedit in Sudo before 1.8.15 allows local users to gain privileges via a symlink attack on a file whose full path is defined using multipl

    YüksekCVSS 7,2Kavram kanıtıEPSS %1

    sudo project · sudo17 Kas 2015

  • CVE-2015-8239
    28İzleyin

    The SHA-2 digest support in the sudoers plugin in sudo after 1.8.7 allows local users with write permissions to parts of the called command

    YüksekCVSS 7,0Kavram kanıtıEPSS %1

    sudo project · sudo10 Eki 2017

  • CVE-2023-42465
    28İzleyin

    Sudo before 1.9.15 might allow row hammer attacks (for authentication bypass or privilege escalation) because application logic sometimes is

    YüksekCVSS 7,0İstismar yokEPSS %1

    sudo project · sudo22 Ara 2023

  • CVE-2019-18684
    28İzleyin

    Sudo through 1.8.29 allows local users to escalate to root if they have write access to file descriptor 3 of the sudo process.

    YüksekCVSS 7,0İstismar yokEPSS %0

    sudo project · sudo4 Kas 2019

  • CVE-2022-43995
    28İzleyin

    Sudo 1.8.0 through 1.9.12, with the crypt() password backend, contains a plugins/sudoers/auth/passwd.c array-out-of-bounds error that can re

    YüksekCVSS 7,1İstismar yokEPSS %0

    sudo project · sudo2 Kas 2022

  • Todd Miller's sudo version 1.8.20 and earlier is vulnerable to an input validation (embedded spaces) in the get_process_ttyname() function r

    OrtaCVSS 6,4Kavram kanıtıEPSS %8

    sudo project · sudo5 Haz 2017

  • CVE-2023-28487
    21İzleyin

    Sudo before 1.9.13 does not escape control characters in sudoreplay output.

    OrtaCVSS 5,3İstismar yokEPSS %1

    sudo project · sudo15 Mar 2023

  • CVE-2023-28486
    21İzleyin

    Sudo before 1.9.13 does not escape control characters in log messages.

    OrtaCVSS 5,3İstismar yokEPSS %1

    sudo project · sudo15 Mar 2023

  • CVE-2014-9680
    13İzleyin

    sudo before 1.8.12 does not ensure that the TZ environment variable is associated with a zoneinfo file, which allows local users to open arb

    DüşükCVSS 3,3İstismar yokEPSS %0

    sudo project · sudo24 Nis 2017

  • CVE-2021-23239
    10İzleyin

    The sudoedit personality of Sudo before 1.9.5 may allow a local unprivileged user to perform arbitrary directory-existence tests by winning

    DüşükCVSS 2,5İstismar yokEPSS %1

    sudo project · sudo12 Oca 2021