Sudo project records
24 published records for vendor sudo project.
Researcher profile
- Entered KEV
- 2 · 8.3%
- Weaponized
- 3 · 12.5%
- Pre-auth RCE
- 0
- With a fix record
- 91.7%
- Median publish → KEV
- 263 days
Recurring classes
- CWE-362 Concurrent Execution using Shared Resource with Improper Synchronization ('Race Condition')3
- CWE-116 Improper Encoding or Escaping of Output2
- CWE-269 Improper Privilege Management2
- CWE-59 Improper Link Resolution Before File Access ('Link Following')2
- CWE-20 Improper Input Validation2
- CWE-200 Exposure of Sensitive Information to an Unauthorized Actor1
The weakness classes this vendor ships most often: where to look.
CWEAll records
24 records| Action | CVE | Vulnerability | Severity | KEV | EPSS | Published |
|---|---|---|---|---|---|---|
91Now | CVE-2021-3156Weaponized | Sudo before 1.9.5p2 contains an off-by-one error that can result in a heap-based buffer overflow, which allows privilege escalation to root sudo project · sudo · CWE-193 | High7.8 | KEV | 100.0% | Jan 26, 2021 |
79This week | CVE-2025-32463Weaponized | Sudo before 1.9.17p1 allows local users to obtain root access because /etc/nsswitch.conf from a user-controlled directory is used with the -sudo project · sudo · CWE-829 | High7.8 | KEV | 61.0% | Jun 30, 2025 |
54Plan | CVE-2019-14287Proof of concept | In Sudo before 1.8.28, an attacker with access to a Runas ALL sudoer account can bypass certain policy blacklists and session PAM modules, asudo project · sudo · CWE-755 | High8.8 | — | 63.8% | Oct 17, 2019 |
48Plan | CVE-2023-22809Weaponized | In Sudo before 1.9.12p2, the sudoedit (aka -e) feature mishandles extra arguments passed in the user-provided environment variables (SUDO_EDsudo project · sudo · CWE-269 | High7.8 | — | 55.4% | Jan 18, 2023 |
37Monitor | CVE-2019-18634Proof of concept | In Sudo before 1.8.26, if pwfeedback is enabled in /etc/sudoers, users can trigger a stack-based buffer overflow in the privileged sudo procsudo project · sudo · CWE-787 | High7.8 | — | 19.4% | Jan 29, 2020 |
36Monitor | CVE-2025-32462Proof of concept | Sudo before 1.9.17p1, when used with a sudoers file that specifies a host that is neither the current host nor ALL, allows listed users to esudo project · sudo · CWE-863 | High8.8 | — | 4.4% | Jun 30, 2025 |
35Monitor | CVE-2023-7090No exploit | Sudo: improper handling of ipa_hostname leads to privilege mismanagementsudo project · sudo · CWE-269 | High8.8 | — | 0.7% | Dec 23, 2023 |
32Monitor | CVE-2017-1000368No exploit | Todd Miller's sudo version 1.8.20p1 and earlier is vulnerable to an input validation (embedded newlines) in the get_process_ttyname() functisudo project · sudo · CWE-20 | High8.2 | — | 0.6% | Jun 5, 2017 |
31Monitor | CVE-2002-0184Proof of concept | Sudo before 1.6.6 contains an off-by-one error that can result in a heap-based buffer overflow that may allow local users to gain root privisudo project · sudo · CWE-131 | High7.8 | — | 1.2% | May 16, 2002 |
31Monitor | CVE-2021-23240No exploit | selinux_edit_copy_tfiles in sudoedit in Sudo before 1.9.5 allows a local unprivileged user to gain file ownership and escalate privileges bysudo project · sudo · CWE-59 | High7.8 | — | 1.1% | Jan 12, 2021 |
31Monitor | CVE-2005-4890No exploit | There is a possible tty hijacking in shadow 4.x before 4.1.5 and sudo 1.x before 1.7.4 via "su - user -c program".debian · shadow · CWE-20 | High7.8 | — | 0.6% | Nov 4, 2019 |
31Monitor | CVE-2016-7076No exploit | sudo before version 1.8.18p1 is vulnerable to a bypass in the sudo noexec restriction if application run via sudo executed wordexp() C librasudo project · sudo · CWE-184 | High7.8 | — | 0.5% | May 29, 2018 |
31Monitor | CVE-2026-35535No exploit | In Sudo through 1.9.17p2 before 3e474c2, a failure of a setuid, setgid, or setgroups call, during a privilege drop before running the mailersudo project · sudo · CWE-271 | High7.8 | — | 0.2% | Apr 2, 2026 |
28Monitor | CVE-2023-27320No exploit | Sudo before 1.9.13p2 has a double free in the per-command chroot feature.sudo project · sudo · CWE-415 | High7.2 | — | 1.7% | Feb 28, 2023 |
28Monitor | CVE-2015-5602Proof of concept | sudoedit in Sudo before 1.8.15 allows local users to gain privileges via a symlink attack on a file whose full path is defined using multiplsudo project · sudo · CWE-264 | High7.2 | — | 1.5% | Nov 17, 2015 |
28Monitor | CVE-2015-8239Proof of concept | The SHA-2 digest support in the sudoers plugin in sudo after 1.8.7 allows local users with write permissions to parts of the called command sudo project · sudo · CWE-362 | High7.0 | — | 0.5% | Oct 10, 2017 |
28Monitor | CVE-2023-42465No exploit | Sudo before 1.9.15 might allow row hammer attacks (for authentication bypass or privilege escalation) because application logic sometimes issudo project · sudo | High7.0 | — | 0.5% | Dec 22, 2023 |
28Monitor | CVE-2019-18684No exploit | Sudo through 1.8.29 allows local users to escalate to root if they have write access to file descriptor 3 of the sudo process.sudo project · sudo · CWE-362 | High7.0 | — | 0.3% | Nov 4, 2019 |
28Monitor | CVE-2022-43995No exploit | Sudo 1.8.0 through 1.9.12, with the crypt() password backend, contains a plugins/sudoers/auth/passwd.c array-out-of-bounds error that can resudo project · sudo · CWE-125 | High7.1 | — | 0.3% | Nov 2, 2022 |
27Monitor | CVE-2017-1000367Proof of concept | Todd Miller's sudo version 1.8.20 and earlier is vulnerable to an input validation (embedded spaces) in the get_process_ttyname() function rsudo project · sudo · CWE-362 | Medium6.4 | — | 8.0% | Jun 5, 2017 |
21Monitor | CVE-2023-28487No exploit | Sudo before 1.9.13 does not escape control characters in sudoreplay output.sudo project · sudo · CWE-116 | Medium5.3 | — | 1.0% | Mar 15, 2023 |
21Monitor | CVE-2023-28486No exploit | Sudo before 1.9.13 does not escape control characters in log messages.sudo project · sudo · CWE-116 | Medium5.3 | — | 0.9% | Mar 15, 2023 |
13Monitor | CVE-2014-9680No exploit | sudo before 1.8.12 does not ensure that the TZ environment variable is associated with a zoneinfo file, which allows local users to open arbsudo project · sudo · CWE-200 | Low3.3 | — | 0.5% | Apr 24, 2017 |
10Monitor | CVE-2021-23239No exploit | The sudoedit personality of Sudo before 1.9.5 may allow a local unprivileged user to perform arbitrary directory-existence tests by winning sudo project · sudo · CWE-59 | Low2.5 | — | 1.0% | Jan 12, 2021 |
- CVE-2021-315691Now
Sudo before 1.9.5p2 contains an off-by-one error that can result in a heap-based buffer overflow, which allows privilege escalation to root
HighCVSS 7.8KEVWeaponizedEPSS 100%sudo project · sudoJan 26, 2021
- CVE-2025-3246379This week
Sudo before 1.9.17p1 allows local users to obtain root access because /etc/nsswitch.conf from a user-controlled directory is used with the -
HighCVSS 7.8KEVWeaponizedEPSS 61%sudo project · sudoJun 30, 2025
- CVE-2019-1428754Plan
In Sudo before 1.8.28, an attacker with access to a Runas ALL sudoer account can bypass certain policy blacklists and session PAM modules, a
HighCVSS 8.8Proof of conceptEPSS 64%sudo project · sudoOct 17, 2019
- CVE-2023-2280948Plan
In Sudo before 1.9.12p2, the sudoedit (aka -e) feature mishandles extra arguments passed in the user-provided environment variables (SUDO_ED
HighCVSS 7.8WeaponizedEPSS 55%sudo project · sudoJan 18, 2023
- CVE-2019-1863437Monitor
In Sudo before 1.8.26, if pwfeedback is enabled in /etc/sudoers, users can trigger a stack-based buffer overflow in the privileged sudo proc
HighCVSS 7.8Proof of conceptEPSS 19%sudo project · sudoJan 29, 2020
- CVE-2025-3246236Monitor
Sudo before 1.9.17p1, when used with a sudoers file that specifies a host that is neither the current host nor ALL, allows listed users to e
HighCVSS 8.8Proof of conceptEPSS 4%sudo project · sudoJun 30, 2025
- CVE-2023-709035Monitor
Sudo: improper handling of ipa_hostname leads to privilege mismanagement
HighCVSS 8.8No exploitEPSS 1%sudo project · sudoDec 23, 2023
- CVE-2017-100036832Monitor
Todd Miller's sudo version 1.8.20p1 and earlier is vulnerable to an input validation (embedded newlines) in the get_process_ttyname() functi
HighCVSS 8.2No exploitEPSS 1%sudo project · sudoJun 5, 2017
- CVE-2002-018431Monitor
Sudo before 1.6.6 contains an off-by-one error that can result in a heap-based buffer overflow that may allow local users to gain root privi
HighCVSS 7.8Proof of conceptEPSS 1%sudo project · sudoMay 16, 2002
- CVE-2021-2324031Monitor
selinux_edit_copy_tfiles in sudoedit in Sudo before 1.9.5 allows a local unprivileged user to gain file ownership and escalate privileges by
HighCVSS 7.8No exploitEPSS 1%sudo project · sudoJan 12, 2021
- CVE-2005-489031Monitor
There is a possible tty hijacking in shadow 4.x before 4.1.5 and sudo 1.x before 1.7.4 via "su - user -c program".
HighCVSS 7.8No exploitEPSS 1%debian · shadowNov 4, 2019
- CVE-2016-707631Monitor
sudo before version 1.8.18p1 is vulnerable to a bypass in the sudo noexec restriction if application run via sudo executed wordexp() C libra
HighCVSS 7.8No exploitEPSS 0%sudo project · sudoMay 29, 2018
- CVE-2026-3553531Monitor
In Sudo through 1.9.17p2 before 3e474c2, a failure of a setuid, setgid, or setgroups call, during a privilege drop before running the mailer
HighCVSS 7.8No exploitEPSS 0%sudo project · sudoApr 2, 2026
- CVE-2023-2732028Monitor
Sudo before 1.9.13p2 has a double free in the per-command chroot feature.
HighCVSS 7.2No exploitEPSS 2%sudo project · sudoFeb 28, 2023
- CVE-2015-560228Monitor
sudoedit in Sudo before 1.8.15 allows local users to gain privileges via a symlink attack on a file whose full path is defined using multipl
HighCVSS 7.2Proof of conceptEPSS 1%sudo project · sudoNov 17, 2015
- CVE-2015-823928Monitor
The SHA-2 digest support in the sudoers plugin in sudo after 1.8.7 allows local users with write permissions to parts of the called command
HighCVSS 7.0Proof of conceptEPSS 1%sudo project · sudoOct 10, 2017
- CVE-2023-4246528Monitor
Sudo before 1.9.15 might allow row hammer attacks (for authentication bypass or privilege escalation) because application logic sometimes is
HighCVSS 7.0No exploitEPSS 1%sudo project · sudoDec 22, 2023
- CVE-2019-1868428Monitor
Sudo through 1.8.29 allows local users to escalate to root if they have write access to file descriptor 3 of the sudo process.
HighCVSS 7.0No exploitEPSS 0%sudo project · sudoNov 4, 2019
- CVE-2022-4399528Monitor
Sudo 1.8.0 through 1.9.12, with the crypt() password backend, contains a plugins/sudoers/auth/passwd.c array-out-of-bounds error that can re
HighCVSS 7.1No exploitEPSS 0%sudo project · sudoNov 2, 2022
- CVE-2017-100036727Monitor
Todd Miller's sudo version 1.8.20 and earlier is vulnerable to an input validation (embedded spaces) in the get_process_ttyname() function r
MediumCVSS 6.4Proof of conceptEPSS 8%sudo project · sudoJun 5, 2017
- CVE-2023-2848721Monitor
Sudo before 1.9.13 does not escape control characters in sudoreplay output.
MediumCVSS 5.3No exploitEPSS 1%sudo project · sudoMar 15, 2023
- CVE-2023-2848621Monitor
Sudo before 1.9.13 does not escape control characters in log messages.
MediumCVSS 5.3No exploitEPSS 1%sudo project · sudoMar 15, 2023
- CVE-2014-968013Monitor
sudo before 1.8.12 does not ensure that the TZ environment variable is associated with a zoneinfo file, which allows local users to open arb
LowCVSS 3.3No exploitEPSS 0%sudo project · sudoApr 24, 2017
- CVE-2021-2323910Monitor
The sudoedit personality of Sudo before 1.9.5 may allow a local unprivileged user to perform arbitrary directory-existence tests by winning
LowCVSS 2.5No exploitEPSS 1%sudo project · sudoJan 12, 2021