Top technology
Linux 13140
Google 12530
Microsoft 12379
Oracle 6737
Apple 6692
Adobe 6387
Ibm 6330
Cisco 5757
Debian 3919
Mozilla 2895
Apache 2864
Redhat 2592
HIGH 7.8
CVE-2026-35535
In Sudo through 1.9.17p2 before 3e474c2, a failure of a setuid, setgid, or setgroups call, during a privilege drop before running the mailer, is not …
Sudo
1.9.17 / 4.0+
HIGH 8.8
CVE-2025-32462
Sudo before 1.9.17p1, when used with a sudoers file that specifies a host that is neither the current host nor ALL, allows listed users to execute co…
Sudo
1.9.17+
HIGH 8.8
CVE-2023-7090
A flaw was found in sudo in the handling of ipa_hostname, where ipa_hostname from /etc/sssd/sssd.conf was not propagated in sudo. Therefore, it leads…
Sudo
1.8.28+
HIGH 7.0
CVE-2023-42465
Sudo before 1.9.15 might allow row hammer attacks (for authentication bypass or privilege escalation) because application logic sometimes is based on…
Sudo
1.9.15+
MEDIUM 5.3
CVE-2023-28486
Sudo before 1.9.13 does not escape control characters in log messages.
Sudo
1.9.13+
MEDIUM 5.3
CVE-2023-28487
Sudo before 1.9.13 does not escape control characters in sudoreplay output.
Sudo
1.9.13+
HIGH 7.1
CVE-2022-43995
Sudo 1.8.0 through 1.9.12, with the crypt() password backend, contains a plugins/sudoers/auth/passwd.c array-out-of-bounds error that can result in a…
Sudo
1.9.12+
HIGH 7.0
CVE-2019-18684
Sudo through 1.8.29 allows local users to escalate to root if they have write access to file descriptor 3 of the sudo process. This occurs because of…
Sudo
after 1.8.29
HIGH 7.8
CVE-2016-7076
sudo before version 1.8.18p1 is vulnerable to a bypass in the sudo noexec restriction if application run via sudo executed wordexp() C library functi…
Sudo
after 1.8.18
HIGH 7.0
CVE-2015-8239
The SHA-2 digest support in the sudoers plugin in sudo after 1.8.7 allows local users with write permissions to parts of the called command to replac…
Sudo
Patch available
HIGH 8.2
CVE-2017-1000368
Todd Miller's sudo version 1.8.20p1 and earlier is vulnerable to an input validation (embedded newlines) in the get_process_ttyname() function result…
Sudo
after 1.8.20
MEDIUM 6.4
CVE-2017-1000367EPSS 8%
Todd Miller's sudo version 1.8.20 and earlier is vulnerable to an input validation (embedded spaces) in the get_process_ttyname() function resulting …
Sudo
after 1.8.20
HIGH 7.2
CVE-2015-5602
sudoedit in Sudo before 1.8.15 allows local users to gain privileges via a symlink attack on a file whose full path is defined using multiple wildcar…
Sudo
after 1.8.14