Vulnerability index

Browse CVEs

12 matching
Filters 1 Clear all
Severity

Filters apply as you choose them.

Sudo HIGH 7.0
CVE-2016-7032

sudo_noexec.so in Sudo before 1.8.15 on Linux might allow local users to bypass intended noexec command restrictions via an application that calls th…

Mitigation only
Fix from $1,950 2017-04-14
Sudo MEDIUM 6.9
CVE-2013-1775

sudo 1.6.0 through 1.7.10p6 and sudo 1.8.0 through 1.8.6p6 allows local users or physically proximate attackers to bypass intended time restrictions …

Fix: after 10.10.4
Fix from $1,600 2013-03-05
Sudo HIGH 7.2
CVE-2012-2337

sudo 1.6.x and 1.7.x before 1.7.9p1, and 1.8.x before 1.8.4p5, does not properly support configurations that use a netmask syntax, which allows local…

Mitigation only
Fix from $1,950 2012-05-18
Sudo HIGH 7.2
CVE-2012-0809

Format string vulnerability in the sudo_debug function in Sudo 1.8.0 through 1.8.3p1 allows local users to execute arbitrary code via format string s…

No fix yet
Fix from $1,950 2012-02-01
Sudo MEDIUM 6.9
CVE-2011-0008

A certain Fedora patch for parse.c in sudo before 1.7.4p5-1.fc14 on Fedora 14 does not properly interpret a system group (aka %group) in the sudoers …

Fix: after 1.7.4p5
Fix from $1,600 2011-01-20
Sudo MEDIUM 6.2
CVE-2010-2956

Sudo 1.7.0 through 1.7.4p3, when a Runas group is configured, does not properly handle use of the -u option in conjunction with the -g option, which …

Mitigation only
Fix from $1,600 2010-09-10
Sudo MEDIUM 6.2
CVE-2010-1646

The secure path feature in env.c in sudo 1.3.1 through 1.6.9p22 and 1.7.0 through 1.7.2p6 does not properly handle an environment that contains multi…

Patch available
Fix from $1,600 2010-06-07
Sudo MEDIUM 6.9
CVE-2010-1163

The command matching functionality in sudo 1.6.8 through 1.7.2p5 does not properly handle when a file in the current working directory has the same n…

Mitigation only
Fix from $1,600 2010-04-16
Sudo MEDIUM 6.9
CVE-2010-0426

sudo 1.6.x before 1.6.9p21 and 1.7.x before 1.7.2p4, when a pseudo-command is enabled, permits a match between the name of the pseudo-command and the…

Patch available
Fix from $1,600 2010-02-24
Sudo HIGH 8.4
CVE-2005-1831

Sudo 1.6.8p7 on SuSE Linux 9.3, and possibly other Linux distributions, allows local users to gain privileges by using sudo to call su, then entering…

Mitigation only
Fix from $1,950 2005-05-31
Sudo HIGH 7.2
CVE-2002-0043

sudo 1.6.0 through 1.6.3p7 does not properly clear the environment before calling the mail program, which could allow local users to gain root privil…

Patch available
Fix from $1,950 2002-01-31
Sudo HIGH 7.2
CVE-1999-0958

sudo 1.5.x allows local users to execute arbitrary commands via a .. (dot dot) attack.

Mitigation only
Fix from $1,950 1998-01-12