CVE Browser
Sudo through 1.9.17p2 Intercept Policy Bypass via execveat
sudo: Sudo: Privilege escalation due to failure in privilege drop calls
sudo: LPE via chroot option
sudo: LPE via host option
Sudo: improper handling of ipa_hostname leads to privilege mismanagement
sudo: Targeted Corruption of Register and Stack Variables
sudo: Sudo does not escape control characters in sudoreplay output
sudo: Sudo does not escape control characters in log messages
sudo: double free with per-command chroot sudoers rules
sudo: arbitrary file write with privileges of the RunAs user
sudo: heap-based overflow with very small passwords
sudo: Heap buffer overflow in argument parsing
sudo: symbolic link attack in SELinux-enabled sudoedit
sudo: possible directory existence test due to race condition in sudoedit
sudo: Stack based buffer overflow when pwfeedback is enabled
sudo: attacker with access to a Runas ALL sudoer account can impersonate a nonexistent user
sudo: by using ! character in the shadow file instead of a password hash can access to a run as all sudoer account
coreutils: tty hijacking possible in "su" via TIOCSTI ioctl
sudo: privilege escalation via write access to file descriptor 3 of the sudo process
sudo: Privilege escalation via 'Runas' specification with 'ALL' keyword
sudo: noexec bypass via wordexp()
sudo: Race condition when checking digests in sudoers
sudo: Privilege escalation via improper get_process_ttyname() parsing (insufficient fix for CVE-2017-1000367)
sudo: Privilege escalation in via improper get_process_ttyname() parsing
sudo: unsafe handling of TZ environment variable
Showing 1 to 25 CVEs · page 1 (more available)