Todd Miller / Sudo
28 CVEs
| CVE ID | Description | Severity | CVSS | Published |
|---|---|---|---|---|
| CVE-2016-7032 | sudo: noexec bypass via system() and popen() | HIGH | 7.0 | Apr 14, 2017 |
| CVE-2014-0106 | sudo: certain environment variables not sanitized when env_reset is disabled | MEDIUM | 6.6 | Mar 11, 2014 |
| CVE-2013-2777 | sudo: bypass of tty_tickets constraints | MEDIUM | 4.4 | Apr 8, 2013 |
| CVE-2013-2776 | sudo: bypass of tty_tickets constraints | MEDIUM | 4.4 | Apr 8, 2013 |
| CVE-2013-1776 | sudo: bypass of tty_tickets constraints | MEDIUM | 4.4 | Apr 8, 2013 |
| CVE-2013-1775 | sudo: authentication bypass via reset system clock | MEDIUM | 6.9 | Mar 4, 2013 |
| CVE-2012-3440 | sudo: insecure temporary file use in RPM %postun script | MEDIUM | 5.6 | Aug 8, 2012 |
| CVE-2012-2337 | sudo: Multiple netmask values used in Host / Host_List configuration cause any host to be allowed access | HIGH | 7.2 | May 18, 2012 |
| CVE-2012-0809 | sudo: format string flaw in sudo_debug() | HIGH | 7.2 | Feb 1, 2012 |
| CVE-2011-0008 | sudo in Fedora vulnerable to CVE-2009-0034 again due to improper patch rediff | MEDIUM | 6.9 | Jan 20, 2011 |
| CVE-2011-0010 | sudo: does not ask for password on GID changes | MEDIUM | 4.4 | Jan 18, 2011 |
| CVE-2010-2956 | sudo: incorrect handling of RunAs specification with both user and group lists | MEDIUM | 6.2 | Sep 10, 2010 |
| CVE-2010-1646 | sudo: insufficient environment sanitization issue | MEDIUM | 6.2 | Jun 7, 2010 |
| CVE-2010-1163 | sudo: incomplete fix for the sudoedit privilege escalation issue CVE-2010-0426 | MEDIUM | 6.9 | Apr 16, 2010 |
| CVE-2010-0427 | sudo: Fails to reset group permissions if runas_default set | MEDIUM | 4.4 | Feb 25, 2010 |
| CVE-2010-0426 | sudo: sudoedit option can possibly allow for arbitrary code execution | MEDIUM | 6.9 | Feb 24, 2010 |
| CVE-2007-4305 | Multiple race conditions in the (1) Sudo monitor mode and (2) Sysjail policies in Systrace on NetBSD and OpenBSD allow local users to defeat system call interp… | MEDIUM | 6.2 | Aug 13, 2007 |
| CVE-2007-3149 | Local authentication bypass in sudo | HIGH | 7.2 | Jun 11, 2007 |
| CVE-2006-0151 | CVE-2004-1051 bash scripts run via Sudo can be subverted (CVE-2005-4158, CVE-2006-0151) | HIGH | 7.2 | Jan 9, 2006 |
| CVE-2005-4158 | CVE-2004-1051 bash scripts run via Sudo can be subverted (CVE-2005-4158, CVE-2006-0151) | MEDIUM | 4.6 | Dec 11, 2005 |
| CVE-2005-2959 | Incomplete blacklist vulnerability in sudo 1.6.8 and earlier allows local users to gain privileges via the (1) SHELLOPTS and (2) PS4 environment variables befo… | MEDIUM | 4.6 | Oct 25, 2005 |
| CVE-2005-1993 | security flaw | LOW | 3.7 | Jun 20, 2005 |
| CVE-2005-1831 | Sudo 1.6.8p7 on SuSE Linux 9.3, and possibly other Linux distributions, allows local users to gain privileges by using sudo to call su, then entering a blank p… | HIGH | 8.4 | Jun 2, 2005 |
| CVE-2005-1119 | Sudo VISudo 1.6.8 and earlier allows local users to corrupt arbitrary files via a symlink attack on temporary files. | LOW | 2.1 | Apr 16, 2005 |
| CVE-2004-1689 | sudoedit (aka sudo -e) in sudo 1.6.8 opens a temporary file with root privileges, which allows local users to read arbitrary files via a symlink attack on the… | LOW | 2.1 | Feb 20, 2005 |
Showing 1 to 25 of 28 CVEs