Vulnerabilities (CVE)

Filtered by vendor Sudo Project Subscribe
Filtered by product Sudo
CVE Vendors Products Updated CVSS v2 CVSS v3
CVE-2002-0184 2 Debian, Sudo Project 2 Debian Linux, Sudo 2021-04-01 7.2 HIGH N/A
Sudo before 1.6.6 contains an off-by-one error that can result in a heap-based buffer overflow that may allow local users to gain root privileges via special characters in the -p (prompt) argument, which are not properly expanded.
CVE-2015-5602 1 Sudo Project 1 Sudo 2016-12-07 7.2 HIGH N/A
sudoedit in Sudo before 1.8.15 allows local users to gain privileges via a symlink attack on a file whose full path is defined using multiple wildcards in /etc/sudoers, as demonstrated by "/home/*/*/file.txt."