📦

sudo

Vendor: sudo_project

Actively Exploited 2 CISA KEV List
PoC / Exploits 10 Code Available
Total RCEs 2 Remote Access
Total CVEs 102 Total Indexed
Avg. EPSS 13.23% Exploit Prob.
Latest CVE CVE-2026-35535 Apr 03

Security Vulnerability Index

Page 3 / 11
6.4 CVSS
CVE-2017-1000367
Exploit Found

Todd Miller's sudo version 1.8.20 and earlier is vulnerable to an input validation (embedded spaces) in the get_process_ttyname() function resulting in information disclosure and command execution.

EPSS: 8.02%
3.3 CVSS

sudo before 1.8.12 does not ensure that the TZ environment variable is associated with a zoneinfo file, which allows local users to open arbitrary files for read access (but not view file contents) by running a program within an sudo session, as demonstrated by interfering with terminal output, discarding kernel-log messages, or repositioning tape drives.

EPSS: 0.47%
7.2 CVSS
CVE-2015-5602
Exploit Found

sudoedit in Sudo before 1.8.15 allows local users to gain privileges via a symlink attack on a file whose full path is defined using multiple wildcards in /etc/sudoers, as demonstrated by "/home/*/*/file.txt."

EPSS: 1.46%
7.8 CVSS
CVE-2002-0184
Exploit Found

Sudo before 1.6.6 contains an off-by-one error that can result in a heap-based buffer overflow that may allow local users to gain root privileges via special characters in the -p (prompt) argument, which are not properly expanded.

EPSS: 1.20%