Vulnerabilidades

Resumen — últimos 7 días

Vulnerabilidades nuevas2614▼ 473 respecto a la semana anterior
Críticas / altas1270▼ 74 respecto a la semana anterior
Nueva explotación activa (KEV)5▼ 3 respecto a la semana anterior
Sin puntuar (sin CVSS)243▼ 274 respecto a la semana anterior
–

65 resultados, ordenados por fecha de publicación (más recientes primero)

CVEEstadoSeveridadEPSS Explotación activaTecnologías afectadasPublicada ▼Modificada Descripción
ModificadaAlta (7.8)0.41%—Gratisoft SudoVmware ESX30/1/200916/6/2026
parse.c in sudo 1.6.9p17 through 1.6.9p19 does not properly interpret a system group (aka %group) in the sudoers file during authorization decisions for a user who belongs to that group, which allows local users to leverage an applicable sudoers file and gain root privileges via a sudo command.
ModificadaMedia (6.2)0.86%—SysjailSystraceTodd Miller Sudo13/8/200716/6/2026
Multiple race conditions in the (1) Sudo monitor mode and (2) Sysjail policies in Systrace on NetBSD and OpenBSD allow local users to defeat system call interposition, and consequently bypass access control policy and auditing.
ModificadaAlta (7.2)0.36%—MIT Kerberos 5Todd Miller Sudo11/6/200716/6/2026
sudo, when linked with MIT Kerberos 5 (krb5), does not properly check whether a user can currently authenticate to Kerberos, which allows local users to gain privileges, in a manner unintended by the sudo security model, via certain KRB5_ environment variable settings. NOTE: another researcher disputes this…
ModificadaAlta (7.2)0.61%—Todd Miller SudoUbuntu Linux9/1/200616/6/2026
sudo 1.6.8 and other versions does not clear the PYTHONINSPECT environment variable, which allows limited local users to gain privileges via a Python script, a variant of CVE-2005-4158.
ModificadaMedia (4.6)1.1%—Todd Miller Sudo11/12/200516/6/2026
Sudo before 1.6.8 p12, when the Perl taint flag is off, does not clear the (1) PERLLIB, (2) PERL5LIB, and (3) PERL5OPT environment variables, which allows limited local users to cause a Perl script to include and execute arbitrary library files that have the same name as library files that are included by the script.
ModificadaMedia (4.6)0.62%—Todd Miller Sudo25/10/200516/6/2026
Incomplete blacklist vulnerability in sudo 1.6.8 and earlier allows local users to gain privileges via the (1) SHELLOPTS and (2) PS4 environment variables before executing a bash script on behalf of another user, which are not cleared even though other variables are.
ModificadaBaja (3.7)0.40%—Todd Miller Sudo20/6/200516/6/2026
Race condition in sudo 1.3.1 up to 1.6.8p8, when the ALL pseudo-command is used after a user entry in the sudoers file, allows local users to gain privileges via a symlink attack.
ModificadaAlta (8.4)0.40%—Todd Miller Sudo31/5/200516/6/2026
Sudo 1.6.8p7 on SuSE Linux 9.3, and possibly other Linux distributions, allows local users to gain privileges by using sudo to call su, then entering a blank password and hitting CTRL-C. NOTE: SuSE and multiple third-party researchers have not been able to replicate this issue, stating "Sudo catches SIGINT and returns…
ModificadaBaja (2.1)0.36%—Todd Miller Sudo2/5/200516/6/2026
Sudo VISudo 1.6.8 and earlier allows local users to corrupt arbitrary files via a symlink attack on temporary files.
ModificadaAlta (7.2)1.4%—Mandrakesoft Mandrake Multi Network FirewallTodd Miller SudoDebian LinuxMandrakesoft Mandrake Linux+31/3/200516/6/2026
sudo before 1.6.8p2 allows local users to execute arbitrary commands by using "()" style environment variables to create functions that have the same name as any program within the bash script that is called without using the program's full pathname.
ModificadaBaja (2.1)1.2%—Todd Miller Sudo16/9/200416/6/2026
sudoedit (aka sudo -e) in sudo 1.6.8 opens a temporary file with root privileges, which allows local users to read arbitrary files via a symlink attack on the temporary file before quitting sudoedit.
ModificadaAlta (7.8)1.2%—Sudo Project SudoDebian Linux16/5/200216/6/2026
Sudo before 1.6.6 contains an off-by-one error that can result in a heap-based buffer overflow that may allow local users to gain root privileges via special characters in the -p (prompt) argument, which are not properly expanded.
ModificadaAlta (7.2)0.93%—Todd Miller Sudo31/1/200216/6/2026
sudo 1.6.0 through 1.6.3p7 does not properly clear the environment before calling the mail program, which could allow local users to gain root privileges by modifying environment variables and changing how the mail program is invoked.
ModificadaBaja (2.1)0.51%—Todd Miller SudoDebian LinuxRedhat Linux8/6/199916/6/2026
Sudo 1.5 in Debian Linux 2.1 and Red Hat 6.0 allows local users to determine the existence of arbitrary files by attempting to execute the target filename as a program, which generates a different error message when the file does not exist.
ModificadaAlta (7.2)0.43%—Todd Miller Sudo12/1/199816/6/2026
sudo 1.5.x allows local users to execute arbitrary commands via a .. (dot dot) attack.