Known vulnerabilities in sudo (Alpine package)

Software CPE: cpe:2.3:o:alpine:sudo_alpine_package:*:*:*:*:*:alpine_linux:*:*
Total vulnerabilities: 14
Public exploits: 5
Known exploited (KEV): 1
Highest CVSSv4 Score: 8.7

Breakdown by Severity Chart

Severity distribution of vulnerabilities affecting sudo (Alpine package) sudo (Alpine package) is affected by 14 known vulnerabilities: 14 low Critical High Medium Low

Vulnerabilities (14)

Vulnerability CWE-ID CSH Severity Public Exploit KEV First fixed release Published Bulletins
#VU50040 - Heap-based Buffer Overflow
CVE-2021-3156
CWE-122 Low
Available
Exploited
1.9.5p2-r0 26.01.2021 SB2021012632
SB2021012633
SB2021012634
and 55 more
#VU49883 - Improper Link Resolution Before File Access ('Link Following')
CVE-2021-23239
CWE-59 Low
No
No
1.9.5-r0 12.01.2021 SB2021011282
SB2021011283
SB20210120114
and 14 more
#VU49884 - Improper Link Resolution Before File Access ('Link Following')
CVE-2021-23240
CWE-59 Low
No
No
1.9.5-r0 12.01.2021 SB2021011284
SB2021011285
SB20210120114
and 11 more
#VU24810 - Stack-based buffer overflow
CVE-2019-18634
CWE-121 Low
Available
No
1.8.29-r2, 1.8.31-r0 31.01.2020 SB2020013120
SB2020013121
SB2020020102
and 17 more
#VU21782 - Permissions, Privileges, and Access Controls
CVE-2019-14287
CWE-264 Low
Available
No
1.8.28-r0 15.10.2019 SB2019101501
SB2019101502
SB2019101503
and 27 more
#VU7193 - Improper input validation
CVE-2017-1000368
CWE-20 Low
No
No
1.8.28-r0 26.06.2017 SB2017062602
SB2017062703
SB2017100803
and 7 more
#VU6846 - Command injection
CVE-2017-1000367
CWE-77 Low
Available
No
1.8.20_p1-r0 31.05.2017 SB2017053106
SB2017053107
SB2017053109
and 23 more
#VU32438 - Exposure of sensitive information to an unauthorized actor
CVE-2014-9680
CWE-200 Low
No
No
1.8.12-r0 24.04.2017 SB2017042407
SB2013100202
SB2015041102
and 2 more
#VU32397 - Permissions, Privileges, and Access Controls
CVE-2015-5602
CWE-264 Low
No
No
1.8.15-r0 17.11.2015 SB2015111702
SB2015081406
SB2016062604
and 3 more
#VU32716 - Permissions, Privileges, and Access Controls
CVE-2013-1775
CWE-264 Low
No
No
1.8.6_p7-r0 05.03.2013 SB2013030501
SB2013032614
#VU32797 - Permissions, Privileges, and Access Controls
CVE-2012-2337
CWE-264 Low
No
No
1.7.9_p1-r0 18.05.2012 SB2012051802
SB2012061108
SB2012072530
and 1 more
#VU32823 - Use of Externally-Controlled Format String
CVE-2012-0809
CWE-134 Low
Available
No
1.8.3_p2-r0 01.02.2012 SB2012020102
SB2012013002
SB2012030604
#VU32862 - Permissions, Privileges, and Access Controls
CVE-2010-0427
CWE-264 Low
No
No
1.7.2_p4-r0 25.02.2010 SB2010022501
SB2010030802
SB2010030301
#VU32861 - Permissions, Privileges, and Access Controls
CVE-2010-0426
CWE-264 Low
No
No
1.7.2_p4-r0 24.02.2010 SB2010022401
SB2010030801
SB2010030301