cbcvebase.
CVE-2014-3204
published 2014-05-06

CVE-2014-3204: Unity before 7.2.1, as used in Ubuntu 14.04, does not properly handle keyboard shortcuts, which allows physically proximate attackers to bypass the lock screen…

PriorityP427medium4.4CVSS 2.0
AVLACMAuNCPIPAP
EPSS
0.48%
38.5th percentile
Unity before 7.2.1, as used in Ubuntu 14.04, does not properly handle keyboard shortcuts, which allows physically proximate attackers to bypass the lock screen and execute arbitrary commands, as demonstrated by right-clicking on the indicator bar and then pressing the ALT and F2 keys.

Affected

9 ranges
VendorProductVersion rangeFixed in
ayatana_projectunity<= 7.2.0
ayatana_projectunity
ayatana_projectunity
ayatana_projectunity
ayatana_projectunity
ayatana_projectunity
ayatana_projectunity
canonicalubuntu_linux
dellunity>= 0 < 7.2.0+14.04.20140423-0ubuntu1.17.2.0+14.04.20140423-0ubuntu1.1

CVSS provenance

nvdv2.04.4MEDIUMAV:L/AC:M/Au:N/C:P/I:P/A:P
osv4.4MEDIUM
Stop checking back — get the weekly exploitation signal.

Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.