cbcvebase.
CVE-2014-5195
published 2014-08-07

CVE-2014-5195: Unity before 7.2.3 and 7.3.x before 7.3.1, as used in Ubuntu, does not properly take focus of the keyboard when switching to the lock screen, which allows…

PriorityP427high7.2CVSS 2.0
AVLACLAuNCCICAC
EPSS
0.30%
22.1th percentile
Unity before 7.2.3 and 7.3.x before 7.3.1, as used in Ubuntu, does not properly take focus of the keyboard when switching to the lock screen, which allows physically proximate attackers to bypass the lock screen by (1) leveraging a machine that had text selected when locking or (2) resuming from a suspension.

Affected

5 ranges
VendorProductVersion rangeFixed in
ayatana_projectunity<= 7.2.2
ayatana_projectunity
ayatana_projectunity
ayatana_projectunity
dellunity>= 0 < 7.2.2+14.04.20140714-0ubuntu1.17.2.2+14.04.20140714-0ubuntu1.1

CVSS provenance

nvdv2.07.2HIGHAV:L/AC:L/Au:N/C:C/I:C/A:C
osv7.2HIGH
Stop checking back — get the weekly exploitation signal.

Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.