Vulnerability Monitor

The vendors, products, and vulnerabilities you care about

CVE-2014-3204


Unity before 7.2.1, as used in Ubuntu 14.04, does not properly handle keyboard shortcuts, which allows physically proximate attackers to bypass the lock screen and execute arbitrary commands, as demonstrated by right-clicking on the indicator bar and then pressing the ALT and F2 keys.


Published

2014-05-06T14:55:06.120

Last Modified

2025-04-12T10:46:40.837

Status

Deferred

Source

[email protected]

Severity

CVSSv2: 4.4 (MEDIUM)

CVSSv2 Vector

AV:L/AC:M/Au:N/C:P/I:P/A:P

  • Access Vector: LOCAL
  • Access Complexity: MEDIUM
  • Authentication: NONE
  • Confidentiality Impact: PARTIAL
  • Integrity Impact: PARTIAL
  • Availability Impact: PARTIAL
Exploitability Score

3.4

Impact Score

6.4

Weaknesses
  • Type: Primary
    CWE-264

Affected Vendors & Products
Type Vendor Product Version/Range Vulnerable?
Application ayatana_project unity ≤ 7.2.0 Yes
Application ayatana_project unity 7.0.0 Yes
Application ayatana_project unity 7.0.1 Yes
Application ayatana_project unity 7.1.0 Yes
Application ayatana_project unity 7.1.1 Yes
Application ayatana_project unity 7.1.2 Yes
Application ayatana_project unity 7.1.3 Yes
Operating System canonical ubuntu_linux 14.04 Yes

References