VulnerabilityModified
CVE-2008-6514
The Expo plugin in Compiz Fusion 0.7.8 allows local users with physical access to drag the screen saver aside and access the locked desktop by using Expo mouse shortcuts, a related issue to CVE-2007-3920.
MEDIUM 6.2EPSS 0.41%
Does this matter?
Lower severity and a low EPSS score (0.41%). Track it; it rarely justifies an emergency change on its own.
Description
The Expo plugin in Compiz Fusion 0.7.8 allows local users with physical access to drag the screen saver aside and access the locked desktop by using Expo mouse shortcuts, a related issue to CVE-2007-3920.
- CVSS 2.0
- 6.2 MEDIUMAV:L/AC:H/Au:N/C:C/I:C/A:C
- EPSS
- 0.41% probability · 35th percentile
- CISA KEV
- Not listed
- Weakness
- CWE-264
- Affected
- compiz/compiz fusion
- Source
- cve@mitre.org
References
- http://bugzilla.gnome.org/show_bug.cgi?id=561567
- http://gitweb.compiz-fusion.org/?p=fusion/plugins/expo%3Ba=commit%3Bh=f97a9fa6f0ad578f674d1f248bd7bef90e3260e0
- http://secunia.com/advisories/33077Vendor Advisory
- http://secunia.com/advisories/34465
- http://www.securityfocus.com/bid/32712Patch
- https://bugs.launchpad.net/ubuntu/+source/compiz-fusion-plugins-main/+bug/247088Exploit
- https://exchange.xforce.ibmcloud.com/vulnerabilities/47172
- https://www.redhat.com/archives/fedora-package-announce/2009-March/msg00860.html
- https://www.redhat.com/archives/fedora-package-announce/2009-March/msg00878.html
- http://bugzilla.gnome.org/show_bug.cgi?id=561567
- http://gitweb.compiz-fusion.org/?p=fusion/plugins/expo%3Ba=commit%3Bh=f97a9fa6f0ad578f674d1f248bd7bef90e3260e0
- http://secunia.com/advisories/33077Vendor Advisory
- http://secunia.com/advisories/34465
- http://www.securityfocus.com/bid/32712Patch
- https://bugs.launchpad.net/ubuntu/+source/compiz-fusion-plugins-main/+bug/247088Exploit
- https://exchange.xforce.ibmcloud.com/vulnerabilities/47172
- https://www.redhat.com/archives/fedora-package-announce/2009-March/msg00860.html
- https://www.redhat.com/archives/fedora-package-announce/2009-March/msg00878.html
Source: NVD record, EPSS from FIRST.org, KEV from CISA. Refreshed daily.