Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

nvd логотип

CVE-2019-14822

Опубликовано: 25 нояб. 2019
Источник: nvd
CVSS3: 7.1
CVSS2: 3.6
EPSS Низкий

Описание

A flaw was discovered in ibus in versions before 1.5.22 that allows any unprivileged user to monitor and send method calls to the ibus bus of another user due to a misconfiguration in the DBus server setup. A local attacker may use this flaw to intercept all keystrokes of a victim user who is using the graphical interface, change the input method engine, or modify other input related configurations of the victim user.

Уязвимые конфигурации

Конфигурация 1
cpe:2.3:a:ibus_project:ibus:*:*:*:*:*:*:*:*
Версия до 1.5.22 (исключая)
Конфигурация 2

Одно из

cpe:2.3:o:redhat:enterprise_linux:7.0:*:*:*:*:*:*:*
cpe:2.3:o:redhat:enterprise_linux:8.0:*:*:*:*:*:*:*
Конфигурация 3

Одно из

cpe:2.3:o:canonical:ubuntu_linux:16.04:*:*:*:esm:*:*:*
cpe:2.3:o:canonical:ubuntu_linux:18.04:*:*:*:lts:*:*:*
cpe:2.3:o:canonical:ubuntu_linux:19.10:*:*:*:*:*:*:*
Конфигурация 4
cpe:2.3:a:oracle:zfs_storage_appliance_kit:8.8:*:*:*:*:*:*:*

EPSS

Процентиль: 48%
0.00246
Низкий

7.1 High

CVSS3

3.6 Low

CVSS2

Дефекты

CWE-862
CWE-862

Связанные уязвимости

CVSS3: 7.1
ubuntu
почти 6 лет назад

A flaw was discovered in ibus in versions before 1.5.22 that allows any unprivileged user to monitor and send method calls to the ibus bus of another user due to a misconfiguration in the DBus server setup. A local attacker may use this flaw to intercept all keystrokes of a victim user who is using the graphical interface, change the input method engine, or modify other input related configurations of the victim user.

CVSS3: 6.1
redhat
около 6 лет назад

A flaw was discovered in ibus in versions before 1.5.22 that allows any unprivileged user to monitor and send method calls to the ibus bus of another user due to a misconfiguration in the DBus server setup. A local attacker may use this flaw to intercept all keystrokes of a victim user who is using the graphical interface, change the input method engine, or modify other input related configurations of the victim user.

CVSS3: 7.1
debian
почти 6 лет назад

A flaw was discovered in ibus in versions before 1.5.22 that allows an ...

suse-cvrf
почти 6 лет назад

Security update for ibus

suse-cvrf
почти 6 лет назад

Security update for ibus

EPSS

Процентиль: 48%
0.00246
Низкий

7.1 High

CVSS3

3.6 Low

CVSS2

Дефекты

CWE-862
CWE-862