CVE-2012-0064

xkeyboard-config before 2.5 in X.Org before 7.6 enables certain XKB debugging functions by default, which allows physically proximate attackers to bypass an X screen lock via keyboard combinations that break the input grab.
ProviderTypeBase ScoreAtk. VectorAtk. ComplexityPriv. RequiredVector
NISTNIST
4.6 UNKNOWN
LOCAL
LOW
AV:L/AC:L/Au:N/C:P/I:P/A:P
redhatCNA
---
---
CVEADP
---
---
Base Score
CVSS 3.x
EPSS Score
Percentile: 24%
VendorProductVersion
xx.org_x11
𝑥
≤ 7.5
xx.org_x11
1.0
xx.org_x11
3.0
xx.org_x11
4.0
xx.org_x11
5.0
xx.org_x11
6.0
xx.org_x11
6.1
xx.org_x11
6.3
xx.org_x11
6.4
xx.org_x11
6.5.1
xx.org_x11
6.6
xx.org_x11
6.7
xx.org_x11
6.8
xx.org_x11
6.8.1
xx.org_x11
6.8.2
xx.org_x11
6.9.0
xx.org_x11
7.0
xx.org_x11
7.1
xx.org_x11
7.2
xx.org_x11
7.3
xx.org_x11
7.4
xx.org_x11
7.5
xkeyboard_config_projectxkeyboard-config
𝑥
≤ 2.4
xkeyboard_config_projectxkeyboard-config
2.0
xkeyboard_config_projectxkeyboard-config
2.1
xkeyboard_config_projectxkeyboard-config
2.2
xkeyboard_config_projectxkeyboard-config
2.3
𝑥
= Vulnerable software versions
Debian logo
Debian Releases
Debian Product
Codename
xorg-server
bullseye
2:1.20.11-1+deb11u13
fixed
squeeze
not-affected
lenny
not-affected
bullseye (security)
2:1.20.11-1+deb11u14
fixed
bookworm
2:21.1.7-3+deb12u7
fixed
bookworm (security)
2:21.1.7-3+deb12u8
fixed
sid
2:21.1.14-1
fixed
trixie
2:21.1.14-1
fixed
Ubuntu logo
Ubuntu Releases
Ubuntu Product
Codename
xorg-server
oneiric
not-affected
natty
not-affected
maverick
not-affected
lucid
not-affected
hardy
ignored
Common Weakness Enumeration