CVE-2012-0064

UnknownEPSS 0.39%

Last modified

CVE-2012-0064 is a vulnerability of currently unknown severity. xkeyboard-config before 2.5 in X.Org before 7.6 enables certain XKB debugging functions by default, which allows physically proximate attackers to bypass an X screen lock via keyboard combinations that break the input grab.. EPSS estimates a 0.39% chance of exploitation in the next 30 days.

Description

xkeyboard-config before 2.5 in X.Org before 7.6 enables certain XKB debugging functions by default, which allows physically proximate attackers to bypass an X screen lock via keyboard combinations that break the input grab.

Metrics

EPSS Probability
0.39%

30.7th percentile

Probability of exploitation in the next 30 days. Learn more

Weakness Enumeration

Affected Software

VendorProductVersionsUpdate
XX.Org X11<= 7.5Rc1
XX.Org X111.0
XX.Org X113.0
XX.Org X114.0
XX.Org X115.0
XX.Org X116.0
XX.Org X116.1
XX.Org X116.3
XX.Org X116.4
XX.Org X116.5.1
XX.Org X116.6
XX.Org X116.7
XX.Org X116.8
XX.Org X116.8.1
XX.Org X116.8.2
XX.Org X116.9.0
XX.Org X117.0
XX.Org X117.1
XX.Org X117.2
XX.Org X117.3
XX.Org X117.4
XX.Org X117.5
Xkeyboard Config ProjectXkeyboard-Config<= 2.4
Xkeyboard Config ProjectXkeyboard-Config2.0
Xkeyboard Config ProjectXkeyboard-Config2.1
Xkeyboard Config ProjectXkeyboard-Config2.2
Xkeyboard Config ProjectXkeyboard-Config2.3

References

Timeline

Published
Last Modified
Status
Modified

Frequently Asked Questions

What is CVE-2012-0064?
xkeyboard-config before 2.5 in X.Org before 7.6 enables certain XKB debugging functions by default, which allows physically proximate attackers to bypass an X screen lock via keyboard combinations that break the input grab.
How severe is CVE-2012-0064?
Severity scoring for CVE-2012-0064 is pending analysis. The EPSS model estimates a 0.39% probability of exploitation in the next 30 days.
How do I fix CVE-2012-0064?
Check the vendor references and advisories linked above for patched versions and mitigation guidance. You can also run a Strix scan to test if your systems are affected.

Are you affected by CVE-2012-0064?

Run a free Strix scan to check your systems for this vulnerability.

Scan your code now

Source: NVD / NIST