{"api_version":"1","generated_at":"2026-07-23T10:43:37+00:00","cve":"CVE-2014-5195","urls":{"html":"https://cve.report/CVE-2014-5195","api":"https://cve.report/api/cve/CVE-2014-5195.json","docs":"https://cve.report/api","cve_org":"https://www.cve.org/CVERecord?id=CVE-2014-5195","nvd":"https://nvd.nist.gov/vuln/detail/CVE-2014-5195"},"summary":{"title":"CVE-2014-5195","description":"Unity before 7.2.3 and 7.3.x before 7.3.1, as used in Ubuntu, does not properly take focus of the keyboard when switching to the lock screen, which allows physically proximate attackers to bypass the lock screen by (1) leveraging a machine that had text selected when locking or (2) resuming from a suspension.","state":"PUBLISHED","assigner":"mitre","published_at":"2014-08-07 11:13:37","updated_at":"2026-05-06 22:30:45"},"problem_types":["CWE-362","n/a"],"metrics":[{"version":"2.0","source":"nvd@nist.gov","type":"Primary","score":"7.2","severity":"","vector":"AV:L/AC:L/Au:N/C:C/I:C/A:C","data":{"version":"2.0","vectorString":"AV:L/AC:L/Au:N/C:C/I:C/A:C","baseScore":7.2,"accessVector":"LOCAL","accessComplexity":"LOW","authentication":"NONE","confidentialityImpact":"COMPLETE","integrityImpact":"COMPLETE","availabilityImpact":"COMPLETE"}}],"references":[{"url":"https://bugs.launchpad.net/unity/7.2/+bug/1349128","name":"https://bugs.launchpad.net/unity/7.2/+bug/1349128","refsource":"af854a3a-2127-422b-91ae-364da2661108","tags":[],"title":"Bug #1349128 “Ubuntu 14.04 lock screen doesn't accept keyboard i...” : Series 7.2 : Bugs : Unity","mime":"text/html","httpstatus":"200","archivestatus":"200"},{"url":"http://www.securityfocus.com/bid/68987","name":"http://www.securityfocus.com/bid/68987","refsource":"af854a3a-2127-422b-91ae-364da2661108","tags":[],"title":"Ubuntu 'Unity' Package Lock Screen Local Security Bypass Vulnerability","mime":"text/html","httpstatus":"200","archivestatus":"0"},{"url":"http://www.ubuntu.com/usn/USN-2303-1","name":"http://www.ubuntu.com/usn/USN-2303-1","refsource":"af854a3a-2127-422b-91ae-364da2661108","tags":[],"title":"USN-2303-1: Unity vulnerability | Ubuntu","mime":"text/html","httpstatus":"200","archivestatus":"200"},{"url":"https://exchange.xforce.ibmcloud.com/vulnerabilities/95199","name":"https://exchange.xforce.ibmcloud.com/vulnerabilities/95199","refsource":"af854a3a-2127-422b-91ae-364da2661108","tags":[],"title":"IBM X-Force Exchange","mime":"text/html","httpstatus":"200","archivestatus":"200"},{"url":"http://www.osvdb.org/109788","name":"http://www.osvdb.org/109788","refsource":"af854a3a-2127-422b-91ae-364da2661108","tags":[],"title":"","mime":"","httpstatus":"-1","archivestatus":"0"},{"url":"https://www.cve.org/CVERecord?id=CVE-2014-5195","name":"CVE Program record","refsource":"CVE.ORG","tags":["canonical"]},{"url":"https://nvd.nist.gov/vuln/detail/CVE-2014-5195","name":"NVD vulnerability detail","refsource":"NVD","tags":["canonical","analysis"]}],"affected":[{"source":"CNA","vendor":"n/a","product":"n/a","version":"affected n/a","platforms":[]}],"timeline":[],"solutions":[],"workarounds":[],"exploits":[],"credits":[],"nvd_cpes":[{"cve_year":"2014","cve_id":"5195","vulnerable":"1","versionEndIncluding":"","cpe1":"cpe","cpe2":"2.3","cpe3":"a","cpe4":"ayatana_project","cpe5":"unity","cpe6":"7.2.0","cpe7":"*","cpe8":"*","cpe9":"*","cpe10":"*","cpe11":"*","cpe12":"*","cpe13":"*"},{"cve_year":"2014","cve_id":"5195","vulnerable":"1","versionEndIncluding":"","cpe1":"cpe","cpe2":"2.3","cpe3":"a","cpe4":"ayatana_project","cpe5":"unity","cpe6":"7.2.1","cpe7":"*","cpe8":"*","cpe9":"*","cpe10":"*","cpe11":"*","cpe12":"*","cpe13":"*"},{"cve_year":"2014","cve_id":"5195","vulnerable":"1","versionEndIncluding":"","cpe1":"cpe","cpe2":"2.3","cpe3":"a","cpe4":"ayatana_project","cpe5":"unity","cpe6":"7.3.0","cpe7":"*","cpe8":"*","cpe9":"*","cpe10":"*","cpe11":"*","cpe12":"*","cpe13":"*"},{"cve_year":"2014","cve_id":"5195","vulnerable":"1","versionEndIncluding":"7.2.2","cpe1":"cpe","cpe2":"2.3","cpe3":"a","cpe4":"ayatana_project","cpe5":"unity","cpe6":"*","cpe7":"*","cpe8":"*","cpe9":"*","cpe10":"*","cpe11":"*","cpe12":"*","cpe13":"*"},{"cve_year":"2014","cve_id":"5195","vulnerable":"0","versionEndIncluding":"","cpe1":"cpe","cpe2":"2.3","cpe3":"o","cpe4":"canonical","cpe5":"ubuntu_linux","cpe6":"14.04","cpe7":"*","cpe8":"*","cpe9":"*","cpe10":"lts","cpe11":"*","cpe12":"*","cpe13":"*"}],"vendor_comments":[],"enrichments":{"kev":null,"epss":null,"legacy_qids":[]},"source_records":{"cve_program":{"containers":{"adp":[{"providerMetadata":{"dateUpdated":"2024-08-06T11:34:37.563Z","orgId":"af854a3a-2127-422b-91ae-364da2661108","shortName":"CVE"},"references":[{"name":"ubuntu-unity-screenlock-sec-bypass(95199)","tags":["vdb-entry","x_refsource_XF","x_transferred"],"url":"https://exchange.xforce.ibmcloud.com/vulnerabilities/95199"},{"name":"USN-2303-1","tags":["vendor-advisory","x_refsource_UBUNTU","x_transferred"],"url":"http://www.ubuntu.com/usn/USN-2303-1"},{"name":"68987","tags":["vdb-entry","x_refsource_BID","x_transferred"],"url":"http://www.securityfocus.com/bid/68987"},{"name":"109788","tags":["vdb-entry","x_refsource_OSVDB","x_transferred"],"url":"http://www.osvdb.org/109788"},{"tags":["x_refsource_CONFIRM","x_transferred"],"url":"https://bugs.launchpad.net/unity/7.2/+bug/1349128"}],"title":"CVE Program Container"}],"cna":{"affected":[{"product":"n/a","vendor":"n/a","versions":[{"status":"affected","version":"n/a"}]}],"datePublic":"2014-07-31T00:00:00.000Z","descriptions":[{"lang":"en","value":"Unity before 7.2.3 and 7.3.x before 7.3.1, as used in Ubuntu, does not properly take focus of the keyboard when switching to the lock screen, which allows physically proximate attackers to bypass the lock screen by (1) leveraging a machine that had text selected when locking or (2) resuming from a suspension."}],"problemTypes":[{"descriptions":[{"description":"n/a","lang":"en","type":"text"}]}],"providerMetadata":{"dateUpdated":"2017-09-07T15:57:01.000Z","orgId":"8254265b-2729-46b6-b9e3-3dfca2d5bfca","shortName":"mitre"},"references":[{"name":"ubuntu-unity-screenlock-sec-bypass(95199)","tags":["vdb-entry","x_refsource_XF"],"url":"https://exchange.xforce.ibmcloud.com/vulnerabilities/95199"},{"name":"USN-2303-1","tags":["vendor-advisory","x_refsource_UBUNTU"],"url":"http://www.ubuntu.com/usn/USN-2303-1"},{"name":"68987","tags":["vdb-entry","x_refsource_BID"],"url":"http://www.securityfocus.com/bid/68987"},{"name":"109788","tags":["vdb-entry","x_refsource_OSVDB"],"url":"http://www.osvdb.org/109788"},{"tags":["x_refsource_CONFIRM"],"url":"https://bugs.launchpad.net/unity/7.2/+bug/1349128"}],"x_legacyV4Record":{"CVE_data_meta":{"ASSIGNER":"cve@mitre.org","ID":"CVE-2014-5195","STATE":"PUBLIC"},"affects":{"vendor":{"vendor_data":[{"product":{"product_data":[{"product_name":"n/a","version":{"version_data":[{"version_value":"n/a"}]}}]},"vendor_name":"n/a"}]}},"data_format":"MITRE","data_type":"CVE","data_version":"4.0","description":{"description_data":[{"lang":"eng","value":"Unity before 7.2.3 and 7.3.x before 7.3.1, as used in Ubuntu, does not properly take focus of the keyboard when switching to the lock screen, which allows physically proximate attackers to bypass the lock screen by (1) leveraging a machine that had text selected when locking or (2) resuming from a suspension."}]},"problemtype":{"problemtype_data":[{"description":[{"lang":"eng","value":"n/a"}]}]},"references":{"reference_data":[{"name":"ubuntu-unity-screenlock-sec-bypass(95199)","refsource":"XF","url":"https://exchange.xforce.ibmcloud.com/vulnerabilities/95199"},{"name":"USN-2303-1","refsource":"UBUNTU","url":"http://www.ubuntu.com/usn/USN-2303-1"},{"name":"68987","refsource":"BID","url":"http://www.securityfocus.com/bid/68987"},{"name":"109788","refsource":"OSVDB","url":"http://www.osvdb.org/109788"},{"name":"https://bugs.launchpad.net/unity/7.2/+bug/1349128","refsource":"CONFIRM","url":"https://bugs.launchpad.net/unity/7.2/+bug/1349128"}]}}}},"cveMetadata":{"assignerOrgId":"8254265b-2729-46b6-b9e3-3dfca2d5bfca","assignerShortName":"mitre","cveId":"CVE-2014-5195","datePublished":"2014-08-07T10:00:00.000Z","dateReserved":"2014-08-07T00:00:00.000Z","dateUpdated":"2024-08-06T11:34:37.563Z","state":"PUBLISHED"},"dataType":"CVE_RECORD","dataVersion":"5.1"},"nvd":{"publishedDate":"2014-08-07 11:13:37","lastModifiedDate":"2026-05-06 22:30:45","problem_types":["CWE-362","n/a"],"metrics":{"cvssMetricV2":[{"source":"nvd@nist.gov","type":"Primary","cvssData":{"version":"2.0","vectorString":"AV:L/AC:L/Au:N/C:C/I:C/A:C","baseScore":7.2,"accessVector":"LOCAL","accessComplexity":"LOW","authentication":"NONE","confidentialityImpact":"COMPLETE","integrityImpact":"COMPLETE","availabilityImpact":"COMPLETE"},"baseSeverity":"HIGH","exploitabilityScore":3.9,"impactScore":10,"acInsufInfo":false,"obtainAllPrivilege":false,"obtainUserPrivilege":false,"obtainOtherPrivilege":false,"userInteractionRequired":false}]},"configurations":[{"operator":"AND","nodes":[{"operator":"OR","negate":false,"cpeMatch":[{"vulnerable":true,"criteria":"cpe:2.3:a:ayatana_project:unity:*:*:*:*:*:*:*:*","versionEndIncluding":"7.2.2","matchCriteriaId":"06405E5B-496D-48F7-9B01-61E4B38857DC"},{"vulnerable":true,"criteria":"cpe:2.3:a:ayatana_project:unity:7.2.0:*:*:*:*:*:*:*","matchCriteriaId":"993D6701-1899-4758-A3DB-50AA9AD9EC73"},{"vulnerable":true,"criteria":"cpe:2.3:a:ayatana_project:unity:7.2.1:*:*:*:*:*:*:*","matchCriteriaId":"4700B93F-776C-4040-B61B-374B16FCBA96"},{"vulnerable":true,"criteria":"cpe:2.3:a:ayatana_project:unity:7.3.0:*:*:*:*:*:*:*","matchCriteriaId":"2DC6342E-B85C-4870-ADAE-5FD53A973C3D"}]},{"operator":"OR","negate":false,"cpeMatch":[{"vulnerable":false,"criteria":"cpe:2.3:o:canonical:ubuntu_linux:14.04:*:*:*:lts:*:*:*","matchCriteriaId":"B5A6F2F3-4894-4392-8296-3B8DD2679084"}]}]}]},"legacy_mitre":{"record":{"CveYear":"2014","CveId":"5195","Ordinal":"1","Title":"CVE-2014-5195","CVE":"CVE-2014-5195","Year":"2014"},"notes":[{"CveYear":"2014","CveId":"5195","Ordinal":"1","NoteData":"Unity before 7.2.3 and 7.3.x before 7.3.1, as used in Ubuntu, does not properly take focus of the keyboard when switching to the lock screen, which allows physically proximate attackers to bypass the lock screen by (1) leveraging a machine that had text selected when locking or (2) resuming from a suspension.","Type":"Description","Title":"CVE-2014-5195"},{"CveYear":"2014","CveId":"5195","Ordinal":"2","NoteData":"2014-08-07","Type":"Other","Title":"Published"},{"CveYear":"2014","CveId":"5195","Ordinal":"3","NoteData":"2017-09-07","Type":"Other","Title":"Modified"}]}}}