CVE-2015-1308

Severity CVSS v4.0:
Pending analysis
Type:
CWE-200 Information Leak / Disclosure
Publication date:
26/01/2015
Last modified:
12/04/2025

Description

kde-workspace 4.2.0 and plasma-workspace before 5.1.95 allows remote attackers to obtain input events, and consequently obtain passwords, by leveraging access to the X server when the screen is locked.

Vulnerable products and versions

CPE From Up to
cpe:2.3:a:kde:plasma-workspace:*:*:*:*:*:*:*:* 5.1 (including)
cpe:2.3:a:kde:kde-workspace:*:*:*:*:*:*:*:* 4.2.0 (including)