
waycrate/swhkd
CVE History
| CVE | Published | CVSS v3 | CVSS v2 |
|---|---|---|---|
| 3.3 LOW | 2.1 LOW | ||
SWHKD 1.1.5 allows arbitrary file-existence tests via the -c option. | |||
| 4.4 MEDIUM | 3.6 LOW | ||
SWHKD 1.1.5 consumes the keyboard events of unintended users. This could potentially cause an information leak, but is usually a denial of functionality. | |||
| 9.1 CRITICAL | 6.4 MEDIUM | ||
SWHKD 1.1.5 unsafely uses the /tmp/swhkd.sock pathname. There can be an information leak or denial of service. | |||
| 5.3 MEDIUM | 4 MEDIUM | ||
SWHKD 1.1.5 allows unsafe parsing via the -c option. An information leak might occur but there is a simple denial of service (memory exhaustion) upon an attempt to parse a large or infinite file (such as a block or character device). | |||
| 7.1 HIGH | 3.3 LOW | ||
SWHKD 1.1.5 unsafely uses the /tmp/swhks.pid pathname. There can be data loss or a denial of service. | |||
| 7.8 HIGH | 6.2 MEDIUM | ||
SWHKD 1.1.5 unsafely uses the /tmp/swhkd.pid pathname. There can be an information leak or denial of service. | |||