RSS   Vulnerabilities for 'Swhkd'   RSS

2022-04-14
 
CVE-2022-27814

CWE-668
 

 
SWHKD 1.1.5 allows arbitrary file-existence tests via the -c option.

 
 
CVE-2022-27817

CWE-668
 

 
SWHKD 1.1.5 consumes the keyboard events of unintended users. This could potentially cause an information leak, but is usually a denial of functionality.

 
2022-04-07
 
CVE-2022-27818

CWE-668
 

 
SWHKD 1.1.5 unsafely uses the /tmp/swhkd.sock pathname. There can be an information leak or denial of service.

 
 
CVE-2022-27819

CWE-400
 

 
SWHKD 1.1.5 allows unsafe parsing via the -c option. An information leak might occur but there is a simple denial of service (memory exhaustion) upon an attempt to parse a large or infinite file (such as a block or character device).

 


Copyright 2024, cxsecurity.com

 

Back to Top