← Vulnerability feed

Vulnerability record · CVE-2014-1949 · published 16 January 2015

CVE-2014-1949: Linuxmint linux mint improper access control vulnerability

Linuxmint · Linux Mint

GTK+ 3.10.9 and earlier, as used in cinnamon-screensaver, gnome-screensaver, and other applications, allows physically proximate attackers to bypass the lock screen by pressing the menu button.

7.2 CVSS 2.0 High EPSS 0.33% · top 75.8% CWE-284 · Improper access control
7.2CVSS 2.0 base score
0.33%EPSS exploitation probability, 30 days
NoNot in CISA KEV
3Affected product versions listed by NVD
16References
17 Jun 2026Last modified by NVD

Description

GTK+ 3.10.9 and earlier, as used in cinnamon-screensaver, gnome-screensaver, and other applications, allows physically proximate attackers to bypass the lock screen by pressing the menu button.

AV:L/AC:L/Au:N/C:C/I:C/A:C

Affected products

3 vulnerable configurations from NVD's CPE data, grouped by vendor and product.

References

Track CVE-2014-1949 inside VULONE

Watch it alongside the ransomware crews, C2 infrastructure and forum chatter that reference it, query it through the API and pull it into your SIEM over TAXII.

Start free Open in platform

Related vulnerabilities

Same products first, then exploited flaws of the same weakness class.

9.8CVE-2012-0828Gnome gtk out-of-bounds write vulnerabilityHeap-based buffer overflow in Xchat-WDK before 1499-4 (2012-01-18) xchat 2.8.6 on Maemo architecture could allow remote attackers to cause a denial o…EPSS 4.3%9.3CVE-2010-4833Gnome gtk untrusted search path vulnerabilityUntrusted search path vulnerability in modules/engines/ms-windows/xp_theme.c in GTK+ before 2.24.0 allows local users to gain privileges via a Trojan…EPSS 2.0%7.8CVE-2005-2975Gnome gdkpixbuf vulnerabilityio-xpm.c in the gdk-pixbuf XPM image rendering library in GTK+ before 2.8.7 allows attackers to cause a denial of service (infinite loop) via a craft…EPSS 3.7%7.5CVE-2005-2976Gnome gdkpixbuf integer overflow vulnerabilityInteger overflow in io-xpm.c in gdk-pixbuf 0.22.0 in GTK+ before 2.8.7 allows attackers to cause a denial of service (crash) or execute arbitrary cod…EPSS 4.5%7.5CVE-2005-0891Gnome gtk double free vulnerabilityDouble free vulnerability in gtk 2 (gtk2) before 2.2.4 allows remote attackers to cause a denial of service (crash) via a crafted BMP image.EPSS 3.5%7.5CVE-2004-0782Gnome gdkpixbuf vulnerabilityInteger overflow in pixbuf_create_from_xpm (io-xpm.c) in the XPM image decoder for gtk+ 2.4.4 (gtk2) and earlier, and gdk-pixbuf before 0.22, allows …EPSS 9.2%7.5CVE-2004-0783Gnome gdkpixbuf out-of-bounds write vulnerabilityStack-based buffer overflow in xpm_extract_color (io-xpm.c) in the XPM image decoder for gtk+ 2.4.4 (gtk2) and earlier, and gdk-pixbuf before 0.22, m…EPSS 9.4%7.2CVE-2001-0084Gnome gtk vulnerabilityGTK+ library allows local users to specify arbitrary modules via the GTK_MODULES environmental variable, which could allow local users to gain privil…EPSS 1.0%

Source: NIST National Vulnerability Database (record CVE-2014-1949), CISA KEV, FIRST EPSS (scores of 2026-09-27). This page is refreshed as NVD updates the record.