CVE-2014-3204: Ayatana Project Unity

Medium severity, CVSS 4.4. EPSS: 0.5% chance of exploitation in the next 30 days.

Unity before 7.2.1, as used in Ubuntu 14.04, does not properly handle keyboard shortcuts, which allows physically proximate attackers to bypass the lock screen and execute arbitrary commands, as demonstrated by right-clicking on the indicator bar and then pressing the ALT and F2 keys.

Affected products

  • Ayatana Project Unity: up to and including 7.2.0; version 7.0.0 only; version 7.0.1 only; version 7.1.0 only; version 7.1.1 only; version 7.1.2 only; …
  • Canonical Ubuntu Linux: version 14.04 only

Published 2014-05-06. Last modified 2026-06-17.