CVE-2008-6514
Status: ModifiedMedium (6.2)—
The Expo plugin in Compiz Fusion 0.7.8 allows local users with physical access to drag the screen saver aside and access the locked desktop by using Expo mouse shortcuts, a related issue to CVE-2007-3920.
CVSS
- Version: 2.0
- Vector: AV:L/AC:H/Au:N/C:C/I:C/A:C
- Base score: 6.2
Exploitation probability (EPSS)
- Probability of exploitation in the next 30 days: 0.41%
- Percentile among all scored CVEs: 34
- Score date: 10/9/2026
EPSS (Exploit Prediction Scoring System, FIRST) estimates how likely a vulnerability is to be exploited in the wild within 30 days. It complements CVSS (impact) and CISA KEV (confirmed exploitation).
Affected technologies (1)
CWEs
- CWE-264
References
- http://bugzilla.gnome.org/show_bug.cgi?id=561567
- http://gitweb.compiz-fusion.org/?p=fusion/plugins/expo%3Ba=commit%3Bh=f97a9fa6f0ad578f674d1f248bd7bef90e3260e0
- http://secunia.com/advisories/33077
- http://secunia.com/advisories/34465
- http://www.securityfocus.com/bid/32712
- https://bugs.launchpad.net/ubuntu/+source/compiz-fusion-plugins-main/+bug/247088
- https://exchange.xforce.ibmcloud.com/vulnerabilities/47172
- https://www.redhat.com/archives/fedora-package-announce/2009-March/msg00860.html
- https://www.redhat.com/archives/fedora-package-announce/2009-March/msg00878.html
- http://bugzilla.gnome.org/show_bug.cgi?id=561567
- http://gitweb.compiz-fusion.org/?p=fusion/plugins/expo%3Ba=commit%3Bh=f97a9fa6f0ad578f674d1f248bd7bef90e3260e0
- http://secunia.com/advisories/33077
- http://secunia.com/advisories/34465
- http://www.securityfocus.com/bid/32712
- https://bugs.launchpad.net/ubuntu/+source/compiz-fusion-plugins-main/+bug/247088
- https://exchange.xforce.ibmcloud.com/vulnerabilities/47172
- https://www.redhat.com/archives/fedora-package-announce/2009-March/msg00860.html
- https://www.redhat.com/archives/fedora-package-announce/2009-March/msg00878.html
Raw JSON (NVD)
Show
{
"id": "CVE-2008-6514",
"cveTags": [],
"metrics": {
"cvssMetricV2": [
{
"type": "Primary",
"source": "nvd@nist.gov",
"cvssData": {
"version": "2.0",
"baseScore": 6.2,
"accessVector": "LOCAL",
"vectorString": "AV:L/AC:H/Au:N/C:C/I:C/A:C",
"authentication": "NONE",
"integrityImpact": "COMPLETE",
"accessComplexity": "HIGH",
"availabilityImpact": "COMPLETE",
"confidentialityImpact": "COMPLETE"
},
"acInsufInfo": false,
"impactScore": 10,
"baseSeverity": "MEDIUM",
"obtainAllPrivilege": false,
"exploitabilityScore": 1.9,
"obtainUserPrivilege": false,
"obtainOtherPrivilege": false,
"userInteractionRequired": false
}
]
},
"affected": [
{
"source": "cve@mitre.org",
"affectedData": [
{
"vendor": "n/a",
"product": "n/a",
"versions": [
{
"status": "affected",
"version": "n/a"
}
]
}
]
}
],
"published": "2009-03-24T14:30:00.233",
"references": [
{
"url": "http://bugzilla.gnome.org/show_bug.cgi?id=561567",
"source": "cve@mitre.org"
},
{
"url": "http://gitweb.compiz-fusion.org/?p=fusion/plugins/expo%3Ba=commit%3Bh=f97a9fa6f0ad578f674d1f248bd7bef90e3260e0",
"source": "cve@mitre.org"
},
{
"url": "http://secunia.com/advisories/33077",
"tags": [
"Vendor Advisory"
],
"source": "cve@mitre.org"
},
{
"url": "http://secunia.com/advisories/34465",
"source": "cve@mitre.org"
},
{
"url": "http://www.securityfocus.com/bid/32712",
"tags": [
"Patch"
],
"source": "cve@mitre.org"
},
{
"url": "https://bugs.launchpad.net/ubuntu/+source/compiz-fusion-plugins-main/+bug/247088",
"tags": [
"Exploit"
],
"source": "cve@mitre.org"
},
{
"url": "https://exchange.xforce.ibmcloud.com/vulnerabilities/47172",
"source": "cve@mitre.org"
},
{
"url": "https://www.redhat.com/archives/fedora-package-announce/2009-March/msg00860.html",
"source": "cve@mitre.org"
},
{
"url": "https://www.redhat.com/archives/fedora-package-announce/2009-March/msg00878.html",
"source": "cve@mitre.org"
},
{
"url": "http://bugzilla.gnome.org/show_bug.cgi?id=561567",
"source": "af854a3a-2127-422b-91ae-364da2661108"
},
{
"url": "http://gitweb.compiz-fusion.org/?p=fusion/plugins/expo%3Ba=commit%3Bh=f97a9fa6f0ad578f674d1f248bd7bef90e3260e0",
"source": "af854a3a-2127-422b-91ae-364da2661108"
},
{
"url": "http://secunia.com/advisories/33077",
"tags": [
"Vendor Advisory"
],
"source": "af854a3a-2127-422b-91ae-364da2661108"
},
{
"url": "http://secunia.com/advisories/34465",
"source": "af854a3a-2127-422b-91ae-364da2661108"
},
{
"url": "http://www.securityfocus.com/bid/32712",
"tags": [
"Patch"
],
"source": "af854a3a-2127-422b-91ae-364da2661108"
},
{
"url": "https://bugs.launchpad.net/ubuntu/+source/compiz-fusion-plugins-main/+bug/247088",
"tags": [
"Exploit"
],
"source": "af854a3a-2127-422b-91ae-364da2661108"
},
{
"url": "https://exchange.xforce.ibmcloud.com/vulnerabilities/47172",
"source": "af854a3a-2127-422b-91ae-364da2661108"
},
{
"url": "https://www.redhat.com/archives/fedora-package-announce/2009-March/msg00860.html",
"source": "af854a3a-2127-422b-91ae-364da2661108"
},
{
"url": "https://www.redhat.com/archives/fedora-package-announce/2009-March/msg00878.html",
"source": "af854a3a-2127-422b-91ae-364da2661108"
}
],
"vulnStatus": "Modified",
"weaknesses": [
{
"type": "Primary",
"source": "nvd@nist.gov",
"description": [
{
"lang": "en",
"value": "CWE-264"
}
]
}
],
"descriptions": [
{
"lang": "en",
"value": "The Expo plugin in Compiz Fusion 0.7.8 allows local users with physical access to drag the screen saver aside and access the locked desktop by using Expo mouse shortcuts, a related issue to CVE-2007-3920."
},
{
"lang": "es",
"value": "El plugin Expo en Compiz Fusion v0.7.8 permite a usuarios locales con acceso físico, arrastrar a un lado el salvapantallas y acceder al escritorio bloqueado mediante el uso de los atajos de teclado de Expo, relacionado con CVE-2007-3920."
}
],
"lastModified": "2026-06-16T23:02:22.140",
"configurations": [
{
"nodes": [
{
"negate": false,
"cpeMatch": [
{
"criteria": "cpe:2.3:a:compiz:compiz_fusion:0.7.8:*:*:*:*:*:*:*",
"vulnerable": true,
"matchCriteriaId": "8BC4142D-1AF7-4031-BF33-8DF26EBD0E57"
}
],
"operator": "OR"
}
]
}
],
"sourceIdentifier": "cve@mitre.org"
}