V
Scaner-VS
HomeCatalogSourcesCWECAPECATT&CKMitigationsProductsVendorsDocs
CVE-2023-49347
DEB
High

Temporary data passed between application components by Budgie Extras Windows Previews could potentially be viewed or manipulated. The data…

CVSS
7.8
High
EPSS
0.00
p21
Published
2023-01-01
Updated
2023-01-01
Description

Temporary data passed between application components by Budgie Extras Windows Previews could potentially be viewed or manipulated. The data is stored in a location that is accessible to any user who has local access to the system. Attackers may read private information from windows, present false information to users, or deny access to the application.

Tags · CWE
CWE-377
CAPEC-149
CAPEC-155
Affected products
Budgie_extras 1.4.0–1.7.1
CVSS vector
CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H
Timeline
2023-01-01
Published
2023-01-01
Updated
CVSS 3.1 breakdown
Attack Vector
AV: L
Local (L)
Attack Complexity
AC: L
Low (L)
Privileges Required
PR: L
Low (L)
User Interaction
UI: N
None (N)
Scope
S: U
Unchanged (U)
Confidentiality Impact
C: H
High (H)
Integrity Impact
I: H
High (H)
Availability Impact
A: H
High (H)
Exploit indicators
EPSS
0.003 · p21
Known exploited (KEV)
No
Known exploits — Сканер-ВС
No Сканер-ВС checks registered for this vulnerability yet.
Affected products
ProductVendorStatus
budgie-extrasTracked
budgie-extrasTracked
budgie-extrasTracked
budgie-extrasTracked
budgie-extrasTracked
budgie-extrasTracked
budgie-extrasTracked
budgie-extrasTracked
budgie-extrasTracked
budgie-extrasTracked
budgie_extras*Tracked
Source databases
DEB
CVE
UBU