Ibus Project develops an input-method framework widely used in Linux desktop and server environments to enable multilingual text input, and its vulnerability footprint concentrates in the core ibus product around access-control and authorization boundaries. The observed weakness class, missing authorization, reflects the architectural sensitivity of input-handling components that operate across user sessions and system-level interfaces. Current severity, exploitation activity, and exposure counts are shown alongside this summary.
The number and severity of CVEs published that impact products developed by Ibus Project over time
Signals from CVEs in this vendor scope (2 CVEs).
2 CVEs · Highest risk first
| CVE | Published | CVSS | Risk | KEV | Exploit |
|---|---|---|---|---|---|
CVE-2019-14822HIGH A flaw was discovered in ibus in versions before 1.5.22 that allows any unprivileged user to monitor and send method calls to the ibus bus of another user due to a misconfiguration | Nov 25, 2019 | 7.1 | 24 | NO | NO |
The default configuration of IBUS 1.5.4, and possibly 1.5.2 and earlier, when IBus.InputPurpose.PASSWORD is not set and used with GNOME 3, does not obscure the entered password cha | Nov 23, 2013 | 1.9 | 11 | NO | NO |
Signals from CVEs in this vendor scope (2 CVEs).
An overview of all social media posts that mention a CVE ID that affects a product developed by Ibus Project.
Media articles that mention a CVE ID that affects a product developed by Ibus Project — matched by CVE ID, not by vendor name.