Uim is a niche input method framework with a focused vulnerability footprint centered on its core product. The associated disclosures reflect generic or uncategorized weakness patterns typical of early-stage or limited-scope vulnerability tracking. Current severity, exploitation, and exposure counts are shown alongside this summary.
The number and severity of CVEs published that impact products developed by Uim over time
Signals from CVEs in this vendor scope (2 CVEs).
2 CVEs · Highest risk first
| CVE | Published | CVSS | Risk | KEV | Exploit |
|---|---|---|---|---|---|
CVE-2005-3149MEDIUM Uim 0.4.x before 0.4.9.1 and 0.5.0 and earlier does not properly handle the LIBUIM_VANILLA environment variable when a suid or sgid application is linked to libuim, such as immodul | Oct 5, 2005 | 4.6 | 14 | NO | NO |
CVE-2005-0503MEDIUM uim before 0.4.5.1 trusts certain environment variables when libUIM is used in setuid or setgid applications, which allows local users to gain privileges. | Feb 21, 2005 | 4.6 | 14 | NO | NO |
Signals from CVEs in this vendor scope (2 CVEs).
An overview of all social media posts that mention a CVE ID that affects a product developed by Uim.
Media articles that mention a CVE ID that affects a product developed by Uim — matched by CVE ID, not by vendor name.