kde-workspace 4.2.0 and plasma-workspace before 5.1.95 allows remote attackers to obtain input events, and consequently obtain passwords, by leveraging access to the X server when the screen is locked.
https://www.kde.org/info/security/advisory-20150122-2.txt
http://www.securityfocus.com/bid/72284