CVE-2006-1335NULL Pointer Dereference in Screensaver

Severity
3.7LOWNVD
EPSS
0.1%
top 77.11%
CISA KEV
Not in KEV
Exploit
No known exploits
Affected products
Timeline
PublishedMar 21
Latest updateMay 1

Description

gnome screensaver before 2.14, when running on an X server with AllowDeactivateGrabs and AllowClosedownGrabs enabled, allows attackers with physical access to cause the screensaver to crash and access the session via the Ctl+Alt+Keypad-Multiply keyboard sequence, which removes the grab from gnome.

CVSS vector

AV:L/AC:H/C:P/I:P/A:PExploitability: 1.9 | Impact: 6.4

Affected Packages1 packages

🔴Vulnerability Details

3
GHSA
GHSA-5vmq-g86w-8p73: gnome screensaver before 22022-05-01
CVEList
CVE-2006-1335: gnome screensaver before 22006-03-21
OSV
CVE-2006-1335: gnome screensaver before 22006-03-21

📋Vendor Advisories

3
Red Hat
openssl: mime_hdr_cmp NULL dereference crash2006-08-29
Red Hat
openssl: mime_hdr_cmp NULL dereference crash2006-08-29
Debian
CVE-2006-1335: gnome-screensaver - gnome screensaver before 2.14, when running on an X server with AllowDeactivateG...2006

💬Community

1
Bugzilla
CVE-2006-7250 openssl: mime_hdr_cmp NULL dereference crash2012-02-28
CVE-2006-1335 — NULL Pointer Dereference in Screensaver | cvebase