CVE-2009-1276
published 2009-04-09CVE-2009-1276: XScreenSaver in Sun Solaris 10 and OpenSolaris before snv_109, and Solaris 8 and 9 with GNOME 2.0 or 2.0.2, allows physically proximate attackers to obtain…
PriorityP44low2.1CVSS 2.0
AVLACLAuNCPINAN
EPSS
0.37%
29.5th percentile
XScreenSaver in Sun Solaris 10 and OpenSolaris before snv_109, and Solaris 8 and 9 with GNOME 2.0 or 2.0.2, allows physically proximate attackers to obtain sensitive information by reading popup windows, which are displayed even when the screen is locked, as demonstrated by Thunderbird new-mail notifications.
Affected
126 ranges· showing 25
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| sun | opensolaris | <= snv_108 | — |
| sun | opensolaris | — | — |
| sun | opensolaris | — | — |
| sun | opensolaris | — | — |
| sun | opensolaris | — | — |
| sun | opensolaris | — | — |
| sun | opensolaris | — | — |
| sun | opensolaris | — | — |
| sun | opensolaris | — | — |
| sun | opensolaris | — | — |
| sun | opensolaris | — | — |
| sun | opensolaris | — | — |
| sun | opensolaris | — | — |
| sun | opensolaris | — | — |
| sun | opensolaris | — | — |
| sun | opensolaris | — | — |
| sun | opensolaris | — | — |
| sun | opensolaris | — | — |
| sun | opensolaris | — | — |
| sun | opensolaris | — | — |
| sun | opensolaris | — | — |
| sun | opensolaris | — | — |
| sun | opensolaris | — | — |
| sun | opensolaris | — | — |
| sun | opensolaris | — | — |
Stop checking back — get the weekly exploitation signal.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
GHSA
GHSA-h96c-vv5w-hqpj: XScreenSaver in Sun Solaris 10 and OpenSolaris before snv_109, and Solaris 8 and 9 with GNOME 2
ghsa_unreviewed·2022-05-02
CVE-2009-1276 [LOW] CWE-200 GHSA-h96c-vv5w-hqpj: XScreenSaver in Sun Solaris 10 and OpenSolaris before snv_109, and Solaris 8 and 9 with GNOME 2
XScreenSaver in Sun Solaris 10 and OpenSolaris before snv_109, and Solaris 8 and 9 with GNOME 2.0 or 2.0.2, allows physically proximate attackers to obtain sensitive information by reading popup windows, which are displayed even when the screen is locked, as demonstrated by Thunderbird new-mail notifications.
GHSA
GHSA-xxfr-xhcv-m89f: XScreenSaver in Sun Solaris 9 and 10, OpenSolaris before snv_120, and X11 6
ghsa_unreviewed·2022-05-02·CVSS 2.1
CVE-2009-2711 [LOW] CWE-200 GHSA-xxfr-xhcv-m89f: XScreenSaver in Sun Solaris 9 and 10, OpenSolaris before snv_120, and X11 6
XScreenSaver in Sun Solaris 9 and 10, OpenSolaris before snv_120, and X11 6.4.1 for Solaris 8, when the Xorg or Xnewt server is used, allows physically proximate attackers to obtain sensitive information by reading popup windows, which are displayed even when the screen is locked, a different vulnerability than CVE-2009-1276.
GHSA
GHSA-gm75-mfx6-2q8j: XScreenSaver in Sun Solaris 10, when the accessibility feature is enabled, allows physically proximate attackers to obtain sensitive information by re
ghsa_unreviewed·2022-05-02·CVSS 2.1
CVE-2009-3746 [LOW] GHSA-gm75-mfx6-2q8j: XScreenSaver in Sun Solaris 10, when the accessibility feature is enabled, allows physically proximate attackers to obtain sensitive information by re
XScreenSaver in Sun Solaris 10, when the accessibility feature is enabled, allows physically proximate attackers to obtain sensitive information by reading popup windows, which are displayed even when the screen is locked, a different vulnerability than CVE-2009-1276 and CVE-2009-2711.
No detection rules found.
No public exploits indexed.
No writeups or analysis indexed.
http://securitytracker.com/id?1022009http://sunsolve.sun.com/search/document.do?assetkey=1-21-120094-22-1http://sunsolve.sun.com/search/document.do?assetkey=1-66-255308-1http://www.securityfocus.com/bid/34421http://www.vupen.com/english/advisories/2009/0978http://securitytracker.com/id?1022009http://sunsolve.sun.com/search/document.do?assetkey=1-21-120094-22-1http://sunsolve.sun.com/search/document.do?assetkey=1-66-255308-1http://www.securityfocus.com/bid/34421http://www.vupen.com/english/advisories/2009/0978
2009-04-09
Published