LOW🇬🇧 English

CVE-2009-1276

CVSS 2.1v2.0pub. 2009-04-09upd. 2026-04-23

XScreenSaver w Sun Solaris 10 i OpenSolaris przed snv_109, a także w Solaris 8 i 9 z GNOME 2.0 lub 2.0.2, umożliwia atakującym o dostępie fizycznym uzyskanie wrażliwych informacji poprzez odczytanie okien popup, które są wyświetlane nawet gdy ekran jest zablokowany, co zostało zademonstrowane na przykładzie powiadomień o nowych wiadomościach w Thunderbirdzie.

Pokaż oryginał (EN)

XScreenSaver in Sun Solaris 10 and OpenSolaris before snv_109, and Solaris 8 and 9 with GNOME 2.0 or 2.0.2, allows physically proximate attackers to obtain sensitive information by reading popup windows, which are displayed even when the screen is locked, as demonstrated by Thunderbird new-mail notifications.

CVSS Vector
AV:L/AC:L/Au:N/C:P/I:N/A:N
  • Gnome

    APP
    Gnome
    2.02.0.2
  • Sun Opensolaris

    OS
    Sun
    snv_01snv_02snv_03snv_04snv_05snv_06snv_07snv_08snv_09snv_10snv_11snv_12snv_13snv_14snv_15+ 83 więcej
🔵
ZWERYFIKUJ U PRODUCENTA
Brak jednoznacznych danych o patchu. Sprawdź referencje od producenta.
CWE
Referencje

Powiązane podatności

CVE-2016-1291CRITICAL9.8PL ✓ten sam produkt

RCE przez deserializację w Cisco Prime Infrastructure i EPNM

CVE-2016-1329CRITICAL9.8PL ✓ten sam produkt

Cisco NX-OS: Hardcoded credentials umożliwiające zdalny dostęp root

CVE-2015-6319CRITICAL9.8PL ✓ten sam produkt

SQL injection w interfejsie zarządzania Cisco RV220W

CVE-2015-6313HIGH7.5ten sam produkt

Cisco TelePresence Server 4.1(2.29) through 4.2(4.17) on 7010; Mobility Services Engine (MSE) 8710; Multiparty...

CVE-2016-1290HIGH8.1ten sam produkt

The web API in Cisco Prime Infrastructure 1.2.0 through 2.2(2) and Cisco Evolved Programmable Network Manager ...