CVE-2009-3851

Solaris 10 - Unprotected User Data Exposure via XScreenSaver Daemon Interference

Title source: llm
STIX 2.1

Description

Trusted Extensions in Sun Solaris 10 interferes with the operation of the xscreensaver-demo command for the XScreenSaver application, which makes it easier for physically proximate attackers to access an unattended workstation for which the intended screen locking did not occur, related to the "restart daemon."

References (3)

Core 3
Core References
Third Party Advisory, VDB Entry vdb-entry signature x_refsource_oval
https://oval.cisecurity.org/repository/search/definition/oval%3Aorg.mitre.oval%3Adef%3A6845
Vendor Advisory vendor-advisory x_refsource_sunalert
http://sunsolve.sun.com/search/document.do?assetkey=1-66-270809-1

Scores

EPSS 0.0005
EPSS Percentile 16.9%

Details

Status published
Products (1)
sun/solaris 10.0 (2 CPE variants)
Published Nov 03, 2009
Tracked Since Feb 18, 2026