Vulnerability Name: | CVE-2009-3746 (CCN-53937) | ||||||||
Assigned: | 2009-10-20 | ||||||||
Published: | 2009-10-20 | ||||||||
Updated: | 2017-09-19 | ||||||||
Summary: | XScreenSaver in Sun Solaris 10, when the accessibility feature is enabled, allows physically proximate attackers to obtain sensitive information by reading popup windows, which are displayed even when the screen is locked, a different vulnerability than CVE-2009-1276 and CVE-2009-2711. | ||||||||
CVSS v3 Severity: | 4.0 Medium (CCN CVSS v3.1 Vector: CVSS:3.1/AV:L/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:N)
| ||||||||
CVSS v2 Severity: | 1.9 Low (CVSS v2 Vector: AV:L/AC:M/Au:N/C:P/I:N/A:N) 1.4 Low (Temporal CVSS v2 Vector: AV:L/AC:M/Au:N/C:P/I:N/A:N/E:U/RL:OF/RC:C)
1.4 Low (CCN Temporal CVSS v2 Vector: AV:L/AC:M/Au:N/C:P/I:N/A:N/E:U/RL:OF/RC:C)
| ||||||||
Vulnerability Type: | CWE-16 | ||||||||
Vulnerability Consequences: | Obtain Information | ||||||||
References: | Source: MITRE Type: CNA CVE-2009-3746 Source: CCN Type: SA37248 Sun Solaris XScreenSaver Pop-up Windows Security Bypass Source: CONFIRM Type: Patch, Vendor Advisory http://sunsolve.sun.com/search/document.do?assetkey=1-21-120094-29-1 Source: CCN Type: Sun Alert ID: 268288 A regression introduced in the Solaris 10 XScreenSaver(see xscreensaver(1)) Source: SUNALERT Type: Patch, Vendor Advisory 268288 Source: CCN Type: BID-36910 Sun Solaris XScreenSaver Popup Windows Security Bypass Vulnerability Source: XF Type: UNKNOWN xscreensaver-popup-information-disclosure(53937) Source: OVAL Type: UNKNOWN oval:org.mitre.oval:def:6644 | ||||||||
Vulnerable Configuration: | Configuration 1: Configuration CCN 1: Denotes that component is vulnerable | ||||||||
Oval Definitions | |||||||||
| |||||||||
BACK |