First published: Thu Apr 09 2009(Updated: )
XScreenSaver in Sun Solaris 10 and OpenSolaris before snv_109, and Solaris 8 and 9 with GNOME 2.0 or 2.0.2, allows physically proximate attackers to obtain sensitive information by reading popup windows, which are displayed even when the screen is locked, as demonstrated by Thunderbird new-mail notifications.
Credit: cve@mitre.org
Affected Software | Affected Version | How to fix |
---|---|---|
GNOME | =2.0 | |
GNOME | =2.0.2 | |
Oracle Solaris and Zettabyte File System (ZFS) | <=snv_108 | |
Oracle Solaris and Zettabyte File System (ZFS) | =snv_01 | |
Oracle Solaris and Zettabyte File System (ZFS) | =snv_02 | |
Oracle Solaris and Zettabyte File System (ZFS) | =snv_03 | |
Oracle Solaris and Zettabyte File System (ZFS) | =snv_04 | |
Oracle Solaris and Zettabyte File System (ZFS) | =snv_05 | |
Oracle Solaris and Zettabyte File System (ZFS) | =snv_06 | |
Oracle Solaris and Zettabyte File System (ZFS) | =snv_07 | |
Oracle Solaris and Zettabyte File System (ZFS) | =snv_08 | |
Oracle Solaris and Zettabyte File System (ZFS) | =snv_09 | |
Oracle Solaris and Zettabyte File System (ZFS) | =snv_10 | |
Oracle Solaris and Zettabyte File System (ZFS) | =snv_11 | |
Oracle Solaris and Zettabyte File System (ZFS) | =snv_12 | |
Oracle Solaris and Zettabyte File System (ZFS) | =snv_13 | |
Oracle Solaris and Zettabyte File System (ZFS) | =snv_14 | |
Oracle Solaris and Zettabyte File System (ZFS) | =snv_15 | |
Oracle Solaris and Zettabyte File System (ZFS) | =snv_16 | |
Oracle Solaris and Zettabyte File System (ZFS) | =snv_17 | |
Oracle Solaris and Zettabyte File System (ZFS) | =snv_18 | |
Oracle Solaris and Zettabyte File System (ZFS) | =snv_19 | |
Oracle Solaris and Zettabyte File System (ZFS) | =snv_20 | |
Oracle Solaris and Zettabyte File System (ZFS) | =snv_21 | |
Oracle Solaris and Zettabyte File System (ZFS) | =snv_22 | |
Oracle Solaris and Zettabyte File System (ZFS) | =snv_23 | |
Oracle Solaris and Zettabyte File System (ZFS) | =snv_24 | |
Oracle Solaris and Zettabyte File System (ZFS) | =snv_25 | |
Oracle Solaris and Zettabyte File System (ZFS) | =snv_26 | |
Oracle Solaris and Zettabyte File System (ZFS) | =snv_27 | |
Oracle Solaris and Zettabyte File System (ZFS) | =snv_28 | |
Oracle Solaris and Zettabyte File System (ZFS) | =snv_29 | |
Oracle Solaris and Zettabyte File System (ZFS) | =snv_30 | |
Oracle Solaris and Zettabyte File System (ZFS) | =snv_31 | |
Oracle Solaris and Zettabyte File System (ZFS) | =snv_32 | |
Oracle Solaris and Zettabyte File System (ZFS) | =snv_33 | |
Oracle Solaris and Zettabyte File System (ZFS) | =snv_34 | |
Oracle Solaris and Zettabyte File System (ZFS) | =snv_35 | |
Oracle Solaris and Zettabyte File System (ZFS) | =snv_36 | |
Oracle Solaris and Zettabyte File System (ZFS) | =snv_37 | |
Oracle Solaris and Zettabyte File System (ZFS) | =snv_38 | |
Oracle Solaris and Zettabyte File System (ZFS) | =snv_39 | |
Oracle Solaris and Zettabyte File System (ZFS) | =snv_40 | |
Oracle Solaris and Zettabyte File System (ZFS) | =snv_41 | |
Oracle Solaris and Zettabyte File System (ZFS) | =snv_42 | |
Oracle Solaris and Zettabyte File System (ZFS) | =snv_43 | |
Oracle Solaris and Zettabyte File System (ZFS) | =snv_44 | |
Oracle Solaris and Zettabyte File System (ZFS) | =snv_45 | |
Oracle Solaris and Zettabyte File System (ZFS) | =snv_46 | |
Oracle Solaris and Zettabyte File System (ZFS) | =snv_47 | |
Oracle Solaris and Zettabyte File System (ZFS) | =snv_48 | |
Oracle Solaris and Zettabyte File System (ZFS) | =snv_49 | |
Oracle Solaris and Zettabyte File System (ZFS) | =snv_50 | |
Oracle Solaris and Zettabyte File System (ZFS) | =snv_51 | |
Oracle Solaris and Zettabyte File System (ZFS) | =snv_52 | |
Oracle Solaris and Zettabyte File System (ZFS) | =snv_53 | |
Oracle Solaris and Zettabyte File System (ZFS) | =snv_54 | |
Oracle Solaris and Zettabyte File System (ZFS) | =snv_55 | |
Oracle Solaris and Zettabyte File System (ZFS) | =snv_56 | |
Oracle Solaris and Zettabyte File System (ZFS) | =snv_57 | |
Oracle Solaris and Zettabyte File System (ZFS) | =snv_58 | |
Oracle Solaris and Zettabyte File System (ZFS) | =snv_59 | |
Oracle Solaris and Zettabyte File System (ZFS) | =snv_60 | |
Oracle Solaris and Zettabyte File System (ZFS) | =snv_61 | |
Oracle Solaris and Zettabyte File System (ZFS) | =snv_62 | |
Oracle Solaris and Zettabyte File System (ZFS) | =snv_63 | |
Oracle Solaris and Zettabyte File System (ZFS) | =snv_64 | |
Oracle Solaris and Zettabyte File System (ZFS) | =snv_65 | |
Oracle Solaris and Zettabyte File System (ZFS) | =snv_66 | |
Oracle Solaris and Zettabyte File System (ZFS) | =snv_67 | |
Oracle Solaris and Zettabyte File System (ZFS) | =snv_68 | |
Oracle Solaris and Zettabyte File System (ZFS) | =snv_69 | |
Oracle Solaris and Zettabyte File System (ZFS) | =snv_70 | |
Oracle Solaris and Zettabyte File System (ZFS) | =snv_71 | |
Oracle Solaris and Zettabyte File System (ZFS) | =snv_72 | |
Oracle Solaris and Zettabyte File System (ZFS) | =snv_73 | |
Oracle Solaris and Zettabyte File System (ZFS) | =snv_74 | |
Oracle Solaris and Zettabyte File System (ZFS) | =snv_75 | |
Oracle Solaris and Zettabyte File System (ZFS) | =snv_76 | |
Oracle Solaris and Zettabyte File System (ZFS) | =snv_77 | |
Oracle Solaris and Zettabyte File System (ZFS) | =snv_78 | |
Oracle Solaris and Zettabyte File System (ZFS) | =snv_79 | |
Oracle Solaris and Zettabyte File System (ZFS) | =snv_80 | |
Oracle Solaris and Zettabyte File System (ZFS) | =snv_81 | |
Oracle Solaris and Zettabyte File System (ZFS) | =snv_82 | |
Oracle Solaris and Zettabyte File System (ZFS) | =snv_83 | |
Oracle Solaris and Zettabyte File System (ZFS) | =snv_84 | |
Oracle Solaris and Zettabyte File System (ZFS) | =snv_85 | |
Oracle Solaris and Zettabyte File System (ZFS) | =snv_86 | |
Oracle Solaris and Zettabyte File System (ZFS) | =snv_87 | |
Oracle Solaris and Zettabyte File System (ZFS) | =snv_88 | |
Oracle Solaris and Zettabyte File System (ZFS) | =snv_89 | |
Oracle Solaris and Zettabyte File System (ZFS) | =snv_90 | |
Oracle Solaris and Zettabyte File System (ZFS) | =snv_91 | |
Oracle Solaris and Zettabyte File System (ZFS) | =snv_92 | |
Oracle Solaris and Zettabyte File System (ZFS) | =snv_93 | |
Oracle Solaris and Zettabyte File System (ZFS) | =snv_94 | |
Oracle Solaris and Zettabyte File System (ZFS) | =snv_95 | |
Oracle Solaris and Zettabyte File System (ZFS) | =snv_96 | |
Oracle Solaris and Zettabyte File System (ZFS) | =snv_97 | |
Oracle Solaris and Zettabyte File System (ZFS) | =snv_98 | |
Oracle Solaris and Zettabyte File System (ZFS) | =snv_99 | |
Oracle Solaris and Zettabyte File System (ZFS) | =snv_100 | |
Oracle Solaris and Zettabyte File System (ZFS) | =snv_101 | |
Oracle Solaris and Zettabyte File System (ZFS) | =snv_102 | |
Oracle Solaris and Zettabyte File System (ZFS) | =snv_103 | |
Oracle Solaris and Zettabyte File System (ZFS) | =snv_104 | |
Oracle Solaris and Zettabyte File System (ZFS) | =snv_105 | |
Oracle Solaris and Zettabyte File System (ZFS) | =snv_106 | |
Oracle Solaris and Zettabyte File System (ZFS) | =snv_107 | |
Oracle Solaris and Zettabyte File System (ZFS) | =8 | |
Oracle Solaris and Zettabyte File System (ZFS) | =9 | |
Oracle Solaris and Zettabyte File System (ZFS) | =10 | |
Oracle Solaris and Zettabyte File System (ZFS) | <=snv_108 | |
Oracle Solaris and Zettabyte File System (ZFS) | =snv_01 | |
Oracle Solaris and Zettabyte File System (ZFS) | =snv_02 | |
Oracle Solaris and Zettabyte File System (ZFS) | =snv_03 | |
Oracle Solaris and Zettabyte File System (ZFS) | =snv_04 | |
Oracle Solaris and Zettabyte File System (ZFS) | =snv_05 | |
Oracle Solaris and Zettabyte File System (ZFS) | =snv_06 | |
Oracle Solaris and Zettabyte File System (ZFS) | =snv_07 | |
Oracle Solaris and Zettabyte File System (ZFS) | =snv_08 | |
Oracle Solaris and Zettabyte File System (ZFS) | =snv_09 | |
Oracle Solaris and Zettabyte File System (ZFS) | =snv_10 | |
Oracle Solaris and Zettabyte File System (ZFS) | =snv_11 | |
Oracle Solaris and Zettabyte File System (ZFS) | =snv_12 | |
Oracle Solaris and Zettabyte File System (ZFS) | =snv_13 | |
Oracle Solaris and Zettabyte File System (ZFS) | =snv_14 | |
Oracle Solaris and Zettabyte File System (ZFS) | =snv_15 | |
Oracle Solaris and Zettabyte File System (ZFS) | =snv_16 | |
Oracle Solaris and Zettabyte File System (ZFS) | =snv_17 | |
Oracle Solaris and Zettabyte File System (ZFS) | =snv_18 | |
Oracle Solaris and Zettabyte File System (ZFS) | =snv_19 | |
Oracle Solaris and Zettabyte File System (ZFS) | =snv_20 | |
Oracle Solaris and Zettabyte File System (ZFS) | =snv_21 | |
Oracle Solaris and Zettabyte File System (ZFS) | =snv_22 | |
Oracle Solaris and Zettabyte File System (ZFS) | =snv_23 | |
Oracle Solaris and Zettabyte File System (ZFS) | =snv_24 | |
Oracle Solaris and Zettabyte File System (ZFS) | =snv_25 | |
Oracle Solaris and Zettabyte File System (ZFS) | =snv_26 | |
Oracle Solaris and Zettabyte File System (ZFS) | =snv_27 | |
Oracle Solaris and Zettabyte File System (ZFS) | =snv_28 | |
Oracle Solaris and Zettabyte File System (ZFS) | =snv_29 | |
Oracle Solaris and Zettabyte File System (ZFS) | =snv_30 | |
Oracle Solaris and Zettabyte File System (ZFS) | =snv_31 | |
Oracle Solaris and Zettabyte File System (ZFS) | =snv_32 | |
Oracle Solaris and Zettabyte File System (ZFS) | =snv_33 | |
Oracle Solaris and Zettabyte File System (ZFS) | =snv_34 | |
Oracle Solaris and Zettabyte File System (ZFS) | =snv_35 | |
Oracle Solaris and Zettabyte File System (ZFS) | =snv_36 | |
Oracle Solaris and Zettabyte File System (ZFS) | =snv_37 | |
Oracle Solaris and Zettabyte File System (ZFS) | =snv_38 | |
Oracle Solaris and Zettabyte File System (ZFS) | =snv_39 | |
Oracle Solaris and Zettabyte File System (ZFS) | =snv_40 | |
Oracle Solaris and Zettabyte File System (ZFS) | =snv_41 | |
Oracle Solaris and Zettabyte File System (ZFS) | =snv_42 | |
Oracle Solaris and Zettabyte File System (ZFS) | =snv_43 | |
Oracle Solaris and Zettabyte File System (ZFS) | =snv_44 | |
Oracle Solaris and Zettabyte File System (ZFS) | =snv_45 | |
Oracle Solaris and Zettabyte File System (ZFS) | =snv_46 | |
Oracle Solaris and Zettabyte File System (ZFS) | =snv_47 | |
Oracle Solaris and Zettabyte File System (ZFS) | =snv_48 | |
Oracle Solaris and Zettabyte File System (ZFS) | =snv_49 | |
Oracle Solaris and Zettabyte File System (ZFS) | =snv_50 | |
Oracle Solaris and Zettabyte File System (ZFS) | =snv_51 | |
Oracle Solaris and Zettabyte File System (ZFS) | =snv_52 | |
Oracle Solaris and Zettabyte File System (ZFS) | =snv_53 | |
Oracle Solaris and Zettabyte File System (ZFS) | =snv_54 | |
Oracle Solaris and Zettabyte File System (ZFS) | =snv_55 | |
Oracle Solaris and Zettabyte File System (ZFS) | =snv_56 | |
Oracle Solaris and Zettabyte File System (ZFS) | =snv_57 | |
Oracle Solaris and Zettabyte File System (ZFS) | =snv_58 | |
Oracle Solaris and Zettabyte File System (ZFS) | =snv_59 | |
Oracle Solaris and Zettabyte File System (ZFS) | =snv_60 | |
Oracle Solaris and Zettabyte File System (ZFS) | =snv_61 | |
Oracle Solaris and Zettabyte File System (ZFS) | =snv_62 | |
Oracle Solaris and Zettabyte File System (ZFS) | =snv_63 | |
Oracle Solaris and Zettabyte File System (ZFS) | =snv_64 | |
Oracle Solaris and Zettabyte File System (ZFS) | =snv_65 | |
Oracle Solaris and Zettabyte File System (ZFS) | =snv_66 | |
Oracle Solaris and Zettabyte File System (ZFS) | =snv_67 | |
Oracle Solaris and Zettabyte File System (ZFS) | =snv_68 | |
Oracle Solaris and Zettabyte File System (ZFS) | =snv_69 | |
Oracle Solaris and Zettabyte File System (ZFS) | =snv_70 | |
Oracle Solaris and Zettabyte File System (ZFS) | =snv_71 | |
Oracle Solaris and Zettabyte File System (ZFS) | =snv_72 | |
Oracle Solaris and Zettabyte File System (ZFS) | =snv_73 | |
Oracle Solaris and Zettabyte File System (ZFS) | =snv_74 | |
Oracle Solaris and Zettabyte File System (ZFS) | =snv_75 | |
Oracle Solaris and Zettabyte File System (ZFS) | =snv_76 | |
Oracle Solaris and Zettabyte File System (ZFS) | =snv_77 | |
Oracle Solaris and Zettabyte File System (ZFS) | =snv_78 | |
Oracle Solaris and Zettabyte File System (ZFS) | =snv_79 | |
Oracle Solaris and Zettabyte File System (ZFS) | =snv_80 | |
Oracle Solaris and Zettabyte File System (ZFS) | =snv_81 | |
Oracle Solaris and Zettabyte File System (ZFS) | =snv_82 | |
Oracle Solaris and Zettabyte File System (ZFS) | =snv_83 | |
Oracle Solaris and Zettabyte File System (ZFS) | =snv_84 | |
Oracle Solaris and Zettabyte File System (ZFS) | =snv_85 | |
Oracle Solaris and Zettabyte File System (ZFS) | =snv_86 | |
Oracle Solaris and Zettabyte File System (ZFS) | =snv_87 | |
Oracle Solaris and Zettabyte File System (ZFS) | =snv_88 | |
Oracle Solaris and Zettabyte File System (ZFS) | =snv_89 | |
Oracle Solaris and Zettabyte File System (ZFS) | =snv_90 | |
Oracle Solaris and Zettabyte File System (ZFS) | =snv_91 | |
Oracle Solaris and Zettabyte File System (ZFS) | =snv_92 | |
Oracle Solaris and Zettabyte File System (ZFS) | =snv_93 | |
Oracle Solaris and Zettabyte File System (ZFS) | =snv_94 | |
Oracle Solaris and Zettabyte File System (ZFS) | =snv_95 | |
Oracle Solaris and Zettabyte File System (ZFS) | =snv_96 | |
Oracle Solaris and Zettabyte File System (ZFS) | =snv_97 | |
Oracle Solaris and Zettabyte File System (ZFS) | =snv_98 | |
Oracle Solaris and Zettabyte File System (ZFS) | =snv_99 | |
Oracle Solaris and Zettabyte File System (ZFS) | =snv_100 | |
Oracle Solaris and Zettabyte File System (ZFS) | =snv_101 | |
Oracle Solaris and Zettabyte File System (ZFS) | =snv_102 | |
Oracle Solaris and Zettabyte File System (ZFS) | =snv_103 | |
Oracle Solaris and Zettabyte File System (ZFS) | =snv_104 | |
Oracle Solaris and Zettabyte File System (ZFS) | =snv_105 | |
Oracle Solaris and Zettabyte File System (ZFS) | =snv_106 | |
Oracle Solaris and Zettabyte File System (ZFS) | =snv_107 | |
Oracle Solaris and Zettabyte File System (ZFS) | =8 | |
Oracle Solaris and Zettabyte File System (ZFS) | =9 | |
Oracle Solaris and Zettabyte File System (ZFS) | =10 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2009-1276 has been classified as a medium severity vulnerability due to its potential to expose sensitive information.
CVE-2009-1276 can be exploited by physically proximate attackers who can access the screen containing locked popup windows.
To mitigate CVE-2009-1276, users should update their XScreenSaver and related software to the latest versions where this vulnerability is addressed.
CVE-2009-1276 affects various versions of Sun Solaris and OpenSolaris, particularly versions before snv_109, and Solaris 8 and 9 with GNOME versions 2.0 or 2.0.2.
CVE-2009-1276 allows attackers to read sensitive information displayed in popup windows, such as email notifications, while the screen is locked.