CVE-2003-1294 describes a vulnerability in Xscreensaver versions prior to 4.15, where several components insecurely create temporary files. This flaw allows a local attacker to perform a symlink attack, potentially overwriting arbitrary files on the system. The vulnerability has a low CVSS score of 2.1, indicating a low severity, as it requires local access and primarily impacts integrity (partial) without affecting confidentiality or availability. There is no evidence of active exploitation, public exploit code (Metasploit, Nuclei, ExploitDB), or significant community discussion or media coverage surrounding this CVE.
| Vendor | Product | Version(s) | CPE |
|---|---|---|---|
4.05_5clCPE matchmatch criteria | cpe:2.3:a:xscreensaver:xscreensaver:4.05_5cl:*:*:*:*:*:*:* | ||
4.05_6CPE matchmatch criteria | cpe:2.3:a:xscreensaver:xscreensaver:4.05_6:*:*:*:*:*:*:* | ||
4.05_6aCPE matchmatch criteria | cpe:2.3:a:xscreensaver:xscreensaver:4.05_6a:*:*:*:*:*:*:* | ||
4.05_150CPE matchmatch criteria | cpe:2.3:a:xscreensaver:xscreensaver:4.05_150:*:*:*:*:*:*:* | ||
4.07_2CPE matchmatch criteria | cpe:2.3:a:xscreensaver:xscreensaver:4.07_2:*:*:*:*:*:*:* |
CVSS version used by this source: 2.0
AV:L/AC:L/Au:N/C:N/I:P/A:N
The average CVE in this peer group has 0.0 Twitter, 0.0 Reddit, 0.0 Bluesky, 0.0 Mastodon, and 0.6 GitHub mentions.
No media coverage found for this CVE.
The average CVE in this peer group has 0.0 InfoSec Media, 0.0 Vendor Blog, and 0.0 Security Researcher mentions.