CVE-2004-2655 describes a vulnerability in rdesktop 1.3.1, and potentially other versions, when used with xscreensaver 4.14 on Fedora and similar platforms. The flaw allows a user's password to be entered into the active window upon unlocking the screen because keyboard focus is not properly released by xscreensaver. With a CVSS score of 5.4 (AV:N/AC:H/Au:N/C:C/I:N/A:N), this vulnerability has a high confidentiality impact but requires high attack complexity. There is no evidence of active exploitation, public exploit code, or Metasploit modules, though it has garnered significant community discussion.
| Vendor | Product | Version(s) | CPE |
|---|---|---|---|
4.14CPE matchmatch criteria | cpe:2.3:a:xscreensaver:xscreensaver:4.14:*:*:*:*:*:*:* | ||
4.16CPE matchmatch criteria | cpe:2.3:a:xscreensaver:xscreensaver:4.16:*:*:*:*:*:*:* | ||
4.17CPE matchmatch criteria | cpe:2.3:a:xscreensaver:xscreensaver:4.17:*:*:*:*:*:*:* |
CVSS version used by this source: 2.0
AV:N/AC:H/Au:N/C:C/I:N/A:N
The average CVE in this peer group has 0.0 Twitter, 0.0 Reddit, 0.0 Bluesky, 0.0 Mastodon, and 0.2 GitHub mentions.
No media coverage found for this CVE.
The average CVE in this peer group has 0.0 InfoSec Media, 0.0 Vendor Blog, and 0.0 Security Researcher mentions.