Screensaver

Vendor:

First CVE: Mar 21, 2006 · Active for 20 years

11
Total CVEs
More Total CVEs than 90% of tracked products
2.2
Avg CVEs / Year
Higher CVE frequency than 76% of tracked products
5.2
Avg CVSS
Higher Avg CVSS than 12% of tracked products
0.0%
KEV Rate
Bottom 1%

Trends Over Time

The number and severity of CVEs published that impact Screensaver over time

Volume of CVEsAvg CVSS Base Score
First CVE
Mar 21, 2006
20 years ago
Most Recent CVE
Aug 7, 2012
5,103 days ago

CVE Severity & Scoring

Screensaver11 CVEs
All CVEs353,173 CVEs
LowMediumHigh
Attack Vector
Local0 (0.0%)
Network0 (0.0%)
Unknown11 (100.0%)
Physical0 (0.0%)
Adjacent Network0 (0.0%)
Attack Complexity
Low0 (0.0%)
High0 (0.0%)
Unknown11 (100.0%)
User Interaction
None0 (0.0%)
Unknown11 (100.0%)
Required0 (0.0%)
Privileges Required
Low0 (0.0%)
High0 (0.0%)
None0 (0.0%)
Unknown11 (100.0%)

Top CVEs

Signals from CVEs in this product scope (11 CVEs).

11 CVEs · Highest risk first

CVEPublishedCVSSRiskKEVExploit
gnome-screensaver before 2.28.2 allows physically proximate attackers to bypass screen locking and access an unattended workstation by moving the mouse position to an external moni
Feb 11, 20107.222NONO
gnome-screensaver 2.26.1 relies on the gnome-session D-Bus interface to determine session idle time, even when an Xfce desktop such as Xubuntu or Mythbuntu is used, which allows ph
Feb 11, 20107.220NONO
gnome-screensaver 2.28.0 does not resume adherence to its activation settings after an inhibiting application becomes unavailable on the session bus, which allows physically proxim
Feb 11, 20107.220NONO
gdk/gdkwindow.c in GTK+ before 2.18.5, as used in gnome-screensaver before 2.28.1, performs implicit paints on windows of type GDK_WINDOW_FOREIGN, which triggers an X error in cert
Mar 19, 20106.219NONO
gnome-screensaver 2.14.3, 2.22.2, 2.27.x, 2.28.0, and 2.28.3, when the X configuration enables the extend screen option, allows physically proximate attackers to bypass screen lock
Feb 24, 20105.619NONO
GNOME screensaver 2.20 in Ubuntu 7.10, when used with Compiz, does not properly reserve input focus, which allows attackers with physical access to take control of the session afte
Oct 29, 20076.217NONO
gnome-screensaver 2.28.x before 2.28.3 does not properly synchronize the state of screen locking and the unlock dialog in situations involving a change to the number of monitors, w
Feb 24, 20104.016NONO
gnome-screensaver before 2.22.1, when a remote authentication server is enabled, crashes upon an unlock attempt during a network outage, which allows physically proximate attackers
Apr 6, 20084.716NONO
gnome-screensaver 3.4.x before 3.4.4 and 3.5.x before 3.5.4, when multiple screens are used, only locks the screen with the active focus, which allows physically proximate attacker
Aug 7, 20123.315NONO
gnome screensaver before 2.14, when running on an X server with AllowDeactivateGrabs and AllowClosedownGrabs enabled, allows attackers with physical access to cause the screensaver
Mar 21, 20063.714NONO

Exploit Exposure

Signals from CVEs in this product scope (11 CVEs).

CISA KEV
0 CVEs
0.0% of CVEs· Bottom 1%
Metasploit
0 CVEs
0.0% of CVEs· Bottom 1%
Nuclei
0 CVEs
0.0% of CVEs· Bottom 1%
ExploitDB
0 CVEs
0.0% of CVEs· Bottom 1%

Social Chatter

Signals from CVEs in this product scope (11 CVEs).

Media Mentions

Signals from CVEs in this product scope (11 CVEs).

Top CNAs Publishing CVEs For Screensaver

Top CWEs

Versions

VersionCVE CountAvg CVSSAvg EPSSKEVExploits
3.5.313.30.3%00
3.4.313.30.3%00
3.4.213.30.3%00
3.4.013.30.3%00
2.28.315.60.3%00
2.28.214.00.4%00
2.28.114.00.4%00
2.28.046.00.4%00
2.2715.60.3%00
2.26.127.20.4%00
2.22.215.60.3%00
2.20.017.20.4%00
2.2035.20.4%00
2.14.315.60.3%00
2.1317.20.4%00