CVE-2009-4996
Estado: ModificadaAlta (7.2)—
Xfce4-session 4.5.91 in Xfce does not lock the screen when the suspend or hibernate button is pressed, which might make it easier for physically proximate attackers to access an unattended laptop via a resume action, a related issue to CVE-2010-2532. NOTE: there is no general agreement that this is a vulnerability, because separate control over locking can be an equally secure, or more secure, behavior in some threat environments
CVSS
- Versión: 2.0
- Vector: AV:L/AC:L/Au:N/C:C/I:C/A:C
- Puntuación base: 7.2
Probabilidad de explotación (EPSS)
- Probabilidad de explotación en los próximos 30 días: 0.33%
- Percentil entre todas las CVEs puntuadas: 24
- Fecha de la puntuación: 6/10/2026
EPSS (Exploit Prediction Scoring System, de FIRST) estima la probabilidad de que una vulnerabilidad sea explotada en 30 días. Complementa a CVSS (impacto) y a CISA KEV (explotación confirmada).
Tecnologías afectadas (1)
CWE
- CWE-264
Referencias
- http://bugzilla.xfce.org/show_bug.cgi?id=4805
- https://bugzilla.redhat.com/show_bug.cgi?id=525395
- https://bugzilla.redhat.com/show_bug.cgi?id=587633
- https://bugzilla.redhat.com/show_bug.cgi?id=614608
- http://bugzilla.xfce.org/show_bug.cgi?id=4805
- https://bugzilla.redhat.com/show_bug.cgi?id=525395
- https://bugzilla.redhat.com/show_bug.cgi?id=587633
- https://bugzilla.redhat.com/show_bug.cgi?id=614608
JSON original (NVD)
Mostrar
{
"id": "CVE-2009-4996",
"cveTags": [
{
"tags": [
"disputed"
],
"sourceIdentifier": "cve@mitre.org"
}
],
"metrics": {
"cvssMetricV2": [
{
"type": "Primary",
"source": "nvd@nist.gov",
"cvssData": {
"version": "2.0",
"baseScore": 7.2,
"accessVector": "LOCAL",
"vectorString": "AV:L/AC:L/Au:N/C:C/I:C/A:C",
"authentication": "NONE",
"integrityImpact": "COMPLETE",
"accessComplexity": "LOW",
"availabilityImpact": "COMPLETE",
"confidentialityImpact": "COMPLETE"
},
"acInsufInfo": false,
"impactScore": 10,
"baseSeverity": "HIGH",
"obtainAllPrivilege": false,
"exploitabilityScore": 3.9,
"obtainUserPrivilege": false,
"obtainOtherPrivilege": false,
"userInteractionRequired": false
}
]
},
"affected": [
{
"source": "cve@mitre.org",
"affectedData": [
{
"vendor": "n/a",
"product": "n/a",
"versions": [
{
"status": "affected",
"version": "n/a"
}
]
}
]
}
],
"published": "2010-09-07T18:00:01.887",
"references": [
{
"url": "http://bugzilla.xfce.org/show_bug.cgi?id=4805",
"source": "cve@mitre.org"
},
{
"url": "https://bugzilla.redhat.com/show_bug.cgi?id=525395",
"source": "cve@mitre.org"
},
{
"url": "https://bugzilla.redhat.com/show_bug.cgi?id=587633",
"source": "cve@mitre.org"
},
{
"url": "https://bugzilla.redhat.com/show_bug.cgi?id=614608",
"source": "cve@mitre.org"
},
{
"url": "http://bugzilla.xfce.org/show_bug.cgi?id=4805",
"source": "af854a3a-2127-422b-91ae-364da2661108"
},
{
"url": "https://bugzilla.redhat.com/show_bug.cgi?id=525395",
"source": "af854a3a-2127-422b-91ae-364da2661108"
},
{
"url": "https://bugzilla.redhat.com/show_bug.cgi?id=587633",
"source": "af854a3a-2127-422b-91ae-364da2661108"
},
{
"url": "https://bugzilla.redhat.com/show_bug.cgi?id=614608",
"source": "af854a3a-2127-422b-91ae-364da2661108"
}
],
"vulnStatus": "Modified",
"weaknesses": [
{
"type": "Primary",
"source": "nvd@nist.gov",
"description": [
{
"lang": "en",
"value": "CWE-264"
}
]
}
],
"descriptions": [
{
"lang": "en",
"value": "Xfce4-session 4.5.91 in Xfce does not lock the screen when the suspend or hibernate button is pressed, which might make it easier for physically proximate attackers to access an unattended laptop via a resume action, a related issue to CVE-2010-2532. NOTE: there is no general agreement that this is a vulnerability, because separate control over locking can be an equally secure, or more secure, behavior in some threat environments"
},
{
"lang": "es",
"value": "** IMPUGNADA ** Xfce4-session en Xfce no bloquea la pantalla cuando se pulsa el botón de suspender o hibernar, lo que podría hacer más sencillo a atacantes fisicamente cercanos, acceder a un portátil desatendido a través de una acción de reactivación del equipo (\"resume action\"), un fallo relacionado con CVE-2010-2532. NOTA: no hay un acuerdo generalizado que confirme que se trate de una vulnerabilidad porque controles separados sobre bloqueo pueden ser comportamientos igual o más seguros en algunos entornos amenazados."
}
],
"lastModified": "2026-06-16T23:14:47.753",
"configurations": [
{
"nodes": [
{
"negate": false,
"cpeMatch": [
{
"criteria": "cpe:2.3:a:xfce:xfce:4.6:beta1:*:*:*:*:*:*",
"vulnerable": true,
"matchCriteriaId": "5A48BD5B-8412-45B7-A1D5-A4CD0067EE00"
}
],
"operator": "OR"
}
]
}
],
"sourceIdentifier": "cve@mitre.org"
}