Vulnerabilidades
Resumen — últimos 7 días
Vulnerabilidades nuevas2517▼ 423 respecto a la semana anterior
Críticas / altas1296▲ 12 respecto a la semana anterior
Nueva explotación activa (KEV)6▼ 5 respecto a la semana anterior
Sin puntuar (sin CVSS)57▼ 471 respecto a la semana anterior
24 resultados, ordenados por fecha de publicación (más recientes primero)
| CVE | Estado | Severidad | EPSS | Explotación activa | Tecnologías afectadas | Publicada ▼ | Modificada | Descripción |
|---|---|---|---|---|---|---|---|---|
| Modificada | Media (4.6) | 0.48% | — | Xscreensaver Project XscreensaverFedoraproject Fedora | 10/6/2021 | 17/6/2026 | XScreenSaver 5.45 can be bypassed if the machine has more than ten disconnectable video outputs. A buffer overflow in update_screen_layout() allows an attacker to bypass the standard screen lock authentication mechanism by crashing XScreenSaver. The attacker must physically disconnect many video outputs. | |
| Modificada | Alta (7.8) | 0.32% | — | Xscreensaver Project Xscreensaver | 21/4/2021 | 17/6/2026 | The Debian xscreensaver 5.42+dfsg1-1 package for XScreenSaver has cap_net_raw enabled for the /usr/libexec/xscreensaver/sonar file, which allows local users to gain privileges because this is arguably incompatible with the design of the Mesa 3D Graphics library dependency. | |
| Modificada | Alta (7.8) | 0.48% | — | Xscreensaver Project XscreensaverDebian Linux | 27/11/2019 | 16/6/2026 | xscreensaver before 5.14 crashes during activation and leaves the screen unlocked when in Blank Only Mode and when DPMS is disabled, which allows local attackers to access resources without authentication. | |
| Modificada | Media (6.1) | 0.58% | — | Mate-desktop Mate-screensaver | 9/1/2019 | 17/6/2026 | mate-screensaver before 1.20.2 in MATE Desktop Environment allows physically proximate attackers to view screen content and possibly control applications. By unplugging and re-plugging or power-cycling external output devices (such as additionally attached graphical outputs via HDMI, VGA, DVI, etc.) the content of a… | |
| Modificada | Alta (7.8) | 1.4% | — | Jasdf Screensavers | 9/6/2017 | 17/6/2026 | Untrusted search path vulnerability in screensaver installers (jasdf_01.exe, jasdf_02.exe, jasdf_03.exe, jasdf_04.exe, jasdf_05.exe, scramble_setup.exe, clock_01_setup.exe, clock_02_setup.exe) available prior to May 25, 2017 allows an attacker to gain privileges via a Trojan horse DLL in an unspecified directory. | |
| Modificada | Baja (2.1) | 0.51% | — | Canonical Ubuntu LinuxXscreensaver Project Xscreensaver | 10/11/2015 | 17/6/2026 | driver/subprocs.c in XScreenSaver before 5.34 does not properly perform an internal consistency check, which allows physically proximate attackers to bypass the lock screen by hot swapping monitors. | |
| Modificada | Alta (7.2) | 0.38% | — | Gnome Screensaver | 8/3/2013 | 16/6/2026 | The default configuration in gnome-screensaver 3.5.4 through 3.6.0 sets the AutostartCondition line to fallback mode in the .desktop file, which prevents the program from starting automatically after login and allows physically proximate attackers to bypass screen locking and access an unattended workstation. | |
| Modificada | Baja (3.3) | 0.34% | — | Gnome Screensaver | 7/8/2012 | 16/6/2026 | gnome-screensaver 3.4.x before 3.4.4 and 3.5.x before 3.5.4, when multiple screens are used, only locks the screen with the active focus, which allows physically proximate attackers to bypass screen locking and access an unattended workstation. | |
| Modificada | Media (6.2) | 0.30% | — | Gnome GTKGnome Screensaver | 19/3/2010 | 16/6/2026 | gdk/gdkwindow.c in GTK+ before 2.18.5, as used in gnome-screensaver before 2.28.1, performs implicit paints on windows of type GDK_WINDOW_FOREIGN, which triggers an X error in certain circumstances and consequently allows physically proximate attackers to bypass screen locking and access an unattended workstation by… | |
| Modificada | Media (4) | 0.36% | — | Gnome Screensaver | 24/2/2010 | 16/6/2026 | gnome-screensaver 2.28.x before 2.28.3 does not properly synchronize the state of screen locking and the unlock dialog in situations involving a change to the number of monitors, which allows physically proximate attackers to bypass screen locking and access an unattended workstation by connecting and disconnecting… | |
| Modificada | Media (5.6) | 0.30% | — | Gnome Screensaver | 24/2/2010 | 16/6/2026 | gnome-screensaver 2.14.3, 2.22.2, 2.27.x, 2.28.0, and 2.28.3, when the X configuration enables the extend screen option, allows physically proximate attackers to bypass screen locking, access an unattended workstation, and view half of the GNOME desktop by attaching an external monitor. | |
| Modificada | Alta (7.2) | 0.34% | — | Gnome Screensaver | 11/2/2010 | 16/6/2026 | gnome-screensaver 2.26.1 relies on the gnome-session D-Bus interface to determine session idle time, even when an Xfce desktop such as Xubuntu or Mythbuntu is used, which allows physically proximate attackers to access an unattended workstation on which screen locking had been intended. | |
| Modificada | Alta (7.2) | 0.37% | — | Gnome Screensaver | 11/2/2010 | 16/6/2026 | gnome-screensaver 2.28.0 does not resume adherence to its activation settings after an inhibiting application becomes unavailable on the session bus, which allows physically proximate attackers to access an unattended workstation on which screen locking had been intended. | |
| Modificada | Alta (7.2) | 0.42% | — | Gnome Screensaver | 11/2/2010 | 16/6/2026 | gnome-screensaver before 2.28.2 allows physically proximate attackers to bypass screen locking and access an unattended workstation by moving the mouse position to an external monitor and then disconnecting that monitor. | |
| Modificada | Media (4.7) | 1.3% | — | Gnome Screensaver | 6/4/2008 | 16/6/2026 | gnome-screensaver before 2.22.1, when a remote authentication server is enabled, crashes upon an unlock attempt during a network outage, which allows physically proximate attackers to gain access to the locked session, a related issue to CVE-2007-1859. | |
| Modificada | Baja (2.1) | 0.37% | — | Gnome Screensaver | 17/12/2007 | 16/6/2026 | The notify feature in GNOME screensaver (gnome-screensaver) 2.20.0 might allow local users to read the clipboard contents and X selection data for a locked session by using ctrl-V. | |
| Modificada | Media (6.2) | 0.36% | — | CompizGnome Screensaver | 29/10/2007 | 16/6/2026 | GNOME screensaver 2.20 in Ubuntu 7.10, when used with Compiz, does not properly reserve input focus, which allows attackers with physical access to take control of the session after entering an Alt-Tab sequence, a related issue to CVE-2007-3069. | |
| Modificada | Media (5) | 1.7% | — | Xscreensaver | 19/10/2007 | 16/6/2026 | xscreensaver 5.03 and earlier, when running without xscreensaver-gl-extras (GL extras) installed, crashes when /usr/bin/xscreensaver-gl-helper does not exist and a user attempts to unlock the screen, which allows attackers with physical access to gain access to the locked session. | |
| Modificada | Media (4.6) | 0.41% | — | Xscreensaver | 2/5/2007 | 16/6/2026 | XScreenSaver 4.10, when using a remote directory service for credentials, does not properly handle the results from the getpwuid function in drivers/lock.c when there is no network connectivity, which causes XScreenSaver to crash and unlock the screen and allows local users to bypass authentication. | |
| Modificada | Alta (7.5) | 4.5% | — | AOL YGP Screensaver Activex Control | 10/10/2006 | 16/6/2026 | Buffer overflow in AOL You've Got Pictures (YGP) Screensaver ActiveX control allows remote attackers to execute arbitrary code via unspecified vectors. | |
| Modificada | Baja (3.7) | 0.34% | — | Gnome Screensaver | 21/3/2006 | 16/6/2026 | gnome screensaver before 2.14, when running on an X server with AllowDeactivateGrabs and AllowClosedownGrabs enabled, allows attackers with physical access to cause the screensaver to crash and access the session via the Ctl+Alt+Keypad-Multiply keyboard sequence, which removes the grab from gnome. | |
| Modificada | Media (5.4) | 2.3% | — | Xscreensaver | 31/12/2004 | 16/6/2026 | rdesktop 1.3.1 with xscreensaver 4.14, and possibly other versions, when running on Fedora and possibly other platforms, does not release the keyboard focus when xscreensaver starts, which causes the password to be entered into the active window when the user unlocks the screen. | |
| Modificada | Media (6.4) | 1.3% | — | Xscreensaver | 31/12/2003 | 16/6/2026 | Xscreensaver 4.14 contains certain debugging code that should have been omitted, which causes Xscreensaver to create temporary files insecurely in the (1) apple2, (2) xanalogtv, and (3) pong screensavers, and allows local users to overwrite arbitrary files via a symlink attack. | |
| Modificada | Baja (2.1) | 0.43% | — | Xscreensaver | 31/12/2003 | 16/6/2026 | Xscreensaver before 4.15 creates temporary files insecurely in (1) driver/passwd-kerberos.c, (2) driver/xscreensaver-getimage-video, (3) driver/xscreensaver.kss.in, and the (4) vidwhacker and (5) webcollage screensavers, which allows local users to overwrite arbitrary files via a symlink attack. |