GNOME screensaver 2.20 in Ubuntu 7.10, when used with Compiz, does not properly reserve input focus, which allows attackers with physical access to take control of the session after entering an Alt-Tab sequence, a related issue to CVE-2007-3069.
Conclusion & alert: CVE-2007-3920 is rated Low Risk (29.1/100): CVSS Medium severity, with low exploitation likelihood (EPSS 0.05%). Mandatory action: Monitor for updates and reassess as exploit intelligence or EPSS changes.
Risk is dynamic; we continuously reassess and refresh what is shown on this page as upstream context changes.
EPSS lead: Daily EPSS estimates relative likelihood of exploitation; percentile ranks this CVE among scored vulnerabilities (higher = more severe relative rank).
| # | Date | Old EPSS score | New EPSS score | Delta (New - Old) |
|---|---|---|---|---|
| 1 | 2025-03-17 | 0.28% | 0.05% | -0.23% |
| 2 | 2024-04-01 | 0.25% | 0.28% | +0.03% |
| 3 | 2023-03-07 | — | 0.25% | — |
Full EPSS history (4 records total)
CVSS metrics for this CVE.
| Base score | Version | Severity | Vector | Exploitability | Impact | Score source |
|---|---|---|---|---|---|---|
| 6.2 | 2.0 | MEDIUM |
|
1.9 | 10.0 | [email protected] |
| vendor | priority | summary | link |
|---|---|---|---|
debian
|
medium | CVE-2007-3920 medium priority: Debian including 2 source packages (gnome-screensaver, xorg-server), 8 status rows across 5 suites (bookworm, bullseye, forky, sid, trixie): resolved 8. | https://security-tracker.debian.org/tracker/CVE-2007-3920 |
redhat
|
low | — | https://access.redhat.com/security/cve/CVE-2007-3920 |
ubuntu
|
medium | CVE-2007-3920 medium priority: Ubuntu including 2 source packages (compiz, gnome-screensaver), 7 status rows across 5 suites (dapper, edgy, feisty, gutsy, upstream): released 4, not-affected 3. | https://ubuntu.com/security/CVE-2007-3920 |
This issue affected Red Hat Enterprise Linux 5 with a low security impact. An update to the compiz package was released to correct this issue: https://rhn.redhat.com/errata/RHSA-2008-0485.html
| Vendor | Product | Version | Raw CPE |
|---|---|---|---|
| compiz | compiz | — | cpe:2.3:a:compiz:compiz:*:*:*:*:*:*:*:* |
| gnome | screensaver | 2.20 | cpe:2.3:a:gnome:screensaver:2.20:*:*:*:*:*:*:* |