CVE-2009-3432

Unspecified vulnerability in xscreensaver in Sun Solaris 10, and OpenSolaris before snv_112, when Xorg or Xnewt is used and RandR is enabled, allows physically proximate attackers to read a locked screen via unknown vectors related to XRandR resize events.

Published: 2009-09-28 Last update: 2026-04-23 Assigner: [email protected] Source: [email protected]

Conclusion & alert: CVE-2009-3432 is rated Low Risk (16.8/100): CVSS Low severity, with low exploitation likelihood (EPSS 0.34%). Mandatory action: Low composite risk—no urgent action required; patch on your normal maintenance cycle and revisit priority if CVSS or EPSS increases.

Risk is dynamic; we continuously reassess and refresh what is shown on this page as upstream context changes.

Exploit prediction scoring system (EPSS) score for CVE-2009-3432

EPSS lead: Daily EPSS estimates relative likelihood of exploitation; percentile ranks this CVE among scored vulnerabilities (higher = more severe relative rank).

# Date Old EPSS score New EPSS score Delta (New - Old)
1 2026-06-15 0.07% 0.34% +0.27%
2 2023-03-07 1.10% 0.07% -1.04%
3 2022-02-04 1.10%

Full EPSS history (3 records total)

Common vulnerability scoring system (CVSS) metrics for CVE-2009-3432

CVSS metrics for this CVE.

Base score Version Severity Vector Exploitability Impact Score source
1.9 2.0 LOW
AV:L/AC:M/Au:N/C:P/I:N/A:N Click to expand
Access vector (AV:L)
Requires local access to the target system.
Access complexity (AC:M)
Exploitation needs some favorable conditions, but not exceptional ones.
Authentication (AU:N)
No authentication is required.
Confidentiality impact (C:P)
Partial confidentiality impact.
Integrity impact (I:N)
No integrity impact.
Availability impact (A:N)
No availability impact.
3.4 2.9 [email protected]

Weakness enumeration for CVE-2009-3432

Affected software / configurations for CVE-2009-3432

Vendor Product Version Raw CPE
sun opensolaris <= snv_111 cpe:2.3:o:sun:opensolaris:*:*:sparc:*:*:*:*:*
sun opensolaris <= snv_111 cpe:2.3:o:sun:opensolaris:*:*:x86:*:*:*:*:*
sun opensolaris snv_01 cpe:2.3:o:sun:opensolaris:snv_01:*:sparc:*:*:*:*:*
sun opensolaris snv_01 cpe:2.3:o:sun:opensolaris:snv_01:*:x86:*:*:*:*:*
sun opensolaris snv_02 cpe:2.3:o:sun:opensolaris:snv_02:*:sparc:*:*:*:*:*
sun opensolaris snv_02 cpe:2.3:o:sun:opensolaris:snv_02:*:x86:*:*:*:*:*
sun opensolaris snv_03 cpe:2.3:o:sun:opensolaris:snv_03:*:sparc:*:*:*:*:*
sun opensolaris snv_03 cpe:2.3:o:sun:opensolaris:snv_03:*:x86:*:*:*:*:*
sun opensolaris snv_04 cpe:2.3:o:sun:opensolaris:snv_04:*:sparc:*:*:*:*:*
sun opensolaris snv_04 cpe:2.3:o:sun:opensolaris:snv_04:*:x86:*:*:*:*:*
sun opensolaris snv_05 cpe:2.3:o:sun:opensolaris:snv_05:*:sparc:*:*:*:*:*
sun opensolaris snv_05 cpe:2.3:o:sun:opensolaris:snv_05:*:x86:*:*:*:*:*
sun opensolaris snv_06 cpe:2.3:o:sun:opensolaris:snv_06:*:sparc:*:*:*:*:*
sun opensolaris snv_06 cpe:2.3:o:sun:opensolaris:snv_06:*:x86:*:*:*:*:*
sun opensolaris snv_07 cpe:2.3:o:sun:opensolaris:snv_07:*:sparc:*:*:*:*:*
sun opensolaris snv_07 cpe:2.3:o:sun:opensolaris:snv_07:*:x86:*:*:*:*:*
sun opensolaris snv_08 cpe:2.3:o:sun:opensolaris:snv_08:*:sparc:*:*:*:*:*
sun opensolaris snv_08 cpe:2.3:o:sun:opensolaris:snv_08:*:x86:*:*:*:*:*
sun opensolaris snv_09 cpe:2.3:o:sun:opensolaris:snv_09:*:sparc:*:*:*:*:*
sun opensolaris snv_09 cpe:2.3:o:sun:opensolaris:snv_09:*:x86:*:*:*:*:*
sun opensolaris snv_10 cpe:2.3:o:sun:opensolaris:snv_10:*:sparc:*:*:*:*:*
sun opensolaris snv_10 cpe:2.3:o:sun:opensolaris:snv_10:*:x86:*:*:*:*:*
sun opensolaris snv_11 cpe:2.3:o:sun:opensolaris:snv_11:*:sparc:*:*:*:*:*
sun opensolaris snv_12 cpe:2.3:o:sun:opensolaris:snv_12:*:sparc:*:*:*:*:*
sun opensolaris snv_13 cpe:2.3:o:sun:opensolaris:snv_13:*:sparc:*:*:*:*:*
sun opensolaris snv_14 cpe:2.3:o:sun:opensolaris:snv_14:*:sparc:*:*:*:*:*
sun opensolaris snv_15 cpe:2.3:o:sun:opensolaris:snv_15:*:sparc:*:*:*:*:*
sun opensolaris snv_16 cpe:2.3:o:sun:opensolaris:snv_16:*:sparc:*:*:*:*:*
sun opensolaris snv_17 cpe:2.3:o:sun:opensolaris:snv_17:*:sparc:*:*:*:*:*
sun opensolaris snv_18 cpe:2.3:o:sun:opensolaris:snv_18:*:sparc:*:*:*:*:*
sun opensolaris snv_19 cpe:2.3:o:sun:opensolaris:snv_19:*:sparc:*:*:*:*:*
sun opensolaris snv_20 cpe:2.3:o:sun:opensolaris:snv_20:*:sparc:*:*:*:*:*
sun opensolaris snv_21 cpe:2.3:o:sun:opensolaris:snv_21:*:sparc:*:*:*:*:*
sun opensolaris snv_21 cpe:2.3:o:sun:opensolaris:snv_21:*:x86:*:*:*:*:*
sun opensolaris snv_22 cpe:2.3:o:sun:opensolaris:snv_22:*:sparc:*:*:*:*:*
sun opensolaris snv_22 cpe:2.3:o:sun:opensolaris:snv_22:*:x86:*:*:*:*:*
sun opensolaris snv_23 cpe:2.3:o:sun:opensolaris:snv_23:*:sparc:*:*:*:*:*
sun opensolaris snv_23 cpe:2.3:o:sun:opensolaris:snv_23:*:x86:*:*:*:*:*
sun opensolaris snv_24 cpe:2.3:o:sun:opensolaris:snv_24:*:sparc:*:*:*:*:*
sun opensolaris snv_24 cpe:2.3:o:sun:opensolaris:snv_24:*:x86:*:*:*:*:*
sun opensolaris snv_25 cpe:2.3:o:sun:opensolaris:snv_25:*:sparc:*:*:*:*:*
sun opensolaris snv_25 cpe:2.3:o:sun:opensolaris:snv_25:*:x86:*:*:*:*:*
sun opensolaris snv_26 cpe:2.3:o:sun:opensolaris:snv_26:*:sparc:*:*:*:*:*
sun opensolaris snv_26 cpe:2.3:o:sun:opensolaris:snv_26:*:x86:*:*:*:*:*
sun opensolaris snv_27 cpe:2.3:o:sun:opensolaris:snv_27:*:sparc:*:*:*:*:*
sun opensolaris snv_27 cpe:2.3:o:sun:opensolaris:snv_27:*:x86:*:*:*:*:*
sun opensolaris snv_28 cpe:2.3:o:sun:opensolaris:snv_28:*:sparc:*:*:*:*:*
sun opensolaris snv_28 cpe:2.3:o:sun:opensolaris:snv_28:*:x86:*:*:*:*:*
sun opensolaris snv_29 cpe:2.3:o:sun:opensolaris:snv_29:*:sparc:*:*:*:*:*
sun opensolaris snv_29 cpe:2.3:o:sun:opensolaris:snv_29:*:x86:*:*:*:*:*
sun opensolaris snv_30 cpe:2.3:o:sun:opensolaris:snv_30:*:sparc:*:*:*:*:*
sun opensolaris snv_30 cpe:2.3:o:sun:opensolaris:snv_30:*:x86:*:*:*:*:*
sun opensolaris snv_31 cpe:2.3:o:sun:opensolaris:snv_31:*:sparc:*:*:*:*:*
sun opensolaris snv_31 cpe:2.3:o:sun:opensolaris:snv_31:*:x86:*:*:*:*:*
sun opensolaris snv_32 cpe:2.3:o:sun:opensolaris:snv_32:*:sparc:*:*:*:*:*
sun opensolaris snv_32 cpe:2.3:o:sun:opensolaris:snv_32:*:x86:*:*:*:*:*
sun opensolaris snv_33 cpe:2.3:o:sun:opensolaris:snv_33:*:sparc:*:*:*:*:*
sun opensolaris snv_33 cpe:2.3:o:sun:opensolaris:snv_33:*:x86:*:*:*:*:*
sun opensolaris snv_34 cpe:2.3:o:sun:opensolaris:snv_34:*:sparc:*:*:*:*:*
sun opensolaris snv_34 cpe:2.3:o:sun:opensolaris:snv_34:*:x86:*:*:*:*:*
sun opensolaris snv_35 cpe:2.3:o:sun:opensolaris:snv_35:*:sparc:*:*:*:*:*
sun opensolaris snv_35 cpe:2.3:o:sun:opensolaris:snv_35:*:x86:*:*:*:*:*
sun opensolaris snv_36 cpe:2.3:o:sun:opensolaris:snv_36:*:sparc:*:*:*:*:*
sun opensolaris snv_36 cpe:2.3:o:sun:opensolaris:snv_36:*:x86:*:*:*:*:*
sun opensolaris snv_37 cpe:2.3:o:sun:opensolaris:snv_37:*:sparc:*:*:*:*:*
sun opensolaris snv_37 cpe:2.3:o:sun:opensolaris:snv_37:*:x86:*:*:*:*:*
sun opensolaris snv_38 cpe:2.3:o:sun:opensolaris:snv_38:*:sparc:*:*:*:*:*
sun opensolaris snv_38 cpe:2.3:o:sun:opensolaris:snv_38:*:x86:*:*:*:*:*
sun opensolaris snv_39 cpe:2.3:o:sun:opensolaris:snv_39:*:sparc:*:*:*:*:*
sun opensolaris snv_39 cpe:2.3:o:sun:opensolaris:snv_39:*:x86:*:*:*:*:*
sun opensolaris snv_40 cpe:2.3:o:sun:opensolaris:snv_40:*:sparc:*:*:*:*:*
sun opensolaris snv_40 cpe:2.3:o:sun:opensolaris:snv_40:*:x86:*:*:*:*:*
sun opensolaris snv_41 cpe:2.3:o:sun:opensolaris:snv_41:*:sparc:*:*:*:*:*
sun opensolaris snv_41 cpe:2.3:o:sun:opensolaris:snv_41:*:x86:*:*:*:*:*
sun opensolaris snv_42 cpe:2.3:o:sun:opensolaris:snv_42:*:sparc:*:*:*:*:*
sun opensolaris snv_42 cpe:2.3:o:sun:opensolaris:snv_42:*:x86:*:*:*:*:*
sun opensolaris snv_43 cpe:2.3:o:sun:opensolaris:snv_43:*:sparc:*:*:*:*:*
sun opensolaris snv_43 cpe:2.3:o:sun:opensolaris:snv_43:*:x86:*:*:*:*:*
sun opensolaris snv_44 cpe:2.3:o:sun:opensolaris:snv_44:*:sparc:*:*:*:*:*
sun opensolaris snv_44 cpe:2.3:o:sun:opensolaris:snv_44:*:x86:*:*:*:*:*

References for CVE-2009-3432

cvelogic Threat Intelligence