CVE-2004-2655
Last modified
CVE-2004-2655 is a vulnerability of currently unknown severity. rdesktop 1.3.1 with xscreensaver 4.14, and possibly other versions, when running on Fedora and possibly other platforms, does not release the keyboard focus when xscreensaver starts, which causes the password to be entered into the active window when the user unlocks the screen.. EPSS estimates a 2.29% chance of exploitation in the next 30 days.
Description
rdesktop 1.3.1 with xscreensaver 4.14, and possibly other versions, when running on Fedora and possibly other platforms, does not release the keyboard focus when xscreensaver starts, which causes the password to be entered into the active window when the user unlocks the screen.
Metrics
Affected Software
| Vendor | Product | Versions |
|---|---|---|
| Xscreensaver | Xscreensaver | 4.14 |
| Xscreensaver | Xscreensaver | 4.16 |
| Xscreensaver | Xscreensaver | 4.17 |
References
Timeline
- Published
- Last Modified
- Status
- Modified
Frequently Asked Questions
What is CVE-2004-2655?
How severe is CVE-2004-2655?
How do I fix CVE-2004-2655?
How Strix Helps
- How Strix found a critical auth bypass in etcdStrix autonomously discovered a critical authentication bypass in etcd, later designated CVE-2026-33413.
- Autonomous PentestingAI agents that find and validate exploitable vulnerabilities like this one across your applications.
- PR ReviewsPentest every pull request so vulnerable code is caught before it ships to production.
- AI Penetration TestingHow AI-driven penetration testing continuously covers your attack surface.
Related CVEs from 2004
- CVE-2004-2649Eudora 6.1.0.6 allows remote attackers to obfuscate URLs dis…
- CVE-2004-2650Spooler in Apache Foundation James 2.2.0 allows local users …
- CVE-2004-2651Multiple cross-site scripting (XSS) vulnerabilities in YaCy …
- CVE-2004-2652The DecodeTCPOptions function in decode.c in Snort before 2.…
- CVE-2004-2653Unspecified vulnerability in PD9 Software MegaBBS 2.0 and 2.…
- CVE-2004-2654The clientAbortBody function in client_side.c in Squid Web P…
- CVE-2004-2656Multiple cross-site scripting (XSS) vulnerabilities in Slash…
- CVE-2004-2657Mozilla Firefox 1.5.0.1, and possibly other versions, preser…
- CVE-2004-2658resmgr in SUSE CORE 9 does not properly identify terminal na…
- CVE-2004-2659Opera offers an Open button to verify that a user wishes to …
- CVE-2004-2660Memory leak in direct-io.c in Linux kernel 2.6.x before 2.6.…
- CVE-2004-2661Soft3304 04WebServer before 1.41 does not properly check fil…
Are you affected by CVE-2004-2655?
Run a free Strix scan to check your systems for this vulnerability.
Scan your code nowSource: NVD / NIST
