Search/CVE-2009-1573
CVE

CVE-2009-1573

xvfb-run 1.6.1 in Debian GNU/Linux, Ubuntu, Fedora 10, and possibly other operating systems place the magic cookie (MCOOKIE) on the command line, which allows local users to gain privileges by listing the process and its arguments.

CVSS v3.1
EPSS
0.46%
probability of exploitation in 30 days
CISA KEV
Not listed
no confirmed exploitation reported
News coverage
0
sources referencing this CVE
Connections
5 relationships
Timeline
disclosure → media coverage
May 6, 2009
Disclosure — published as a CVE record. · last revised by NVD Apr 23, 2026