GNOME XScreenSaver in Sun Solaris 8 and 9 before 20070417, when root is logged into the console, does not automatically lock the screen after a session has been inactive, which might allow physically proximate attackers to access the console.
https://oval.cisecurity.org/repository/search/definition/oval%3Aorg.mitre.oval%3Adef%3A2037
http://www.jwz.org/xscreensaver/faq.html#root-lock
http://sunsolve.sun.com/search/document.do?assetkey=1-26-101338-1