CVE-2016-5407 is a critical vulnerability affecting X.org libXv versions prior to 1.0.11, specifically impacting the XvQueryAdaptors and XvQueryEncodings functions. A remote X server can exploit this flaw by manipulating length specifications in received data, leading to out-of-bounds memory access. With a CVSS score of 9.8 (Critical), this vulnerability allows for unauthenticated remote attacks with low complexity, potentially resulting in complete compromise of confidentiality, integrity, and availability. While there is no evidence of active exploitation or public exploit code (Metasploit, Nuclei, ExploitDB), the vulnerability has garnered significant community discussion and media coverage, indicating its perceived importance despite the lack of confirmed exploits.
| Vendor | Product | Version(s) | CPE |
|---|---|---|---|
<= 1.0.10CPE matchmatch criteria | cpe:2.3:a:x.org:libxv:*:*:*:*:*:*:*:* | ||
24CPE matchmatch criteria | cpe:2.3:o:fedoraproject:fedora:24:*:*:*:*:*:*:* | ||
25CPE matchmatch criteria | cpe:2.3:o:fedoraproject:fedora:25:*:*:*:*:*:*:* |
CVSS version used by this source: 3.0
CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
The average CVE in this peer group has 0.0 Twitter, 0.1 Reddit, 0.3 Bluesky, 0.3 Mastodon, and 2.4 GitHub mentions.
The average CVE in this peer group has 0.3 InfoSec Media, 0.0 Vendor Blog, and 0.0 Security Researcher mentions.