Predictive Vulnerability Intelligence.

Product

  • Product
  • Pricing
  • Documentation

Company

  • About
  • Partnerships
  • Blog
  • Support

Legal

  • Terms
  • Privacy
  • Data Licensing

© 2026 FAUCET Technologies LLC. All rights reserved.

CVE-2016-7949

31
FAUCET Score

CVE-2016-7949 describes multiple critical buffer overflow vulnerabilities in the X.org libXrender library, specifically affecting the XvQueryAdaptors and XvQueryEncodings functions. These flaws allow a remote X server to execute out-of-bounds write operations by manipulating length fields, impacting various Fedora and X.org libXrender versions. With a CVSS score of 9.8 (CRITICAL), this vulnerability presents a severe risk, enabling full compromise of confidentiality, integrity, and availability without user interaction. While there is no known active exploitation or public exploit code (Metasploit, Nuclei, ExploitDB), the vulnerability has garnered significant community discussion and media coverage, indicating awareness of its potential impact.

Impacted Technologies

VendorProductVersion(s)CPE
<= 0.9.9CPE matchmatch criteria
cpe:2.3:a:x.org:libxrender:*:*:*:*:*:*:*:*
24CPE matchmatch criteria
cpe:2.3:o:fedoraproject:fedora:24:*:*:*:*:*:*:*
25CPE matchmatch criteria
cpe:2.3:o:fedoraproject:fedora:25:*:*:*:*:*:*:*

CVSS Data

CVSS version used by this source: 3.0

9.8CRITICAL

CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H

Attack Vector
NETWORK
Attack Complexity
LOW
Privileges Required
NONE
User Interaction
NONE
Scope
UNCHANGED
Confidentiality Impact
HIGH
Integrity Impact
HIGH
Availability Impact
HIGH
Exploitability Score
3.9
Impact Score
5.9
CvssVersion
3.0

Exploit Intelligence

EPSS Score
3.72%
Probability of exploitation in next 30 days
EPSS Percentile
88.6%
Percentile rank of EPSS score among Peer Group
As of 2026-07-24
Model: v2026.06.15
This CVE's current EPSS score of 0.0372 is in the 81st percentile among its peer group of 36,829 CVEs.

Social Chatter

The average CVE in this peer group has 0.0 Twitter, 0.1 Reddit, 0.3 Bluesky, 0.3 Mastodon, and 2.4 GitHub mentions.

Media Mentions

The average CVE in this peer group has 0.3 InfoSec Media, 0.0 Vendor Blog, and 0.0 Security Researcher mentions.

Remediation

Vendor Patches (3)

redhatend of lifevia redhat_api
Product: Red Hat Enterprise Linux 5Fixed in: libXrender
redhatend of lifevia redhat_api
Product: Red Hat Enterprise Linux 6Fixed in: libXrender
redhatend of lifevia redhat_api
Product: Red Hat Enterprise Linux 7Fixed in: libXrender

Vendor Advisories (1)

redhatCVE-2016-7949Moderate

libXrender: Insufficient validation of server responses results in overflow of previously reserved memory

Sep 25, 2016

References

cgit.freedesktop.org / xorg/lib/libXrender/commit
lists.fedoraproject.org / archives/list/package-announce%40lists.fedoraproject.org/message/7WCKZFMZ76APAVMIRCUKKHEB4GAS7ZUP
lists.fedoraproject.org / archives/list/package-announce%40lists.fedoraproject.org/message/ZHUT5YOSWVMBJNWZGUQNZRBFIZKRM4A6
lists.x.org / archives/xorg-announce/2016-October/002720.html
security.gentoo.org / glsa/201704-03
openwall.com / lists/oss-security/2016/10/04/2
openwall.com / lists/oss-security/2016/10/04/4
securityfocus.com / bid/93366
securitytracker.com / id/1036945