CVE-2016-7953 describes a critical buffer underflow vulnerability in X.org libXvMC versions prior to 1.0.10, affecting Fedora and X.org products. This flaw allows remote X servers to cause unspecified impact by sending an empty string. With a CVSS score of 9.8 (CRITICAL), this vulnerability is easily exploitable over the network without user interaction, potentially leading to full compromise of confidentiality, integrity, and availability. While there is no known active exploitation, public exploit code, or KEV listing, the vulnerability has garnered some community discussion and media coverage, indicating awareness within the cybersecurity community.
| Vendor | Product | Version(s) | CPE |
|---|---|---|---|
24CPE matchmatch criteria | cpe:2.3:o:fedoraproject:fedora:24:*:*:*:*:*:*:* | ||
25CPE matchmatch criteria | cpe:2.3:o:fedoraproject:fedora:25:*:*:*:*:*:*:* | ||
<= 1.0.9CPE matchmatch criteria | cpe:2.3:a:x.org:libxvmc:*:*:*:*:*:*:*:* |
CVSS version used by this source: 3.0
CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
No social media mentions found for this CVE.
The average CVE in this peer group has 0.0 Twitter, 0.1 Reddit, 0.3 Bluesky, 0.3 Mastodon, and 2.4 GitHub mentions.
The average CVE in this peer group has 0.3 InfoSec Media, 0.0 Vendor Blog, and 0.0 Security Researcher mentions.