CVE-2016-7945 describes multiple integer overflow vulnerabilities in X.org's libXi library, affecting Fedora and X.org libXi versions prior to 1.7.7. A remote X server could exploit these flaws by manipulating length fields, leading to a denial of service through out-of-bounds memory access or an infinite loop. This vulnerability has a CVSS v3 score of 7.5 (High), indicating a network-based attack with low complexity and no user interaction required, resulting in high availability impact. While there are no known public exploits in Metasploit or ExploitDB, and it's not listed in CISA's KEV catalog, it has received some community discussion and media coverage, suggesting awareness within the cybersecurity community.
| Vendor | Product | Version(s) | CPE |
|---|---|---|---|
24CPE matchmatch criteria | cpe:2.3:o:fedoraproject:fedora:24:*:*:*:*:*:*:* | ||
25CPE matchmatch criteria | cpe:2.3:o:fedoraproject:fedora:25:*:*:*:*:*:*:* | ||
<= 1.7.6CPE matchmatch criteria | cpe:2.3:a:x.org:libxi:*:*:*:*:*:*:*:* |
CVSS version used by this source: 3.0
CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H
No social media mentions found for this CVE.
The average CVE in this peer group has 0.0 Twitter, 0.0 Reddit, 0.1 Bluesky, 0.1 Mastodon, and 0.4 GitHub mentions.
The average CVE in this peer group has 0.1 InfoSec Media, 0.0 Vendor Blog, and 0.0 Security Researcher mentions.