CVE-2016-7950 describes an out-of-bounds write vulnerability in the X.org libXrender library (before version 0.9.10), specifically within the XRenderQueryFilters function, affecting Fedora and X.org products. This critical vulnerability (CVSS 9.8) can be exploited remotely without user interaction, potentially leading to complete compromise of confidentiality, integrity, and availability. While no public exploit code or active exploitation is reported, its high severity and mention in media coverage indicate its potential impact.
| Vendor | Product | Version(s) | CPE |
|---|---|---|---|
<= 0.9.9CPE matchmatch criteria | cpe:2.3:a:x.org:libxrender:*:*:*:*:*:*:*:* | ||
24CPE matchmatch criteria | cpe:2.3:o:fedoraproject:fedora:24:*:*:*:*:*:*:* | ||
25CPE matchmatch criteria | cpe:2.3:o:fedoraproject:fedora:25:*:*:*:*:*:*:* |
CVSS version used by this source: 3.0
CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
The average CVE in this peer group has 0.0 Twitter, 0.1 Reddit, 0.3 Bluesky, 0.3 Mastodon, and 2.4 GitHub mentions.
The average CVE in this peer group has 0.3 InfoSec Media, 0.0 Vendor Blog, and 0.0 Security Researcher mentions.