CVE-2013-1990: X Libxvmc

Medium severity, CVSS 6.8. EPSS: 1.4% chance of exploitation in the next 30 days.

Multiple integer overflows in X.org libXvMC 1.0.7 and earlier allow X servers to trigger allocation of insufficient memory and a buffer overflow via vectors related to the (1) XvMCListSurfaceTypes and (2) XvMCListSubpictureTypes functions.

Affected products

  • X Libxvmc: up to and including 1.0.7; version 1.0.2 only; version 1.0.3 only; version 1.0.4 only; version 1.0.5 only; version 1.0.6 only

Published 2013-06-15. Last modified 2026-06-16.