CVE-2016-5407: Fedoraproject Fedora
Critical severity, CVSS 9.8. EPSS: 4.5% chance of exploitation in the next 30 days.
The (1) XvQueryAdaptors and (2) XvQueryEncodings functions in X.org libXv before 1.0.11 allow remote X servers to trigger out-of-bounds memory access operations via vectors involving length specifications in received data.
Affected products
- Fedoraproject Fedora: version 24 only; version 25 only
- X.org Libxv: up to and including 1.0.10
Published 2016-12-13. Last modified 2026-06-17.