CVE-2016-5407: libXv: Insufficient validation of server responses results in out-of bounds accesses

Severity: Critical

CVSS Score: 9.8

The (1) XvQueryAdaptors and (2) XvQueryEncodings functions in X.org libXv before 1.0.11 allow remote X servers to trigger out-of-bounds memory access operations via vectors involving length specifications in received data.