<?xml version="1.0" encoding="UTF-8"?>
<cvrfdoc xmlns="http://www.icasi.org/CVRF/schema/cvrf/1.1" xmlns:cvrf="http://www.icasi.org/CVRF/schema/cvrf/1.1">
  <DocumentTitle xml:lang="en">Security update for X Window System client libraries</DocumentTitle>
  <DocumentType>SUSE Patch</DocumentType>
  <DocumentPublisher Type="Vendor">
    <ContactDetails>security@suse.de</ContactDetails>
    <IssuingAuthority>SUSE Security Team</IssuingAuthority>
  </DocumentPublisher>
  <DocumentTracking>
    <Identification>
      <ID>openSUSE-SU-2016:2600-1</ID>
    </Identification>
    <Status>Final</Status>
    <Version>1</Version>
    <RevisionHistory>
      <Revision>
        <Number>1</Number>
        <Date>2016-10-23T18:46:26Z</Date>
        <Description>current</Description>
      </Revision>
    </RevisionHistory>
    <InitialReleaseDate>2016-10-23T18:46:26Z</InitialReleaseDate>
    <CurrentReleaseDate>2016-10-23T18:46:26Z</CurrentReleaseDate>
    <Generator>
      <Engine>cve-database/bin/generate-cvrf.pl</Engine>
      <Date>2017-02-24T01:00:00Z</Date>
    </Generator>
  </DocumentTracking>
  <DocumentNotes>
    <Note Title="Topic" Type="Summary" Ordinal="1" xml:lang="en">Security update for X Window System client libraries</Note>
    <Note Title="Details" Type="General" Ordinal="2" xml:lang="en">This update for the X Window System client libraries fixes a class of privilege escalation issues.

A malicious X Server could send specially crafted data to X clients, which allowed for triggering crashes, or privilege escalation if this relationship was untrusted or crossed user or permission level boundaries.

libX11, libXfixes, libXi, libXrandr, libXrender, libXtst, libXv, libXvMC were fixed, specifically:

libX11:
- CVE-2016-7942: insufficient validation of data from the X server allowed out of boundary memory read (bsc#1002991)

libXfixes:
- CVE-2016-7944: insufficient validation of data from the X server can cause an integer overflow on 32 bit architectures (bsc#1002995)

libXi:
- CVE-2016-7945, CVE-2016-7946: insufficient validation of data from the X server can cause out of boundary memory access or endless loops (Denial of Service) (bsc#1002998)

libXtst:
- CVE-2016-7951, CVE-2016-7952: insufficient validation of data from the X server can cause out of boundary memory access or endless loops (Denial of Service) (bsc#1003012)

libXv:
- CVE-2016-5407: insufficient validation of data from the X server can cause out of boundary memory and memory corruption (bsc#1003017)

libXvMC:
- CVE-2016-7953: insufficient validation of data from the X server can cause a one byte buffer read underrun (bsc#1003023)

libXrender:
- CVE-2016-7949, CVE-2016-7950: insufficient validation of data from the X server can cause out of boundary memory writes (bsc#1003002)

libXrandr:
- CVE-2016-7947, CVE-2016-7948: insufficient validation of data from the X server can cause out of boundary memory writes (bsc#1003000)

This update was imported from the SUSE:SLE-12:Update update project.</Note>
    <Note Title="Terms of Use" Type="Legal Disclaimer" Ordinal="3" xml:lang="en">The CVRF data is provided by SUSE under the Creative Commons License 4.0 with Attribution (CC-BY-4.0).</Note>
  </DocumentNotes>
  <DocumentDistribution xml:lang="en">Copyright SUSE LLC under the Creative Commons License 4.0 with Attribution (CC-BY-4.0)</DocumentDistribution>
  <DocumentReferences>
    <Reference Type="Self">
      <URL>https://lists.opensuse.org/opensuse-updates/2016-10/msg00078.html</URL>
      <Description>E-Mail link for openSUSE-SU-2016:2600-1</Description>
    </Reference>
    <Reference Type="Self">
      <URL>https://www.suse.com/support/security/rating/</URL>
      <Description>SUSE Security Ratings</Description>
    </Reference>
  </DocumentReferences>
  <ProductTree xmlns="http://www.icasi.org/CVRF/schema/prod/1.1">
    <Branch Type="Product Family" Name="openSUSE Leap 42.1">
      <Branch Type="Product Name" Name="openSUSE Leap 42.1">
        <FullProductName ProductID="openSUSE Leap 42.1">openSUSE Leap 42.1</FullProductName>
      </Branch>
    </Branch>
    <Branch Type="Product Version" Name="libX11-1.6.3-6.1">
      <FullProductName ProductID="libX11-1.6.3-6.1">libX11-1.6.3-6.1</FullProductName>
    </Branch>
    <Branch Type="Product Version" Name="libX11-6-1.6.3-6.1">
      <FullProductName ProductID="libX11-6-1.6.3-6.1">libX11-6-1.6.3-6.1</FullProductName>
    </Branch>
    <Branch Type="Product Version" Name="libX11-6-32bit-1.6.3-6.1">
      <FullProductName ProductID="libX11-6-32bit-1.6.3-6.1">libX11-6-32bit-1.6.3-6.1</FullProductName>
    </Branch>
    <Branch Type="Product Version" Name="libX11-data-1.6.3-6.1">
      <FullProductName ProductID="libX11-data-1.6.3-6.1">libX11-data-1.6.3-6.1</FullProductName>
    </Branch>
    <Branch Type="Product Version" Name="libX11-devel-1.6.3-6.1">
      <FullProductName ProductID="libX11-devel-1.6.3-6.1">libX11-devel-1.6.3-6.1</FullProductName>
    </Branch>
    <Branch Type="Product Version" Name="libX11-devel-32bit-1.6.3-6.1">
      <FullProductName ProductID="libX11-devel-32bit-1.6.3-6.1">libX11-devel-32bit-1.6.3-6.1</FullProductName>
    </Branch>
    <Branch Type="Product Version" Name="libX11-xcb1-1.6.3-6.1">
      <FullProductName ProductID="libX11-xcb1-1.6.3-6.1">libX11-xcb1-1.6.3-6.1</FullProductName>
    </Branch>
    <Branch Type="Product Version" Name="libX11-xcb1-32bit-1.6.3-6.1">
      <FullProductName ProductID="libX11-xcb1-32bit-1.6.3-6.1">libX11-xcb1-32bit-1.6.3-6.1</FullProductName>
    </Branch>
    <Branch Type="Product Version" Name="libXfixes-5.0.1-7.1">
      <FullProductName ProductID="libXfixes-5.0.1-7.1">libXfixes-5.0.1-7.1</FullProductName>
    </Branch>
    <Branch Type="Product Version" Name="libXfixes-devel-5.0.1-7.1">
      <FullProductName ProductID="libXfixes-devel-5.0.1-7.1">libXfixes-devel-5.0.1-7.1</FullProductName>
    </Branch>
    <Branch Type="Product Version" Name="libXfixes-devel-32bit-5.0.1-7.1">
      <FullProductName ProductID="libXfixes-devel-32bit-5.0.1-7.1">libXfixes-devel-32bit-5.0.1-7.1</FullProductName>
    </Branch>
    <Branch Type="Product Version" Name="libXfixes3-5.0.1-7.1">
      <FullProductName ProductID="libXfixes3-5.0.1-7.1">libXfixes3-5.0.1-7.1</FullProductName>
    </Branch>
    <Branch Type="Product Version" Name="libXfixes3-32bit-5.0.1-7.1">
      <FullProductName ProductID="libXfixes3-32bit-5.0.1-7.1">libXfixes3-32bit-5.0.1-7.1</FullProductName>
    </Branch>
    <Branch Type="Product Version" Name="libXi-1.7.5-3.1">
      <FullProductName ProductID="libXi-1.7.5-3.1">libXi-1.7.5-3.1</FullProductName>
    </Branch>
    <Branch Type="Product Version" Name="libXi-devel-1.7.5-3.1">
      <FullProductName ProductID="libXi-devel-1.7.5-3.1">libXi-devel-1.7.5-3.1</FullProductName>
    </Branch>
    <Branch Type="Product Version" Name="libXi-devel-32bit-1.7.5-3.1">
      <FullProductName ProductID="libXi-devel-32bit-1.7.5-3.1">libXi-devel-32bit-1.7.5-3.1</FullProductName>
    </Branch>
    <Branch Type="Product Version" Name="libXi6-1.7.5-3.1">
      <FullProductName ProductID="libXi6-1.7.5-3.1">libXi6-1.7.5-3.1</FullProductName>
    </Branch>
    <Branch Type="Product Version" Name="libXi6-32bit-1.7.5-3.1">
      <FullProductName ProductID="libXi6-32bit-1.7.5-3.1">libXi6-32bit-1.7.5-3.1</FullProductName>
    </Branch>
    <Branch Type="Product Version" Name="libXrandr-1.5.0-3.1">
      <FullProductName ProductID="libXrandr-1.5.0-3.1">libXrandr-1.5.0-3.1</FullProductName>
    </Branch>
    <Branch Type="Product Version" Name="libXrandr-devel-1.5.0-3.1">
      <FullProductName ProductID="libXrandr-devel-1.5.0-3.1">libXrandr-devel-1.5.0-3.1</FullProductName>
    </Branch>
    <Branch Type="Product Version" Name="libXrandr-devel-32bit-1.5.0-3.1">
      <FullProductName ProductID="libXrandr-devel-32bit-1.5.0-3.1">libXrandr-devel-32bit-1.5.0-3.1</FullProductName>
    </Branch>
    <Branch Type="Product Version" Name="libXrandr2-1.5.0-3.1">
      <FullProductName ProductID="libXrandr2-1.5.0-3.1">libXrandr2-1.5.0-3.1</FullProductName>
    </Branch>
    <Branch Type="Product Version" Name="libXrandr2-32bit-1.5.0-3.1">
      <FullProductName ProductID="libXrandr2-32bit-1.5.0-3.1">libXrandr2-32bit-1.5.0-3.1</FullProductName>
    </Branch>
    <Branch Type="Product Version" Name="libXrender-0.9.9-3.1">
      <FullProductName ProductID="libXrender-0.9.9-3.1">libXrender-0.9.9-3.1</FullProductName>
    </Branch>
    <Branch Type="Product Version" Name="libXrender-devel-0.9.9-3.1">
      <FullProductName ProductID="libXrender-devel-0.9.9-3.1">libXrender-devel-0.9.9-3.1</FullProductName>
    </Branch>
    <Branch Type="Product Version" Name="libXrender-devel-32bit-0.9.9-3.1">
      <FullProductName ProductID="libXrender-devel-32bit-0.9.9-3.1">libXrender-devel-32bit-0.9.9-3.1</FullProductName>
    </Branch>
    <Branch Type="Product Version" Name="libXrender1-0.9.9-3.1">
      <FullProductName ProductID="libXrender1-0.9.9-3.1">libXrender1-0.9.9-3.1</FullProductName>
    </Branch>
    <Branch Type="Product Version" Name="libXrender1-32bit-0.9.9-3.1">
      <FullProductName ProductID="libXrender1-32bit-0.9.9-3.1">libXrender1-32bit-0.9.9-3.1</FullProductName>
    </Branch>
    <Branch Type="Product Version" Name="libXtst-1.2.2-7.1">
      <FullProductName ProductID="libXtst-1.2.2-7.1">libXtst-1.2.2-7.1</FullProductName>
    </Branch>
    <Branch Type="Product Version" Name="libXtst-devel-1.2.2-7.1">
      <FullProductName ProductID="libXtst-devel-1.2.2-7.1">libXtst-devel-1.2.2-7.1</FullProductName>
    </Branch>
    <Branch Type="Product Version" Name="libXtst-devel-32bit-1.2.2-7.1">
      <FullProductName ProductID="libXtst-devel-32bit-1.2.2-7.1">libXtst-devel-32bit-1.2.2-7.1</FullProductName>
    </Branch>
    <Branch Type="Product Version" Name="libXtst6-1.2.2-7.1">
      <FullProductName ProductID="libXtst6-1.2.2-7.1">libXtst6-1.2.2-7.1</FullProductName>
    </Branch>
    <Branch Type="Product Version" Name="libXtst6-32bit-1.2.2-7.1">
      <FullProductName ProductID="libXtst6-32bit-1.2.2-7.1">libXtst6-32bit-1.2.2-7.1</FullProductName>
    </Branch>
    <Branch Type="Product Version" Name="libXv-1.0.10-7.1">
      <FullProductName ProductID="libXv-1.0.10-7.1">libXv-1.0.10-7.1</FullProductName>
    </Branch>
    <Branch Type="Product Version" Name="libXv-devel-1.0.10-7.1">
      <FullProductName ProductID="libXv-devel-1.0.10-7.1">libXv-devel-1.0.10-7.1</FullProductName>
    </Branch>
    <Branch Type="Product Version" Name="libXv-devel-32bit-1.0.10-7.1">
      <FullProductName ProductID="libXv-devel-32bit-1.0.10-7.1">libXv-devel-32bit-1.0.10-7.1</FullProductName>
    </Branch>
    <Branch Type="Product Version" Name="libXv1-1.0.10-7.1">
      <FullProductName ProductID="libXv1-1.0.10-7.1">libXv1-1.0.10-7.1</FullProductName>
    </Branch>
    <Branch Type="Product Version" Name="libXv1-32bit-1.0.10-7.1">
      <FullProductName ProductID="libXv1-32bit-1.0.10-7.1">libXv1-32bit-1.0.10-7.1</FullProductName>
    </Branch>
    <Branch Type="Product Version" Name="libXvMC-1.0.9-3.1">
      <FullProductName ProductID="libXvMC-1.0.9-3.1">libXvMC-1.0.9-3.1</FullProductName>
    </Branch>
    <Branch Type="Product Version" Name="libXvMC-devel-1.0.9-3.1">
      <FullProductName ProductID="libXvMC-devel-1.0.9-3.1">libXvMC-devel-1.0.9-3.1</FullProductName>
    </Branch>
    <Branch Type="Product Version" Name="libXvMC-devel-32bit-1.0.9-3.1">
      <FullProductName ProductID="libXvMC-devel-32bit-1.0.9-3.1">libXvMC-devel-32bit-1.0.9-3.1</FullProductName>
    </Branch>
    <Branch Type="Product Version" Name="libXvMC1-1.0.9-3.1">
      <FullProductName ProductID="libXvMC1-1.0.9-3.1">libXvMC1-1.0.9-3.1</FullProductName>
    </Branch>
    <Branch Type="Product Version" Name="libXvMC1-32bit-1.0.9-3.1">
      <FullProductName ProductID="libXvMC1-32bit-1.0.9-3.1">libXvMC1-32bit-1.0.9-3.1</FullProductName>
    </Branch>
    <Relationship ProductReference="libX11-1.6.3-6.1" RelationType="Default Component Of" RelatesToProductReference="openSUSE Leap 42.1">
      <FullProductName ProductID="openSUSE Leap 42.1:libX11-1.6.3-6.1">libX11-1.6.3-6.1 as a component of openSUSE Leap 42.1</FullProductName>
    </Relationship>
    <Relationship ProductReference="libX11-6-1.6.3-6.1" RelationType="Default Component Of" RelatesToProductReference="openSUSE Leap 42.1">
      <FullProductName ProductID="openSUSE Leap 42.1:libX11-6-1.6.3-6.1">libX11-6-1.6.3-6.1 as a component of openSUSE Leap 42.1</FullProductName>
    </Relationship>
    <Relationship ProductReference="libX11-6-32bit-1.6.3-6.1" RelationType="Default Component Of" RelatesToProductReference="openSUSE Leap 42.1">
      <FullProductName ProductID="openSUSE Leap 42.1:libX11-6-32bit-1.6.3-6.1">libX11-6-32bit-1.6.3-6.1 as a component of openSUSE Leap 42.1</FullProductName>
    </Relationship>
    <Relationship ProductReference="libX11-data-1.6.3-6.1" RelationType="Default Component Of" RelatesToProductReference="openSUSE Leap 42.1">
      <FullProductName ProductID="openSUSE Leap 42.1:libX11-data-1.6.3-6.1">libX11-data-1.6.3-6.1 as a component of openSUSE Leap 42.1</FullProductName>
    </Relationship>
    <Relationship ProductReference="libX11-devel-1.6.3-6.1" RelationType="Default Component Of" RelatesToProductReference="openSUSE Leap 42.1">
      <FullProductName ProductID="openSUSE Leap 42.1:libX11-devel-1.6.3-6.1">libX11-devel-1.6.3-6.1 as a component of openSUSE Leap 42.1</FullProductName>
    </Relationship>
    <Relationship ProductReference="libX11-devel-32bit-1.6.3-6.1" RelationType="Default Component Of" RelatesToProductReference="openSUSE Leap 42.1">
      <FullProductName ProductID="openSUSE Leap 42.1:libX11-devel-32bit-1.6.3-6.1">libX11-devel-32bit-1.6.3-6.1 as a component of openSUSE Leap 42.1</FullProductName>
    </Relationship>
    <Relationship ProductReference="libX11-xcb1-1.6.3-6.1" RelationType="Default Component Of" RelatesToProductReference="openSUSE Leap 42.1">
      <FullProductName ProductID="openSUSE Leap 42.1:libX11-xcb1-1.6.3-6.1">libX11-xcb1-1.6.3-6.1 as a component of openSUSE Leap 42.1</FullProductName>
    </Relationship>
    <Relationship ProductReference="libX11-xcb1-32bit-1.6.3-6.1" RelationType="Default Component Of" RelatesToProductReference="openSUSE Leap 42.1">
      <FullProductName ProductID="openSUSE Leap 42.1:libX11-xcb1-32bit-1.6.3-6.1">libX11-xcb1-32bit-1.6.3-6.1 as a component of openSUSE Leap 42.1</FullProductName>
    </Relationship>
    <Relationship ProductReference="libXfixes-5.0.1-7.1" RelationType="Default Component Of" RelatesToProductReference="openSUSE Leap 42.1">
      <FullProductName ProductID="openSUSE Leap 42.1:libXfixes-5.0.1-7.1">libXfixes-5.0.1-7.1 as a component of openSUSE Leap 42.1</FullProductName>
    </Relationship>
    <Relationship ProductReference="libXfixes-devel-5.0.1-7.1" RelationType="Default Component Of" RelatesToProductReference="openSUSE Leap 42.1">
      <FullProductName ProductID="openSUSE Leap 42.1:libXfixes-devel-5.0.1-7.1">libXfixes-devel-5.0.1-7.1 as a component of openSUSE Leap 42.1</FullProductName>
    </Relationship>
    <Relationship ProductReference="libXfixes-devel-32bit-5.0.1-7.1" RelationType="Default Component Of" RelatesToProductReference="openSUSE Leap 42.1">
      <FullProductName ProductID="openSUSE Leap 42.1:libXfixes-devel-32bit-5.0.1-7.1">libXfixes-devel-32bit-5.0.1-7.1 as a component of openSUSE Leap 42.1</FullProductName>
    </Relationship>
    <Relationship ProductReference="libXfixes3-5.0.1-7.1" RelationType="Default Component Of" RelatesToProductReference="openSUSE Leap 42.1">
      <FullProductName ProductID="openSUSE Leap 42.1:libXfixes3-5.0.1-7.1">libXfixes3-5.0.1-7.1 as a component of openSUSE Leap 42.1</FullProductName>
    </Relationship>
    <Relationship ProductReference="libXfixes3-32bit-5.0.1-7.1" RelationType="Default Component Of" RelatesToProductReference="openSUSE Leap 42.1">
      <FullProductName ProductID="openSUSE Leap 42.1:libXfixes3-32bit-5.0.1-7.1">libXfixes3-32bit-5.0.1-7.1 as a component of openSUSE Leap 42.1</FullProductName>
    </Relationship>
    <Relationship ProductReference="libXi-1.7.5-3.1" RelationType="Default Component Of" RelatesToProductReference="openSUSE Leap 42.1">
      <FullProductName ProductID="openSUSE Leap 42.1:libXi-1.7.5-3.1">libXi-1.7.5-3.1 as a component of openSUSE Leap 42.1</FullProductName>
    </Relationship>
    <Relationship ProductReference="libXi-devel-1.7.5-3.1" RelationType="Default Component Of" RelatesToProductReference="openSUSE Leap 42.1">
      <FullProductName ProductID="openSUSE Leap 42.1:libXi-devel-1.7.5-3.1">libXi-devel-1.7.5-3.1 as a component of openSUSE Leap 42.1</FullProductName>
    </Relationship>
    <Relationship ProductReference="libXi-devel-32bit-1.7.5-3.1" RelationType="Default Component Of" RelatesToProductReference="openSUSE Leap 42.1">
      <FullProductName ProductID="openSUSE Leap 42.1:libXi-devel-32bit-1.7.5-3.1">libXi-devel-32bit-1.7.5-3.1 as a component of openSUSE Leap 42.1</FullProductName>
    </Relationship>
    <Relationship ProductReference="libXi6-1.7.5-3.1" RelationType="Default Component Of" RelatesToProductReference="openSUSE Leap 42.1">
      <FullProductName ProductID="openSUSE Leap 42.1:libXi6-1.7.5-3.1">libXi6-1.7.5-3.1 as a component of openSUSE Leap 42.1</FullProductName>
    </Relationship>
    <Relationship ProductReference="libXi6-32bit-1.7.5-3.1" RelationType="Default Component Of" RelatesToProductReference="openSUSE Leap 42.1">
      <FullProductName ProductID="openSUSE Leap 42.1:libXi6-32bit-1.7.5-3.1">libXi6-32bit-1.7.5-3.1 as a component of openSUSE Leap 42.1</FullProductName>
    </Relationship>
    <Relationship ProductReference="libXrandr-1.5.0-3.1" RelationType="Default Component Of" RelatesToProductReference="openSUSE Leap 42.1">
      <FullProductName ProductID="openSUSE Leap 42.1:libXrandr-1.5.0-3.1">libXrandr-1.5.0-3.1 as a component of openSUSE Leap 42.1</FullProductName>
    </Relationship>
    <Relationship ProductReference="libXrandr-devel-1.5.0-3.1" RelationType="Default Component Of" RelatesToProductReference="openSUSE Leap 42.1">
      <FullProductName ProductID="openSUSE Leap 42.1:libXrandr-devel-1.5.0-3.1">libXrandr-devel-1.5.0-3.1 as a component of openSUSE Leap 42.1</FullProductName>
    </Relationship>
    <Relationship ProductReference="libXrandr-devel-32bit-1.5.0-3.1" RelationType="Default Component Of" RelatesToProductReference="openSUSE Leap 42.1">
      <FullProductName ProductID="openSUSE Leap 42.1:libXrandr-devel-32bit-1.5.0-3.1">libXrandr-devel-32bit-1.5.0-3.1 as a component of openSUSE Leap 42.1</FullProductName>
    </Relationship>
    <Relationship ProductReference="libXrandr2-1.5.0-3.1" RelationType="Default Component Of" RelatesToProductReference="openSUSE Leap 42.1">
      <FullProductName ProductID="openSUSE Leap 42.1:libXrandr2-1.5.0-3.1">libXrandr2-1.5.0-3.1 as a component of openSUSE Leap 42.1</FullProductName>
    </Relationship>
    <Relationship ProductReference="libXrandr2-32bit-1.5.0-3.1" RelationType="Default Component Of" RelatesToProductReference="openSUSE Leap 42.1">
      <FullProductName ProductID="openSUSE Leap 42.1:libXrandr2-32bit-1.5.0-3.1">libXrandr2-32bit-1.5.0-3.1 as a component of openSUSE Leap 42.1</FullProductName>
    </Relationship>
    <Relationship ProductReference="libXrender-0.9.9-3.1" RelationType="Default Component Of" RelatesToProductReference="openSUSE Leap 42.1">
      <FullProductName ProductID="openSUSE Leap 42.1:libXrender-0.9.9-3.1">libXrender-0.9.9-3.1 as a component of openSUSE Leap 42.1</FullProductName>
    </Relationship>
    <Relationship ProductReference="libXrender-devel-0.9.9-3.1" RelationType="Default Component Of" RelatesToProductReference="openSUSE Leap 42.1">
      <FullProductName ProductID="openSUSE Leap 42.1:libXrender-devel-0.9.9-3.1">libXrender-devel-0.9.9-3.1 as a component of openSUSE Leap 42.1</FullProductName>
    </Relationship>
    <Relationship ProductReference="libXrender-devel-32bit-0.9.9-3.1" RelationType="Default Component Of" RelatesToProductReference="openSUSE Leap 42.1">
      <FullProductName ProductID="openSUSE Leap 42.1:libXrender-devel-32bit-0.9.9-3.1">libXrender-devel-32bit-0.9.9-3.1 as a component of openSUSE Leap 42.1</FullProductName>
    </Relationship>
    <Relationship ProductReference="libXrender1-0.9.9-3.1" RelationType="Default Component Of" RelatesToProductReference="openSUSE Leap 42.1">
      <FullProductName ProductID="openSUSE Leap 42.1:libXrender1-0.9.9-3.1">libXrender1-0.9.9-3.1 as a component of openSUSE Leap 42.1</FullProductName>
    </Relationship>
    <Relationship ProductReference="libXrender1-32bit-0.9.9-3.1" RelationType="Default Component Of" RelatesToProductReference="openSUSE Leap 42.1">
      <FullProductName ProductID="openSUSE Leap 42.1:libXrender1-32bit-0.9.9-3.1">libXrender1-32bit-0.9.9-3.1 as a component of openSUSE Leap 42.1</FullProductName>
    </Relationship>
    <Relationship ProductReference="libXtst-1.2.2-7.1" RelationType="Default Component Of" RelatesToProductReference="openSUSE Leap 42.1">
      <FullProductName ProductID="openSUSE Leap 42.1:libXtst-1.2.2-7.1">libXtst-1.2.2-7.1 as a component of openSUSE Leap 42.1</FullProductName>
    </Relationship>
    <Relationship ProductReference="libXtst-devel-1.2.2-7.1" RelationType="Default Component Of" RelatesToProductReference="openSUSE Leap 42.1">
      <FullProductName ProductID="openSUSE Leap 42.1:libXtst-devel-1.2.2-7.1">libXtst-devel-1.2.2-7.1 as a component of openSUSE Leap 42.1</FullProductName>
    </Relationship>
    <Relationship ProductReference="libXtst-devel-32bit-1.2.2-7.1" RelationType="Default Component Of" RelatesToProductReference="openSUSE Leap 42.1">
      <FullProductName ProductID="openSUSE Leap 42.1:libXtst-devel-32bit-1.2.2-7.1">libXtst-devel-32bit-1.2.2-7.1 as a component of openSUSE Leap 42.1</FullProductName>
    </Relationship>
    <Relationship ProductReference="libXtst6-1.2.2-7.1" RelationType="Default Component Of" RelatesToProductReference="openSUSE Leap 42.1">
      <FullProductName ProductID="openSUSE Leap 42.1:libXtst6-1.2.2-7.1">libXtst6-1.2.2-7.1 as a component of openSUSE Leap 42.1</FullProductName>
    </Relationship>
    <Relationship ProductReference="libXtst6-32bit-1.2.2-7.1" RelationType="Default Component Of" RelatesToProductReference="openSUSE Leap 42.1">
      <FullProductName ProductID="openSUSE Leap 42.1:libXtst6-32bit-1.2.2-7.1">libXtst6-32bit-1.2.2-7.1 as a component of openSUSE Leap 42.1</FullProductName>
    </Relationship>
    <Relationship ProductReference="libXv-1.0.10-7.1" RelationType="Default Component Of" RelatesToProductReference="openSUSE Leap 42.1">
      <FullProductName ProductID="openSUSE Leap 42.1:libXv-1.0.10-7.1">libXv-1.0.10-7.1 as a component of openSUSE Leap 42.1</FullProductName>
    </Relationship>
    <Relationship ProductReference="libXv-devel-1.0.10-7.1" RelationType="Default Component Of" RelatesToProductReference="openSUSE Leap 42.1">
      <FullProductName ProductID="openSUSE Leap 42.1:libXv-devel-1.0.10-7.1">libXv-devel-1.0.10-7.1 as a component of openSUSE Leap 42.1</FullProductName>
    </Relationship>
    <Relationship ProductReference="libXv-devel-32bit-1.0.10-7.1" RelationType="Default Component Of" RelatesToProductReference="openSUSE Leap 42.1">
      <FullProductName ProductID="openSUSE Leap 42.1:libXv-devel-32bit-1.0.10-7.1">libXv-devel-32bit-1.0.10-7.1 as a component of openSUSE Leap 42.1</FullProductName>
    </Relationship>
    <Relationship ProductReference="libXv1-1.0.10-7.1" RelationType="Default Component Of" RelatesToProductReference="openSUSE Leap 42.1">
      <FullProductName ProductID="openSUSE Leap 42.1:libXv1-1.0.10-7.1">libXv1-1.0.10-7.1 as a component of openSUSE Leap 42.1</FullProductName>
    </Relationship>
    <Relationship ProductReference="libXv1-32bit-1.0.10-7.1" RelationType="Default Component Of" RelatesToProductReference="openSUSE Leap 42.1">
      <FullProductName ProductID="openSUSE Leap 42.1:libXv1-32bit-1.0.10-7.1">libXv1-32bit-1.0.10-7.1 as a component of openSUSE Leap 42.1</FullProductName>
    </Relationship>
    <Relationship ProductReference="libXvMC-1.0.9-3.1" RelationType="Default Component Of" RelatesToProductReference="openSUSE Leap 42.1">
      <FullProductName ProductID="openSUSE Leap 42.1:libXvMC-1.0.9-3.1">libXvMC-1.0.9-3.1 as a component of openSUSE Leap 42.1</FullProductName>
    </Relationship>
    <Relationship ProductReference="libXvMC-devel-1.0.9-3.1" RelationType="Default Component Of" RelatesToProductReference="openSUSE Leap 42.1">
      <FullProductName ProductID="openSUSE Leap 42.1:libXvMC-devel-1.0.9-3.1">libXvMC-devel-1.0.9-3.1 as a component of openSUSE Leap 42.1</FullProductName>
    </Relationship>
    <Relationship ProductReference="libXvMC-devel-32bit-1.0.9-3.1" RelationType="Default Component Of" RelatesToProductReference="openSUSE Leap 42.1">
      <FullProductName ProductID="openSUSE Leap 42.1:libXvMC-devel-32bit-1.0.9-3.1">libXvMC-devel-32bit-1.0.9-3.1 as a component of openSUSE Leap 42.1</FullProductName>
    </Relationship>
    <Relationship ProductReference="libXvMC1-1.0.9-3.1" RelationType="Default Component Of" RelatesToProductReference="openSUSE Leap 42.1">
      <FullProductName ProductID="openSUSE Leap 42.1:libXvMC1-1.0.9-3.1">libXvMC1-1.0.9-3.1 as a component of openSUSE Leap 42.1</FullProductName>
    </Relationship>
    <Relationship ProductReference="libXvMC1-32bit-1.0.9-3.1" RelationType="Default Component Of" RelatesToProductReference="openSUSE Leap 42.1">
      <FullProductName ProductID="openSUSE Leap 42.1:libXvMC1-32bit-1.0.9-3.1">libXvMC1-32bit-1.0.9-3.1 as a component of openSUSE Leap 42.1</FullProductName>
    </Relationship>
  </ProductTree>
  <Vulnerability xmlns="http://www.icasi.org/CVRF/schema/vuln/1.1" Ordinal="1">
    <Notes>
      <Note Title="Vulnerability Description" Type="General" Ordinal="1" xml:lang="en">The (1) XvQueryAdaptors and (2) XvQueryEncodings functions in X.org libXv before 1.0.11 allow remote X servers to trigger out-of-bounds memory access operations via vectors involving length specifications in received data.</Note>
    </Notes>
    <CVE>CVE-2016-5407</CVE>
    <ProductStatuses>
      <Status Type="Fixed">
        <ProductID>openSUSE Leap 42.1:libX11-1.6.3-6.1</ProductID>
        <ProductID>openSUSE Leap 42.1:libX11-6-1.6.3-6.1</ProductID>
        <ProductID>openSUSE Leap 42.1:libX11-6-32bit-1.6.3-6.1</ProductID>
        <ProductID>openSUSE Leap 42.1:libX11-data-1.6.3-6.1</ProductID>
        <ProductID>openSUSE Leap 42.1:libX11-devel-1.6.3-6.1</ProductID>
        <ProductID>openSUSE Leap 42.1:libX11-devel-32bit-1.6.3-6.1</ProductID>
        <ProductID>openSUSE Leap 42.1:libX11-xcb1-1.6.3-6.1</ProductID>
        <ProductID>openSUSE Leap 42.1:libX11-xcb1-32bit-1.6.3-6.1</ProductID>
        <ProductID>openSUSE Leap 42.1:libXfixes-5.0.1-7.1</ProductID>
        <ProductID>openSUSE Leap 42.1:libXfixes-devel-32bit-5.0.1-7.1</ProductID>
        <ProductID>openSUSE Leap 42.1:libXfixes-devel-5.0.1-7.1</ProductID>
        <ProductID>openSUSE Leap 42.1:libXfixes3-32bit-5.0.1-7.1</ProductID>
        <ProductID>openSUSE Leap 42.1:libXfixes3-5.0.1-7.1</ProductID>
        <ProductID>openSUSE Leap 42.1:libXi-1.7.5-3.1</ProductID>
        <ProductID>openSUSE Leap 42.1:libXi-devel-1.7.5-3.1</ProductID>
        <ProductID>openSUSE Leap 42.1:libXi-devel-32bit-1.7.5-3.1</ProductID>
        <ProductID>openSUSE Leap 42.1:libXi6-1.7.5-3.1</ProductID>
        <ProductID>openSUSE Leap 42.1:libXi6-32bit-1.7.5-3.1</ProductID>
        <ProductID>openSUSE Leap 42.1:libXrandr-1.5.0-3.1</ProductID>
        <ProductID>openSUSE Leap 42.1:libXrandr-devel-1.5.0-3.1</ProductID>
        <ProductID>openSUSE Leap 42.1:libXrandr-devel-32bit-1.5.0-3.1</ProductID>
        <ProductID>openSUSE Leap 42.1:libXrandr2-1.5.0-3.1</ProductID>
        <ProductID>openSUSE Leap 42.1:libXrandr2-32bit-1.5.0-3.1</ProductID>
        <ProductID>openSUSE Leap 42.1:libXrender-0.9.9-3.1</ProductID>
        <ProductID>openSUSE Leap 42.1:libXrender-devel-0.9.9-3.1</ProductID>
        <ProductID>openSUSE Leap 42.1:libXrender-devel-32bit-0.9.9-3.1</ProductID>
        <ProductID>openSUSE Leap 42.1:libXrender1-0.9.9-3.1</ProductID>
        <ProductID>openSUSE Leap 42.1:libXrender1-32bit-0.9.9-3.1</ProductID>
        <ProductID>openSUSE Leap 42.1:libXtst-1.2.2-7.1</ProductID>
        <ProductID>openSUSE Leap 42.1:libXtst-devel-1.2.2-7.1</ProductID>
        <ProductID>openSUSE Leap 42.1:libXtst-devel-32bit-1.2.2-7.1</ProductID>
        <ProductID>openSUSE Leap 42.1:libXtst6-1.2.2-7.1</ProductID>
        <ProductID>openSUSE Leap 42.1:libXtst6-32bit-1.2.2-7.1</ProductID>
        <ProductID>openSUSE Leap 42.1:libXv-1.0.10-7.1</ProductID>
        <ProductID>openSUSE Leap 42.1:libXv-devel-1.0.10-7.1</ProductID>
        <ProductID>openSUSE Leap 42.1:libXv-devel-32bit-1.0.10-7.1</ProductID>
        <ProductID>openSUSE Leap 42.1:libXv1-1.0.10-7.1</ProductID>
        <ProductID>openSUSE Leap 42.1:libXv1-32bit-1.0.10-7.1</ProductID>
        <ProductID>openSUSE Leap 42.1:libXvMC-1.0.9-3.1</ProductID>
        <ProductID>openSUSE Leap 42.1:libXvMC-devel-1.0.9-3.1</ProductID>
        <ProductID>openSUSE Leap 42.1:libXvMC-devel-32bit-1.0.9-3.1</ProductID>
        <ProductID>openSUSE Leap 42.1:libXvMC1-1.0.9-3.1</ProductID>
        <ProductID>openSUSE Leap 42.1:libXvMC1-32bit-1.0.9-3.1</ProductID>
      </Status>
    </ProductStatuses>
    <Threats>
      <Threat Type="Impact">
        <Description>moderate</Description>
      </Threat>
    </Threats>
    <CVSSScoreSets>
      <ScoreSet>
        <BaseScore>5.1</BaseScore>
        <Vector>AV:N/AC:H/Au:N/C:P/I:P/A:P</Vector>
      </ScoreSet>
    </CVSSScoreSets>
    <Remediations>
      <Remediation Type="Vendor Fix">
        <Description xml:lang="en">Please Install the update.</Description>
        <URL>https://lists.opensuse.org/opensuse-updates/2016-10/msg00078.html</URL>
      </Remediation>
    </Remediations>
    <References>
      <Reference>
        <URL>https://www.suse.com/security/cve/CVE-2016-5407.html</URL>
        <Description>CVE-2016-5407</Description>
      </Reference>
      <Reference>
        <URL>https://bugzilla.suse.com/1003017</URL>
        <Description>SUSE Bug 1003017</Description>
      </Reference>
      <Reference>
        <URL>https://bugzilla.suse.com/1123148</URL>
        <Description>SUSE Bug 1123148</Description>
      </Reference>
    </References>
  </Vulnerability>
  <Vulnerability xmlns="http://www.icasi.org/CVRF/schema/vuln/1.1" Ordinal="2">
    <Notes>
      <Note Title="Vulnerability Description" Type="General" Ordinal="1" xml:lang="en">The XGetImage function in X.org libX11 before 1.6.4 might allow remote X servers to gain privileges via vectors involving image type and geometry, which triggers out-of-bounds read operations.</Note>
    </Notes>
    <CVE>CVE-2016-7942</CVE>
    <ProductStatuses>
      <Status Type="Fixed">
        <ProductID>openSUSE Leap 42.1:libX11-1.6.3-6.1</ProductID>
        <ProductID>openSUSE Leap 42.1:libX11-6-1.6.3-6.1</ProductID>
        <ProductID>openSUSE Leap 42.1:libX11-6-32bit-1.6.3-6.1</ProductID>
        <ProductID>openSUSE Leap 42.1:libX11-data-1.6.3-6.1</ProductID>
        <ProductID>openSUSE Leap 42.1:libX11-devel-1.6.3-6.1</ProductID>
        <ProductID>openSUSE Leap 42.1:libX11-devel-32bit-1.6.3-6.1</ProductID>
        <ProductID>openSUSE Leap 42.1:libX11-xcb1-1.6.3-6.1</ProductID>
        <ProductID>openSUSE Leap 42.1:libX11-xcb1-32bit-1.6.3-6.1</ProductID>
        <ProductID>openSUSE Leap 42.1:libXfixes-5.0.1-7.1</ProductID>
        <ProductID>openSUSE Leap 42.1:libXfixes-devel-32bit-5.0.1-7.1</ProductID>
        <ProductID>openSUSE Leap 42.1:libXfixes-devel-5.0.1-7.1</ProductID>
        <ProductID>openSUSE Leap 42.1:libXfixes3-32bit-5.0.1-7.1</ProductID>
        <ProductID>openSUSE Leap 42.1:libXfixes3-5.0.1-7.1</ProductID>
        <ProductID>openSUSE Leap 42.1:libXi-1.7.5-3.1</ProductID>
        <ProductID>openSUSE Leap 42.1:libXi-devel-1.7.5-3.1</ProductID>
        <ProductID>openSUSE Leap 42.1:libXi-devel-32bit-1.7.5-3.1</ProductID>
        <ProductID>openSUSE Leap 42.1:libXi6-1.7.5-3.1</ProductID>
        <ProductID>openSUSE Leap 42.1:libXi6-32bit-1.7.5-3.1</ProductID>
        <ProductID>openSUSE Leap 42.1:libXrandr-1.5.0-3.1</ProductID>
        <ProductID>openSUSE Leap 42.1:libXrandr-devel-1.5.0-3.1</ProductID>
        <ProductID>openSUSE Leap 42.1:libXrandr-devel-32bit-1.5.0-3.1</ProductID>
        <ProductID>openSUSE Leap 42.1:libXrandr2-1.5.0-3.1</ProductID>
        <ProductID>openSUSE Leap 42.1:libXrandr2-32bit-1.5.0-3.1</ProductID>
        <ProductID>openSUSE Leap 42.1:libXrender-0.9.9-3.1</ProductID>
        <ProductID>openSUSE Leap 42.1:libXrender-devel-0.9.9-3.1</ProductID>
        <ProductID>openSUSE Leap 42.1:libXrender-devel-32bit-0.9.9-3.1</ProductID>
        <ProductID>openSUSE Leap 42.1:libXrender1-0.9.9-3.1</ProductID>
        <ProductID>openSUSE Leap 42.1:libXrender1-32bit-0.9.9-3.1</ProductID>
        <ProductID>openSUSE Leap 42.1:libXtst-1.2.2-7.1</ProductID>
        <ProductID>openSUSE Leap 42.1:libXtst-devel-1.2.2-7.1</ProductID>
        <ProductID>openSUSE Leap 42.1:libXtst-devel-32bit-1.2.2-7.1</ProductID>
        <ProductID>openSUSE Leap 42.1:libXtst6-1.2.2-7.1</ProductID>
        <ProductID>openSUSE Leap 42.1:libXtst6-32bit-1.2.2-7.1</ProductID>
        <ProductID>openSUSE Leap 42.1:libXv-1.0.10-7.1</ProductID>
        <ProductID>openSUSE Leap 42.1:libXv-devel-1.0.10-7.1</ProductID>
        <ProductID>openSUSE Leap 42.1:libXv-devel-32bit-1.0.10-7.1</ProductID>
        <ProductID>openSUSE Leap 42.1:libXv1-1.0.10-7.1</ProductID>
        <ProductID>openSUSE Leap 42.1:libXv1-32bit-1.0.10-7.1</ProductID>
        <ProductID>openSUSE Leap 42.1:libXvMC-1.0.9-3.1</ProductID>
        <ProductID>openSUSE Leap 42.1:libXvMC-devel-1.0.9-3.1</ProductID>
        <ProductID>openSUSE Leap 42.1:libXvMC-devel-32bit-1.0.9-3.1</ProductID>
        <ProductID>openSUSE Leap 42.1:libXvMC1-1.0.9-3.1</ProductID>
        <ProductID>openSUSE Leap 42.1:libXvMC1-32bit-1.0.9-3.1</ProductID>
      </Status>
    </ProductStatuses>
    <Threats>
      <Threat Type="Impact">
        <Description>moderate</Description>
      </Threat>
    </Threats>
    <CVSSScoreSets>
      <ScoreSet>
        <BaseScore>5.1</BaseScore>
        <Vector>AV:N/AC:H/Au:N/C:P/I:P/A:P</Vector>
      </ScoreSet>
    </CVSSScoreSets>
    <Remediations>
      <Remediation Type="Vendor Fix">
        <Description xml:lang="en">Please Install the update.</Description>
        <URL>https://lists.opensuse.org/opensuse-updates/2016-10/msg00078.html</URL>
      </Remediation>
    </Remediations>
    <References>
      <Reference>
        <URL>https://www.suse.com/security/cve/CVE-2016-7942.html</URL>
        <Description>CVE-2016-7942</Description>
      </Reference>
      <Reference>
        <URL>https://bugzilla.suse.com/1002991</URL>
        <Description>SUSE Bug 1002991</Description>
      </Reference>
      <Reference>
        <URL>https://bugzilla.suse.com/1174752</URL>
        <Description>SUSE Bug 1174752</Description>
      </Reference>
    </References>
  </Vulnerability>
  <Vulnerability xmlns="http://www.icasi.org/CVRF/schema/vuln/1.1" Ordinal="3">
    <Notes>
      <Note Title="Vulnerability Description" Type="General" Ordinal="1" xml:lang="en">Integer overflow in X.org libXfixes before 5.0.3 on 32-bit platforms might allow remote X servers to gain privileges via a length value of INT_MAX, which triggers the client to stop reading data and get out of sync.</Note>
    </Notes>
    <CVE>CVE-2016-7944</CVE>
    <ProductStatuses>
      <Status Type="Fixed">
        <ProductID>openSUSE Leap 42.1:libX11-1.6.3-6.1</ProductID>
        <ProductID>openSUSE Leap 42.1:libX11-6-1.6.3-6.1</ProductID>
        <ProductID>openSUSE Leap 42.1:libX11-6-32bit-1.6.3-6.1</ProductID>
        <ProductID>openSUSE Leap 42.1:libX11-data-1.6.3-6.1</ProductID>
        <ProductID>openSUSE Leap 42.1:libX11-devel-1.6.3-6.1</ProductID>
        <ProductID>openSUSE Leap 42.1:libX11-devel-32bit-1.6.3-6.1</ProductID>
        <ProductID>openSUSE Leap 42.1:libX11-xcb1-1.6.3-6.1</ProductID>
        <ProductID>openSUSE Leap 42.1:libX11-xcb1-32bit-1.6.3-6.1</ProductID>
        <ProductID>openSUSE Leap 42.1:libXfixes-5.0.1-7.1</ProductID>
        <ProductID>openSUSE Leap 42.1:libXfixes-devel-32bit-5.0.1-7.1</ProductID>
        <ProductID>openSUSE Leap 42.1:libXfixes-devel-5.0.1-7.1</ProductID>
        <ProductID>openSUSE Leap 42.1:libXfixes3-32bit-5.0.1-7.1</ProductID>
        <ProductID>openSUSE Leap 42.1:libXfixes3-5.0.1-7.1</ProductID>
        <ProductID>openSUSE Leap 42.1:libXi-1.7.5-3.1</ProductID>
        <ProductID>openSUSE Leap 42.1:libXi-devel-1.7.5-3.1</ProductID>
        <ProductID>openSUSE Leap 42.1:libXi-devel-32bit-1.7.5-3.1</ProductID>
        <ProductID>openSUSE Leap 42.1:libXi6-1.7.5-3.1</ProductID>
        <ProductID>openSUSE Leap 42.1:libXi6-32bit-1.7.5-3.1</ProductID>
        <ProductID>openSUSE Leap 42.1:libXrandr-1.5.0-3.1</ProductID>
        <ProductID>openSUSE Leap 42.1:libXrandr-devel-1.5.0-3.1</ProductID>
        <ProductID>openSUSE Leap 42.1:libXrandr-devel-32bit-1.5.0-3.1</ProductID>
        <ProductID>openSUSE Leap 42.1:libXrandr2-1.5.0-3.1</ProductID>
        <ProductID>openSUSE Leap 42.1:libXrandr2-32bit-1.5.0-3.1</ProductID>
        <ProductID>openSUSE Leap 42.1:libXrender-0.9.9-3.1</ProductID>
        <ProductID>openSUSE Leap 42.1:libXrender-devel-0.9.9-3.1</ProductID>
        <ProductID>openSUSE Leap 42.1:libXrender-devel-32bit-0.9.9-3.1</ProductID>
        <ProductID>openSUSE Leap 42.1:libXrender1-0.9.9-3.1</ProductID>
        <ProductID>openSUSE Leap 42.1:libXrender1-32bit-0.9.9-3.1</ProductID>
        <ProductID>openSUSE Leap 42.1:libXtst-1.2.2-7.1</ProductID>
        <ProductID>openSUSE Leap 42.1:libXtst-devel-1.2.2-7.1</ProductID>
        <ProductID>openSUSE Leap 42.1:libXtst-devel-32bit-1.2.2-7.1</ProductID>
        <ProductID>openSUSE Leap 42.1:libXtst6-1.2.2-7.1</ProductID>
        <ProductID>openSUSE Leap 42.1:libXtst6-32bit-1.2.2-7.1</ProductID>
        <ProductID>openSUSE Leap 42.1:libXv-1.0.10-7.1</ProductID>
        <ProductID>openSUSE Leap 42.1:libXv-devel-1.0.10-7.1</ProductID>
        <ProductID>openSUSE Leap 42.1:libXv-devel-32bit-1.0.10-7.1</ProductID>
        <ProductID>openSUSE Leap 42.1:libXv1-1.0.10-7.1</ProductID>
        <ProductID>openSUSE Leap 42.1:libXv1-32bit-1.0.10-7.1</ProductID>
        <ProductID>openSUSE Leap 42.1:libXvMC-1.0.9-3.1</ProductID>
        <ProductID>openSUSE Leap 42.1:libXvMC-devel-1.0.9-3.1</ProductID>
        <ProductID>openSUSE Leap 42.1:libXvMC-devel-32bit-1.0.9-3.1</ProductID>
        <ProductID>openSUSE Leap 42.1:libXvMC1-1.0.9-3.1</ProductID>
        <ProductID>openSUSE Leap 42.1:libXvMC1-32bit-1.0.9-3.1</ProductID>
      </Status>
    </ProductStatuses>
    <Threats>
      <Threat Type="Impact">
        <Description>moderate</Description>
      </Threat>
    </Threats>
    <CVSSScoreSets>
      <ScoreSet>
        <BaseScore>5.1</BaseScore>
        <Vector>AV:N/AC:H/Au:N/C:P/I:P/A:P</Vector>
      </ScoreSet>
    </CVSSScoreSets>
    <Remediations>
      <Remediation Type="Vendor Fix">
        <Description xml:lang="en">Please Install the update.</Description>
        <URL>https://lists.opensuse.org/opensuse-updates/2016-10/msg00078.html</URL>
      </Remediation>
    </Remediations>
    <References>
      <Reference>
        <URL>https://www.suse.com/security/cve/CVE-2016-7944.html</URL>
        <Description>CVE-2016-7944</Description>
      </Reference>
      <Reference>
        <URL>https://bugzilla.suse.com/1002995</URL>
        <Description>SUSE Bug 1002995</Description>
      </Reference>
      <Reference>
        <URL>https://bugzilla.suse.com/1149962</URL>
        <Description>SUSE Bug 1149962</Description>
      </Reference>
    </References>
  </Vulnerability>
  <Vulnerability xmlns="http://www.icasi.org/CVRF/schema/vuln/1.1" Ordinal="4">
    <Notes>
      <Note Title="Vulnerability Description" Type="General" Ordinal="1" xml:lang="en">Multiple integer overflows in X.org libXi before 1.7.7 allow remote X servers to cause a denial of service (out-of-bounds memory access or infinite loop) via vectors involving length fields.</Note>
    </Notes>
    <CVE>CVE-2016-7945</CVE>
    <ProductStatuses>
      <Status Type="Fixed">
        <ProductID>openSUSE Leap 42.1:libX11-1.6.3-6.1</ProductID>
        <ProductID>openSUSE Leap 42.1:libX11-6-1.6.3-6.1</ProductID>
        <ProductID>openSUSE Leap 42.1:libX11-6-32bit-1.6.3-6.1</ProductID>
        <ProductID>openSUSE Leap 42.1:libX11-data-1.6.3-6.1</ProductID>
        <ProductID>openSUSE Leap 42.1:libX11-devel-1.6.3-6.1</ProductID>
        <ProductID>openSUSE Leap 42.1:libX11-devel-32bit-1.6.3-6.1</ProductID>
        <ProductID>openSUSE Leap 42.1:libX11-xcb1-1.6.3-6.1</ProductID>
        <ProductID>openSUSE Leap 42.1:libX11-xcb1-32bit-1.6.3-6.1</ProductID>
        <ProductID>openSUSE Leap 42.1:libXfixes-5.0.1-7.1</ProductID>
        <ProductID>openSUSE Leap 42.1:libXfixes-devel-32bit-5.0.1-7.1</ProductID>
        <ProductID>openSUSE Leap 42.1:libXfixes-devel-5.0.1-7.1</ProductID>
        <ProductID>openSUSE Leap 42.1:libXfixes3-32bit-5.0.1-7.1</ProductID>
        <ProductID>openSUSE Leap 42.1:libXfixes3-5.0.1-7.1</ProductID>
        <ProductID>openSUSE Leap 42.1:libXi-1.7.5-3.1</ProductID>
        <ProductID>openSUSE Leap 42.1:libXi-devel-1.7.5-3.1</ProductID>
        <ProductID>openSUSE Leap 42.1:libXi-devel-32bit-1.7.5-3.1</ProductID>
        <ProductID>openSUSE Leap 42.1:libXi6-1.7.5-3.1</ProductID>
        <ProductID>openSUSE Leap 42.1:libXi6-32bit-1.7.5-3.1</ProductID>
        <ProductID>openSUSE Leap 42.1:libXrandr-1.5.0-3.1</ProductID>
        <ProductID>openSUSE Leap 42.1:libXrandr-devel-1.5.0-3.1</ProductID>
        <ProductID>openSUSE Leap 42.1:libXrandr-devel-32bit-1.5.0-3.1</ProductID>
        <ProductID>openSUSE Leap 42.1:libXrandr2-1.5.0-3.1</ProductID>
        <ProductID>openSUSE Leap 42.1:libXrandr2-32bit-1.5.0-3.1</ProductID>
        <ProductID>openSUSE Leap 42.1:libXrender-0.9.9-3.1</ProductID>
        <ProductID>openSUSE Leap 42.1:libXrender-devel-0.9.9-3.1</ProductID>
        <ProductID>openSUSE Leap 42.1:libXrender-devel-32bit-0.9.9-3.1</ProductID>
        <ProductID>openSUSE Leap 42.1:libXrender1-0.9.9-3.1</ProductID>
        <ProductID>openSUSE Leap 42.1:libXrender1-32bit-0.9.9-3.1</ProductID>
        <ProductID>openSUSE Leap 42.1:libXtst-1.2.2-7.1</ProductID>
        <ProductID>openSUSE Leap 42.1:libXtst-devel-1.2.2-7.1</ProductID>
        <ProductID>openSUSE Leap 42.1:libXtst-devel-32bit-1.2.2-7.1</ProductID>
        <ProductID>openSUSE Leap 42.1:libXtst6-1.2.2-7.1</ProductID>
        <ProductID>openSUSE Leap 42.1:libXtst6-32bit-1.2.2-7.1</ProductID>
        <ProductID>openSUSE Leap 42.1:libXv-1.0.10-7.1</ProductID>
        <ProductID>openSUSE Leap 42.1:libXv-devel-1.0.10-7.1</ProductID>
        <ProductID>openSUSE Leap 42.1:libXv-devel-32bit-1.0.10-7.1</ProductID>
        <ProductID>openSUSE Leap 42.1:libXv1-1.0.10-7.1</ProductID>
        <ProductID>openSUSE Leap 42.1:libXv1-32bit-1.0.10-7.1</ProductID>
        <ProductID>openSUSE Leap 42.1:libXvMC-1.0.9-3.1</ProductID>
        <ProductID>openSUSE Leap 42.1:libXvMC-devel-1.0.9-3.1</ProductID>
        <ProductID>openSUSE Leap 42.1:libXvMC-devel-32bit-1.0.9-3.1</ProductID>
        <ProductID>openSUSE Leap 42.1:libXvMC1-1.0.9-3.1</ProductID>
        <ProductID>openSUSE Leap 42.1:libXvMC1-32bit-1.0.9-3.1</ProductID>
      </Status>
    </ProductStatuses>
    <Threats>
      <Threat Type="Impact">
        <Description>moderate</Description>
      </Threat>
    </Threats>
    <CVSSScoreSets>
      <ScoreSet>
        <BaseScore>5.1</BaseScore>
        <Vector>AV:N/AC:H/Au:N/C:P/I:P/A:P</Vector>
      </ScoreSet>
    </CVSSScoreSets>
    <Remediations>
      <Remediation Type="Vendor Fix">
        <Description xml:lang="en">Please Install the update.</Description>
        <URL>https://lists.opensuse.org/opensuse-updates/2016-10/msg00078.html</URL>
      </Remediation>
    </Remediations>
    <References>
      <Reference>
        <URL>https://www.suse.com/security/cve/CVE-2016-7945.html</URL>
        <Description>CVE-2016-7945</Description>
      </Reference>
      <Reference>
        <URL>https://bugzilla.suse.com/1002998</URL>
        <Description>SUSE Bug 1002998</Description>
      </Reference>
      <Reference>
        <URL>https://bugzilla.suse.com/1134167</URL>
        <Description>SUSE Bug 1134167</Description>
      </Reference>
      <Reference>
        <URL>https://bugzilla.suse.com/1159415</URL>
        <Description>SUSE Bug 1159415</Description>
      </Reference>
    </References>
  </Vulnerability>
  <Vulnerability xmlns="http://www.icasi.org/CVRF/schema/vuln/1.1" Ordinal="5">
    <Notes>
      <Note Title="Vulnerability Description" Type="General" Ordinal="1" xml:lang="en">X.org libXi before 1.7.7 allows remote X servers to cause a denial of service (infinite loop) via vectors involving length fields.</Note>
    </Notes>
    <CVE>CVE-2016-7946</CVE>
    <ProductStatuses>
      <Status Type="Fixed">
        <ProductID>openSUSE Leap 42.1:libX11-1.6.3-6.1</ProductID>
        <ProductID>openSUSE Leap 42.1:libX11-6-1.6.3-6.1</ProductID>
        <ProductID>openSUSE Leap 42.1:libX11-6-32bit-1.6.3-6.1</ProductID>
        <ProductID>openSUSE Leap 42.1:libX11-data-1.6.3-6.1</ProductID>
        <ProductID>openSUSE Leap 42.1:libX11-devel-1.6.3-6.1</ProductID>
        <ProductID>openSUSE Leap 42.1:libX11-devel-32bit-1.6.3-6.1</ProductID>
        <ProductID>openSUSE Leap 42.1:libX11-xcb1-1.6.3-6.1</ProductID>
        <ProductID>openSUSE Leap 42.1:libX11-xcb1-32bit-1.6.3-6.1</ProductID>
        <ProductID>openSUSE Leap 42.1:libXfixes-5.0.1-7.1</ProductID>
        <ProductID>openSUSE Leap 42.1:libXfixes-devel-32bit-5.0.1-7.1</ProductID>
        <ProductID>openSUSE Leap 42.1:libXfixes-devel-5.0.1-7.1</ProductID>
        <ProductID>openSUSE Leap 42.1:libXfixes3-32bit-5.0.1-7.1</ProductID>
        <ProductID>openSUSE Leap 42.1:libXfixes3-5.0.1-7.1</ProductID>
        <ProductID>openSUSE Leap 42.1:libXi-1.7.5-3.1</ProductID>
        <ProductID>openSUSE Leap 42.1:libXi-devel-1.7.5-3.1</ProductID>
        <ProductID>openSUSE Leap 42.1:libXi-devel-32bit-1.7.5-3.1</ProductID>
        <ProductID>openSUSE Leap 42.1:libXi6-1.7.5-3.1</ProductID>
        <ProductID>openSUSE Leap 42.1:libXi6-32bit-1.7.5-3.1</ProductID>
        <ProductID>openSUSE Leap 42.1:libXrandr-1.5.0-3.1</ProductID>
        <ProductID>openSUSE Leap 42.1:libXrandr-devel-1.5.0-3.1</ProductID>
        <ProductID>openSUSE Leap 42.1:libXrandr-devel-32bit-1.5.0-3.1</ProductID>
        <ProductID>openSUSE Leap 42.1:libXrandr2-1.5.0-3.1</ProductID>
        <ProductID>openSUSE Leap 42.1:libXrandr2-32bit-1.5.0-3.1</ProductID>
        <ProductID>openSUSE Leap 42.1:libXrender-0.9.9-3.1</ProductID>
        <ProductID>openSUSE Leap 42.1:libXrender-devel-0.9.9-3.1</ProductID>
        <ProductID>openSUSE Leap 42.1:libXrender-devel-32bit-0.9.9-3.1</ProductID>
        <ProductID>openSUSE Leap 42.1:libXrender1-0.9.9-3.1</ProductID>
        <ProductID>openSUSE Leap 42.1:libXrender1-32bit-0.9.9-3.1</ProductID>
        <ProductID>openSUSE Leap 42.1:libXtst-1.2.2-7.1</ProductID>
        <ProductID>openSUSE Leap 42.1:libXtst-devel-1.2.2-7.1</ProductID>
        <ProductID>openSUSE Leap 42.1:libXtst-devel-32bit-1.2.2-7.1</ProductID>
        <ProductID>openSUSE Leap 42.1:libXtst6-1.2.2-7.1</ProductID>
        <ProductID>openSUSE Leap 42.1:libXtst6-32bit-1.2.2-7.1</ProductID>
        <ProductID>openSUSE Leap 42.1:libXv-1.0.10-7.1</ProductID>
        <ProductID>openSUSE Leap 42.1:libXv-devel-1.0.10-7.1</ProductID>
        <ProductID>openSUSE Leap 42.1:libXv-devel-32bit-1.0.10-7.1</ProductID>
        <ProductID>openSUSE Leap 42.1:libXv1-1.0.10-7.1</ProductID>
        <ProductID>openSUSE Leap 42.1:libXv1-32bit-1.0.10-7.1</ProductID>
        <ProductID>openSUSE Leap 42.1:libXvMC-1.0.9-3.1</ProductID>
        <ProductID>openSUSE Leap 42.1:libXvMC-devel-1.0.9-3.1</ProductID>
        <ProductID>openSUSE Leap 42.1:libXvMC-devel-32bit-1.0.9-3.1</ProductID>
        <ProductID>openSUSE Leap 42.1:libXvMC1-1.0.9-3.1</ProductID>
        <ProductID>openSUSE Leap 42.1:libXvMC1-32bit-1.0.9-3.1</ProductID>
      </Status>
    </ProductStatuses>
    <Threats>
      <Threat Type="Impact">
        <Description>moderate</Description>
      </Threat>
    </Threats>
    <CVSSScoreSets>
      <ScoreSet>
        <BaseScore>5.1</BaseScore>
        <Vector>AV:N/AC:H/Au:N/C:P/I:P/A:P</Vector>
      </ScoreSet>
    </CVSSScoreSets>
    <Remediations>
      <Remediation Type="Vendor Fix">
        <Description xml:lang="en">Please Install the update.</Description>
        <URL>https://lists.opensuse.org/opensuse-updates/2016-10/msg00078.html</URL>
      </Remediation>
    </Remediations>
    <References>
      <Reference>
        <URL>https://www.suse.com/security/cve/CVE-2016-7946.html</URL>
        <Description>CVE-2016-7946</Description>
      </Reference>
      <Reference>
        <URL>https://bugzilla.suse.com/1002998</URL>
        <Description>SUSE Bug 1002998</Description>
      </Reference>
      <Reference>
        <URL>https://bugzilla.suse.com/1134167</URL>
        <Description>SUSE Bug 1134167</Description>
      </Reference>
      <Reference>
        <URL>https://bugzilla.suse.com/1159415</URL>
        <Description>SUSE Bug 1159415</Description>
      </Reference>
    </References>
  </Vulnerability>
  <Vulnerability xmlns="http://www.icasi.org/CVRF/schema/vuln/1.1" Ordinal="6">
    <Notes>
      <Note Title="Vulnerability Description" Type="General" Ordinal="1" xml:lang="en">Multiple integer overflows in X.org libXrandr before 1.5.1 allow remote X servers to trigger out-of-bounds write operations via a crafted response.</Note>
    </Notes>
    <CVE>CVE-2016-7947</CVE>
    <ProductStatuses>
      <Status Type="Fixed">
        <ProductID>openSUSE Leap 42.1:libX11-1.6.3-6.1</ProductID>
        <ProductID>openSUSE Leap 42.1:libX11-6-1.6.3-6.1</ProductID>
        <ProductID>openSUSE Leap 42.1:libX11-6-32bit-1.6.3-6.1</ProductID>
        <ProductID>openSUSE Leap 42.1:libX11-data-1.6.3-6.1</ProductID>
        <ProductID>openSUSE Leap 42.1:libX11-devel-1.6.3-6.1</ProductID>
        <ProductID>openSUSE Leap 42.1:libX11-devel-32bit-1.6.3-6.1</ProductID>
        <ProductID>openSUSE Leap 42.1:libX11-xcb1-1.6.3-6.1</ProductID>
        <ProductID>openSUSE Leap 42.1:libX11-xcb1-32bit-1.6.3-6.1</ProductID>
        <ProductID>openSUSE Leap 42.1:libXfixes-5.0.1-7.1</ProductID>
        <ProductID>openSUSE Leap 42.1:libXfixes-devel-32bit-5.0.1-7.1</ProductID>
        <ProductID>openSUSE Leap 42.1:libXfixes-devel-5.0.1-7.1</ProductID>
        <ProductID>openSUSE Leap 42.1:libXfixes3-32bit-5.0.1-7.1</ProductID>
        <ProductID>openSUSE Leap 42.1:libXfixes3-5.0.1-7.1</ProductID>
        <ProductID>openSUSE Leap 42.1:libXi-1.7.5-3.1</ProductID>
        <ProductID>openSUSE Leap 42.1:libXi-devel-1.7.5-3.1</ProductID>
        <ProductID>openSUSE Leap 42.1:libXi-devel-32bit-1.7.5-3.1</ProductID>
        <ProductID>openSUSE Leap 42.1:libXi6-1.7.5-3.1</ProductID>
        <ProductID>openSUSE Leap 42.1:libXi6-32bit-1.7.5-3.1</ProductID>
        <ProductID>openSUSE Leap 42.1:libXrandr-1.5.0-3.1</ProductID>
        <ProductID>openSUSE Leap 42.1:libXrandr-devel-1.5.0-3.1</ProductID>
        <ProductID>openSUSE Leap 42.1:libXrandr-devel-32bit-1.5.0-3.1</ProductID>
        <ProductID>openSUSE Leap 42.1:libXrandr2-1.5.0-3.1</ProductID>
        <ProductID>openSUSE Leap 42.1:libXrandr2-32bit-1.5.0-3.1</ProductID>
        <ProductID>openSUSE Leap 42.1:libXrender-0.9.9-3.1</ProductID>
        <ProductID>openSUSE Leap 42.1:libXrender-devel-0.9.9-3.1</ProductID>
        <ProductID>openSUSE Leap 42.1:libXrender-devel-32bit-0.9.9-3.1</ProductID>
        <ProductID>openSUSE Leap 42.1:libXrender1-0.9.9-3.1</ProductID>
        <ProductID>openSUSE Leap 42.1:libXrender1-32bit-0.9.9-3.1</ProductID>
        <ProductID>openSUSE Leap 42.1:libXtst-1.2.2-7.1</ProductID>
        <ProductID>openSUSE Leap 42.1:libXtst-devel-1.2.2-7.1</ProductID>
        <ProductID>openSUSE Leap 42.1:libXtst-devel-32bit-1.2.2-7.1</ProductID>
        <ProductID>openSUSE Leap 42.1:libXtst6-1.2.2-7.1</ProductID>
        <ProductID>openSUSE Leap 42.1:libXtst6-32bit-1.2.2-7.1</ProductID>
        <ProductID>openSUSE Leap 42.1:libXv-1.0.10-7.1</ProductID>
        <ProductID>openSUSE Leap 42.1:libXv-devel-1.0.10-7.1</ProductID>
        <ProductID>openSUSE Leap 42.1:libXv-devel-32bit-1.0.10-7.1</ProductID>
        <ProductID>openSUSE Leap 42.1:libXv1-1.0.10-7.1</ProductID>
        <ProductID>openSUSE Leap 42.1:libXv1-32bit-1.0.10-7.1</ProductID>
        <ProductID>openSUSE Leap 42.1:libXvMC-1.0.9-3.1</ProductID>
        <ProductID>openSUSE Leap 42.1:libXvMC-devel-1.0.9-3.1</ProductID>
        <ProductID>openSUSE Leap 42.1:libXvMC-devel-32bit-1.0.9-3.1</ProductID>
        <ProductID>openSUSE Leap 42.1:libXvMC1-1.0.9-3.1</ProductID>
        <ProductID>openSUSE Leap 42.1:libXvMC1-32bit-1.0.9-3.1</ProductID>
      </Status>
    </ProductStatuses>
    <Threats>
      <Threat Type="Impact">
        <Description>moderate</Description>
      </Threat>
    </Threats>
    <CVSSScoreSets>
      <ScoreSet>
        <BaseScore>5.1</BaseScore>
        <Vector>AV:N/AC:H/Au:N/C:P/I:P/A:P</Vector>
      </ScoreSet>
    </CVSSScoreSets>
    <Remediations>
      <Remediation Type="Vendor Fix">
        <Description xml:lang="en">Please Install the update.</Description>
        <URL>https://lists.opensuse.org/opensuse-updates/2016-10/msg00078.html</URL>
      </Remediation>
    </Remediations>
    <References>
      <Reference>
        <URL>https://www.suse.com/security/cve/CVE-2016-7947.html</URL>
        <Description>CVE-2016-7947</Description>
      </Reference>
      <Reference>
        <URL>https://bugzilla.suse.com/1003000</URL>
        <Description>SUSE Bug 1003000</Description>
      </Reference>
      <Reference>
        <URL>https://bugzilla.suse.com/1159415</URL>
        <Description>SUSE Bug 1159415</Description>
      </Reference>
    </References>
  </Vulnerability>
  <Vulnerability xmlns="http://www.icasi.org/CVRF/schema/vuln/1.1" Ordinal="7">
    <Notes>
      <Note Title="Vulnerability Description" Type="General" Ordinal="1" xml:lang="en">X.org libXrandr before 1.5.1 allows remote X servers to trigger out-of-bounds write operations by leveraging mishandling of reply data.</Note>
    </Notes>
    <CVE>CVE-2016-7948</CVE>
    <ProductStatuses>
      <Status Type="Fixed">
        <ProductID>openSUSE Leap 42.1:libX11-1.6.3-6.1</ProductID>
        <ProductID>openSUSE Leap 42.1:libX11-6-1.6.3-6.1</ProductID>
        <ProductID>openSUSE Leap 42.1:libX11-6-32bit-1.6.3-6.1</ProductID>
        <ProductID>openSUSE Leap 42.1:libX11-data-1.6.3-6.1</ProductID>
        <ProductID>openSUSE Leap 42.1:libX11-devel-1.6.3-6.1</ProductID>
        <ProductID>openSUSE Leap 42.1:libX11-devel-32bit-1.6.3-6.1</ProductID>
        <ProductID>openSUSE Leap 42.1:libX11-xcb1-1.6.3-6.1</ProductID>
        <ProductID>openSUSE Leap 42.1:libX11-xcb1-32bit-1.6.3-6.1</ProductID>
        <ProductID>openSUSE Leap 42.1:libXfixes-5.0.1-7.1</ProductID>
        <ProductID>openSUSE Leap 42.1:libXfixes-devel-32bit-5.0.1-7.1</ProductID>
        <ProductID>openSUSE Leap 42.1:libXfixes-devel-5.0.1-7.1</ProductID>
        <ProductID>openSUSE Leap 42.1:libXfixes3-32bit-5.0.1-7.1</ProductID>
        <ProductID>openSUSE Leap 42.1:libXfixes3-5.0.1-7.1</ProductID>
        <ProductID>openSUSE Leap 42.1:libXi-1.7.5-3.1</ProductID>
        <ProductID>openSUSE Leap 42.1:libXi-devel-1.7.5-3.1</ProductID>
        <ProductID>openSUSE Leap 42.1:libXi-devel-32bit-1.7.5-3.1</ProductID>
        <ProductID>openSUSE Leap 42.1:libXi6-1.7.5-3.1</ProductID>
        <ProductID>openSUSE Leap 42.1:libXi6-32bit-1.7.5-3.1</ProductID>
        <ProductID>openSUSE Leap 42.1:libXrandr-1.5.0-3.1</ProductID>
        <ProductID>openSUSE Leap 42.1:libXrandr-devel-1.5.0-3.1</ProductID>
        <ProductID>openSUSE Leap 42.1:libXrandr-devel-32bit-1.5.0-3.1</ProductID>
        <ProductID>openSUSE Leap 42.1:libXrandr2-1.5.0-3.1</ProductID>
        <ProductID>openSUSE Leap 42.1:libXrandr2-32bit-1.5.0-3.1</ProductID>
        <ProductID>openSUSE Leap 42.1:libXrender-0.9.9-3.1</ProductID>
        <ProductID>openSUSE Leap 42.1:libXrender-devel-0.9.9-3.1</ProductID>
        <ProductID>openSUSE Leap 42.1:libXrender-devel-32bit-0.9.9-3.1</ProductID>
        <ProductID>openSUSE Leap 42.1:libXrender1-0.9.9-3.1</ProductID>
        <ProductID>openSUSE Leap 42.1:libXrender1-32bit-0.9.9-3.1</ProductID>
        <ProductID>openSUSE Leap 42.1:libXtst-1.2.2-7.1</ProductID>
        <ProductID>openSUSE Leap 42.1:libXtst-devel-1.2.2-7.1</ProductID>
        <ProductID>openSUSE Leap 42.1:libXtst-devel-32bit-1.2.2-7.1</ProductID>
        <ProductID>openSUSE Leap 42.1:libXtst6-1.2.2-7.1</ProductID>
        <ProductID>openSUSE Leap 42.1:libXtst6-32bit-1.2.2-7.1</ProductID>
        <ProductID>openSUSE Leap 42.1:libXv-1.0.10-7.1</ProductID>
        <ProductID>openSUSE Leap 42.1:libXv-devel-1.0.10-7.1</ProductID>
        <ProductID>openSUSE Leap 42.1:libXv-devel-32bit-1.0.10-7.1</ProductID>
        <ProductID>openSUSE Leap 42.1:libXv1-1.0.10-7.1</ProductID>
        <ProductID>openSUSE Leap 42.1:libXv1-32bit-1.0.10-7.1</ProductID>
        <ProductID>openSUSE Leap 42.1:libXvMC-1.0.9-3.1</ProductID>
        <ProductID>openSUSE Leap 42.1:libXvMC-devel-1.0.9-3.1</ProductID>
        <ProductID>openSUSE Leap 42.1:libXvMC-devel-32bit-1.0.9-3.1</ProductID>
        <ProductID>openSUSE Leap 42.1:libXvMC1-1.0.9-3.1</ProductID>
        <ProductID>openSUSE Leap 42.1:libXvMC1-32bit-1.0.9-3.1</ProductID>
      </Status>
    </ProductStatuses>
    <Threats>
      <Threat Type="Impact">
        <Description>moderate</Description>
      </Threat>
    </Threats>
    <CVSSScoreSets>
      <ScoreSet>
        <BaseScore>5.1</BaseScore>
        <Vector>AV:N/AC:H/Au:N/C:P/I:P/A:P</Vector>
      </ScoreSet>
    </CVSSScoreSets>
    <Remediations>
      <Remediation Type="Vendor Fix">
        <Description xml:lang="en">Please Install the update.</Description>
        <URL>https://lists.opensuse.org/opensuse-updates/2016-10/msg00078.html</URL>
      </Remediation>
    </Remediations>
    <References>
      <Reference>
        <URL>https://www.suse.com/security/cve/CVE-2016-7948.html</URL>
        <Description>CVE-2016-7948</Description>
      </Reference>
      <Reference>
        <URL>https://bugzilla.suse.com/1003000</URL>
        <Description>SUSE Bug 1003000</Description>
      </Reference>
      <Reference>
        <URL>https://bugzilla.suse.com/1159415</URL>
        <Description>SUSE Bug 1159415</Description>
      </Reference>
    </References>
  </Vulnerability>
  <Vulnerability xmlns="http://www.icasi.org/CVRF/schema/vuln/1.1" Ordinal="8">
    <Notes>
      <Note Title="Vulnerability Description" Type="General" Ordinal="1" xml:lang="en">Multiple buffer overflows in the (1) XvQueryAdaptors and (2) XvQueryEncodings functions in X.org libXrender before 0.9.10 allow remote X servers to trigger out-of-bounds write operations via vectors involving length fields.</Note>
    </Notes>
    <CVE>CVE-2016-7949</CVE>
    <ProductStatuses>
      <Status Type="Fixed">
        <ProductID>openSUSE Leap 42.1:libX11-1.6.3-6.1</ProductID>
        <ProductID>openSUSE Leap 42.1:libX11-6-1.6.3-6.1</ProductID>
        <ProductID>openSUSE Leap 42.1:libX11-6-32bit-1.6.3-6.1</ProductID>
        <ProductID>openSUSE Leap 42.1:libX11-data-1.6.3-6.1</ProductID>
        <ProductID>openSUSE Leap 42.1:libX11-devel-1.6.3-6.1</ProductID>
        <ProductID>openSUSE Leap 42.1:libX11-devel-32bit-1.6.3-6.1</ProductID>
        <ProductID>openSUSE Leap 42.1:libX11-xcb1-1.6.3-6.1</ProductID>
        <ProductID>openSUSE Leap 42.1:libX11-xcb1-32bit-1.6.3-6.1</ProductID>
        <ProductID>openSUSE Leap 42.1:libXfixes-5.0.1-7.1</ProductID>
        <ProductID>openSUSE Leap 42.1:libXfixes-devel-32bit-5.0.1-7.1</ProductID>
        <ProductID>openSUSE Leap 42.1:libXfixes-devel-5.0.1-7.1</ProductID>
        <ProductID>openSUSE Leap 42.1:libXfixes3-32bit-5.0.1-7.1</ProductID>
        <ProductID>openSUSE Leap 42.1:libXfixes3-5.0.1-7.1</ProductID>
        <ProductID>openSUSE Leap 42.1:libXi-1.7.5-3.1</ProductID>
        <ProductID>openSUSE Leap 42.1:libXi-devel-1.7.5-3.1</ProductID>
        <ProductID>openSUSE Leap 42.1:libXi-devel-32bit-1.7.5-3.1</ProductID>
        <ProductID>openSUSE Leap 42.1:libXi6-1.7.5-3.1</ProductID>
        <ProductID>openSUSE Leap 42.1:libXi6-32bit-1.7.5-3.1</ProductID>
        <ProductID>openSUSE Leap 42.1:libXrandr-1.5.0-3.1</ProductID>
        <ProductID>openSUSE Leap 42.1:libXrandr-devel-1.5.0-3.1</ProductID>
        <ProductID>openSUSE Leap 42.1:libXrandr-devel-32bit-1.5.0-3.1</ProductID>
        <ProductID>openSUSE Leap 42.1:libXrandr2-1.5.0-3.1</ProductID>
        <ProductID>openSUSE Leap 42.1:libXrandr2-32bit-1.5.0-3.1</ProductID>
        <ProductID>openSUSE Leap 42.1:libXrender-0.9.9-3.1</ProductID>
        <ProductID>openSUSE Leap 42.1:libXrender-devel-0.9.9-3.1</ProductID>
        <ProductID>openSUSE Leap 42.1:libXrender-devel-32bit-0.9.9-3.1</ProductID>
        <ProductID>openSUSE Leap 42.1:libXrender1-0.9.9-3.1</ProductID>
        <ProductID>openSUSE Leap 42.1:libXrender1-32bit-0.9.9-3.1</ProductID>
        <ProductID>openSUSE Leap 42.1:libXtst-1.2.2-7.1</ProductID>
        <ProductID>openSUSE Leap 42.1:libXtst-devel-1.2.2-7.1</ProductID>
        <ProductID>openSUSE Leap 42.1:libXtst-devel-32bit-1.2.2-7.1</ProductID>
        <ProductID>openSUSE Leap 42.1:libXtst6-1.2.2-7.1</ProductID>
        <ProductID>openSUSE Leap 42.1:libXtst6-32bit-1.2.2-7.1</ProductID>
        <ProductID>openSUSE Leap 42.1:libXv-1.0.10-7.1</ProductID>
        <ProductID>openSUSE Leap 42.1:libXv-devel-1.0.10-7.1</ProductID>
        <ProductID>openSUSE Leap 42.1:libXv-devel-32bit-1.0.10-7.1</ProductID>
        <ProductID>openSUSE Leap 42.1:libXv1-1.0.10-7.1</ProductID>
        <ProductID>openSUSE Leap 42.1:libXv1-32bit-1.0.10-7.1</ProductID>
        <ProductID>openSUSE Leap 42.1:libXvMC-1.0.9-3.1</ProductID>
        <ProductID>openSUSE Leap 42.1:libXvMC-devel-1.0.9-3.1</ProductID>
        <ProductID>openSUSE Leap 42.1:libXvMC-devel-32bit-1.0.9-3.1</ProductID>
        <ProductID>openSUSE Leap 42.1:libXvMC1-1.0.9-3.1</ProductID>
        <ProductID>openSUSE Leap 42.1:libXvMC1-32bit-1.0.9-3.1</ProductID>
      </Status>
    </ProductStatuses>
    <Threats>
      <Threat Type="Impact">
        <Description>moderate</Description>
      </Threat>
    </Threats>
    <CVSSScoreSets>
      <ScoreSet>
        <BaseScore>5.1</BaseScore>
        <Vector>AV:N/AC:H/Au:N/C:P/I:P/A:P</Vector>
      </ScoreSet>
    </CVSSScoreSets>
    <Remediations>
      <Remediation Type="Vendor Fix">
        <Description xml:lang="en">Please Install the update.</Description>
        <URL>https://lists.opensuse.org/opensuse-updates/2016-10/msg00078.html</URL>
      </Remediation>
    </Remediations>
    <References>
      <Reference>
        <URL>https://www.suse.com/security/cve/CVE-2016-7949.html</URL>
        <Description>CVE-2016-7949</Description>
      </Reference>
      <Reference>
        <URL>https://bugzilla.suse.com/1003002</URL>
        <Description>SUSE Bug 1003002</Description>
      </Reference>
      <Reference>
        <URL>https://bugzilla.suse.com/1015442</URL>
        <Description>SUSE Bug 1015442</Description>
      </Reference>
      <Reference>
        <URL>https://bugzilla.suse.com/1123146</URL>
        <Description>SUSE Bug 1123146</Description>
      </Reference>
    </References>
  </Vulnerability>
  <Vulnerability xmlns="http://www.icasi.org/CVRF/schema/vuln/1.1" Ordinal="9">
    <Notes>
      <Note Title="Vulnerability Description" Type="General" Ordinal="1" xml:lang="en">The XRenderQueryFilters function in X.org libXrender before 0.9.10 allows remote X servers to trigger out-of-bounds write operations via vectors involving filter name lengths.</Note>
    </Notes>
    <CVE>CVE-2016-7950</CVE>
    <ProductStatuses>
      <Status Type="Fixed">
        <ProductID>openSUSE Leap 42.1:libX11-1.6.3-6.1</ProductID>
        <ProductID>openSUSE Leap 42.1:libX11-6-1.6.3-6.1</ProductID>
        <ProductID>openSUSE Leap 42.1:libX11-6-32bit-1.6.3-6.1</ProductID>
        <ProductID>openSUSE Leap 42.1:libX11-data-1.6.3-6.1</ProductID>
        <ProductID>openSUSE Leap 42.1:libX11-devel-1.6.3-6.1</ProductID>
        <ProductID>openSUSE Leap 42.1:libX11-devel-32bit-1.6.3-6.1</ProductID>
        <ProductID>openSUSE Leap 42.1:libX11-xcb1-1.6.3-6.1</ProductID>
        <ProductID>openSUSE Leap 42.1:libX11-xcb1-32bit-1.6.3-6.1</ProductID>
        <ProductID>openSUSE Leap 42.1:libXfixes-5.0.1-7.1</ProductID>
        <ProductID>openSUSE Leap 42.1:libXfixes-devel-32bit-5.0.1-7.1</ProductID>
        <ProductID>openSUSE Leap 42.1:libXfixes-devel-5.0.1-7.1</ProductID>
        <ProductID>openSUSE Leap 42.1:libXfixes3-32bit-5.0.1-7.1</ProductID>
        <ProductID>openSUSE Leap 42.1:libXfixes3-5.0.1-7.1</ProductID>
        <ProductID>openSUSE Leap 42.1:libXi-1.7.5-3.1</ProductID>
        <ProductID>openSUSE Leap 42.1:libXi-devel-1.7.5-3.1</ProductID>
        <ProductID>openSUSE Leap 42.1:libXi-devel-32bit-1.7.5-3.1</ProductID>
        <ProductID>openSUSE Leap 42.1:libXi6-1.7.5-3.1</ProductID>
        <ProductID>openSUSE Leap 42.1:libXi6-32bit-1.7.5-3.1</ProductID>
        <ProductID>openSUSE Leap 42.1:libXrandr-1.5.0-3.1</ProductID>
        <ProductID>openSUSE Leap 42.1:libXrandr-devel-1.5.0-3.1</ProductID>
        <ProductID>openSUSE Leap 42.1:libXrandr-devel-32bit-1.5.0-3.1</ProductID>
        <ProductID>openSUSE Leap 42.1:libXrandr2-1.5.0-3.1</ProductID>
        <ProductID>openSUSE Leap 42.1:libXrandr2-32bit-1.5.0-3.1</ProductID>
        <ProductID>openSUSE Leap 42.1:libXrender-0.9.9-3.1</ProductID>
        <ProductID>openSUSE Leap 42.1:libXrender-devel-0.9.9-3.1</ProductID>
        <ProductID>openSUSE Leap 42.1:libXrender-devel-32bit-0.9.9-3.1</ProductID>
        <ProductID>openSUSE Leap 42.1:libXrender1-0.9.9-3.1</ProductID>
        <ProductID>openSUSE Leap 42.1:libXrender1-32bit-0.9.9-3.1</ProductID>
        <ProductID>openSUSE Leap 42.1:libXtst-1.2.2-7.1</ProductID>
        <ProductID>openSUSE Leap 42.1:libXtst-devel-1.2.2-7.1</ProductID>
        <ProductID>openSUSE Leap 42.1:libXtst-devel-32bit-1.2.2-7.1</ProductID>
        <ProductID>openSUSE Leap 42.1:libXtst6-1.2.2-7.1</ProductID>
        <ProductID>openSUSE Leap 42.1:libXtst6-32bit-1.2.2-7.1</ProductID>
        <ProductID>openSUSE Leap 42.1:libXv-1.0.10-7.1</ProductID>
        <ProductID>openSUSE Leap 42.1:libXv-devel-1.0.10-7.1</ProductID>
        <ProductID>openSUSE Leap 42.1:libXv-devel-32bit-1.0.10-7.1</ProductID>
        <ProductID>openSUSE Leap 42.1:libXv1-1.0.10-7.1</ProductID>
        <ProductID>openSUSE Leap 42.1:libXv1-32bit-1.0.10-7.1</ProductID>
        <ProductID>openSUSE Leap 42.1:libXvMC-1.0.9-3.1</ProductID>
        <ProductID>openSUSE Leap 42.1:libXvMC-devel-1.0.9-3.1</ProductID>
        <ProductID>openSUSE Leap 42.1:libXvMC-devel-32bit-1.0.9-3.1</ProductID>
        <ProductID>openSUSE Leap 42.1:libXvMC1-1.0.9-3.1</ProductID>
        <ProductID>openSUSE Leap 42.1:libXvMC1-32bit-1.0.9-3.1</ProductID>
      </Status>
    </ProductStatuses>
    <Threats>
      <Threat Type="Impact">
        <Description>moderate</Description>
      </Threat>
    </Threats>
    <CVSSScoreSets>
      <ScoreSet>
        <BaseScore>5.1</BaseScore>
        <Vector>AV:N/AC:H/Au:N/C:P/I:P/A:P</Vector>
      </ScoreSet>
    </CVSSScoreSets>
    <Remediations>
      <Remediation Type="Vendor Fix">
        <Description xml:lang="en">Please Install the update.</Description>
        <URL>https://lists.opensuse.org/opensuse-updates/2016-10/msg00078.html</URL>
      </Remediation>
    </Remediations>
    <References>
      <Reference>
        <URL>https://www.suse.com/security/cve/CVE-2016-7950.html</URL>
        <Description>CVE-2016-7950</Description>
      </Reference>
      <Reference>
        <URL>https://bugzilla.suse.com/1003002</URL>
        <Description>SUSE Bug 1003002</Description>
      </Reference>
      <Reference>
        <URL>https://bugzilla.suse.com/1015442</URL>
        <Description>SUSE Bug 1015442</Description>
      </Reference>
      <Reference>
        <URL>https://bugzilla.suse.com/1123146</URL>
        <Description>SUSE Bug 1123146</Description>
      </Reference>
    </References>
  </Vulnerability>
  <Vulnerability xmlns="http://www.icasi.org/CVRF/schema/vuln/1.1" Ordinal="10">
    <Notes>
      <Note Title="Vulnerability Description" Type="General" Ordinal="1" xml:lang="en">Multiple integer overflows in X.org libXtst before 1.2.3 allow remote X servers to trigger out-of-bounds memory access operations by leveraging the lack of range checks.</Note>
    </Notes>
    <CVE>CVE-2016-7951</CVE>
    <ProductStatuses>
      <Status Type="Fixed">
        <ProductID>openSUSE Leap 42.1:libX11-1.6.3-6.1</ProductID>
        <ProductID>openSUSE Leap 42.1:libX11-6-1.6.3-6.1</ProductID>
        <ProductID>openSUSE Leap 42.1:libX11-6-32bit-1.6.3-6.1</ProductID>
        <ProductID>openSUSE Leap 42.1:libX11-data-1.6.3-6.1</ProductID>
        <ProductID>openSUSE Leap 42.1:libX11-devel-1.6.3-6.1</ProductID>
        <ProductID>openSUSE Leap 42.1:libX11-devel-32bit-1.6.3-6.1</ProductID>
        <ProductID>openSUSE Leap 42.1:libX11-xcb1-1.6.3-6.1</ProductID>
        <ProductID>openSUSE Leap 42.1:libX11-xcb1-32bit-1.6.3-6.1</ProductID>
        <ProductID>openSUSE Leap 42.1:libXfixes-5.0.1-7.1</ProductID>
        <ProductID>openSUSE Leap 42.1:libXfixes-devel-32bit-5.0.1-7.1</ProductID>
        <ProductID>openSUSE Leap 42.1:libXfixes-devel-5.0.1-7.1</ProductID>
        <ProductID>openSUSE Leap 42.1:libXfixes3-32bit-5.0.1-7.1</ProductID>
        <ProductID>openSUSE Leap 42.1:libXfixes3-5.0.1-7.1</ProductID>
        <ProductID>openSUSE Leap 42.1:libXi-1.7.5-3.1</ProductID>
        <ProductID>openSUSE Leap 42.1:libXi-devel-1.7.5-3.1</ProductID>
        <ProductID>openSUSE Leap 42.1:libXi-devel-32bit-1.7.5-3.1</ProductID>
        <ProductID>openSUSE Leap 42.1:libXi6-1.7.5-3.1</ProductID>
        <ProductID>openSUSE Leap 42.1:libXi6-32bit-1.7.5-3.1</ProductID>
        <ProductID>openSUSE Leap 42.1:libXrandr-1.5.0-3.1</ProductID>
        <ProductID>openSUSE Leap 42.1:libXrandr-devel-1.5.0-3.1</ProductID>
        <ProductID>openSUSE Leap 42.1:libXrandr-devel-32bit-1.5.0-3.1</ProductID>
        <ProductID>openSUSE Leap 42.1:libXrandr2-1.5.0-3.1</ProductID>
        <ProductID>openSUSE Leap 42.1:libXrandr2-32bit-1.5.0-3.1</ProductID>
        <ProductID>openSUSE Leap 42.1:libXrender-0.9.9-3.1</ProductID>
        <ProductID>openSUSE Leap 42.1:libXrender-devel-0.9.9-3.1</ProductID>
        <ProductID>openSUSE Leap 42.1:libXrender-devel-32bit-0.9.9-3.1</ProductID>
        <ProductID>openSUSE Leap 42.1:libXrender1-0.9.9-3.1</ProductID>
        <ProductID>openSUSE Leap 42.1:libXrender1-32bit-0.9.9-3.1</ProductID>
        <ProductID>openSUSE Leap 42.1:libXtst-1.2.2-7.1</ProductID>
        <ProductID>openSUSE Leap 42.1:libXtst-devel-1.2.2-7.1</ProductID>
        <ProductID>openSUSE Leap 42.1:libXtst-devel-32bit-1.2.2-7.1</ProductID>
        <ProductID>openSUSE Leap 42.1:libXtst6-1.2.2-7.1</ProductID>
        <ProductID>openSUSE Leap 42.1:libXtst6-32bit-1.2.2-7.1</ProductID>
        <ProductID>openSUSE Leap 42.1:libXv-1.0.10-7.1</ProductID>
        <ProductID>openSUSE Leap 42.1:libXv-devel-1.0.10-7.1</ProductID>
        <ProductID>openSUSE Leap 42.1:libXv-devel-32bit-1.0.10-7.1</ProductID>
        <ProductID>openSUSE Leap 42.1:libXv1-1.0.10-7.1</ProductID>
        <ProductID>openSUSE Leap 42.1:libXv1-32bit-1.0.10-7.1</ProductID>
        <ProductID>openSUSE Leap 42.1:libXvMC-1.0.9-3.1</ProductID>
        <ProductID>openSUSE Leap 42.1:libXvMC-devel-1.0.9-3.1</ProductID>
        <ProductID>openSUSE Leap 42.1:libXvMC-devel-32bit-1.0.9-3.1</ProductID>
        <ProductID>openSUSE Leap 42.1:libXvMC1-1.0.9-3.1</ProductID>
        <ProductID>openSUSE Leap 42.1:libXvMC1-32bit-1.0.9-3.1</ProductID>
      </Status>
    </ProductStatuses>
    <Threats>
      <Threat Type="Impact">
        <Description>moderate</Description>
      </Threat>
    </Threats>
    <CVSSScoreSets>
      <ScoreSet>
        <BaseScore>5.1</BaseScore>
        <Vector>AV:N/AC:H/Au:N/C:P/I:P/A:P</Vector>
      </ScoreSet>
    </CVSSScoreSets>
    <Remediations>
      <Remediation Type="Vendor Fix">
        <Description xml:lang="en">Please Install the update.</Description>
        <URL>https://lists.opensuse.org/opensuse-updates/2016-10/msg00078.html</URL>
      </Remediation>
    </Remediations>
    <References>
      <Reference>
        <URL>https://www.suse.com/security/cve/CVE-2016-7951.html</URL>
        <Description>CVE-2016-7951</Description>
      </Reference>
      <Reference>
        <URL>https://bugzilla.suse.com/1003012</URL>
        <Description>SUSE Bug 1003012</Description>
      </Reference>
      <Reference>
        <URL>https://bugzilla.suse.com/1159415</URL>
        <Description>SUSE Bug 1159415</Description>
      </Reference>
    </References>
  </Vulnerability>
  <Vulnerability xmlns="http://www.icasi.org/CVRF/schema/vuln/1.1" Ordinal="11">
    <Notes>
      <Note Title="Vulnerability Description" Type="General" Ordinal="1" xml:lang="en">X.org libXtst before 1.2.3 allows remote X servers to cause a denial of service (infinite loop) via a reply in the (1) XRecordStartOfData, (2) XRecordEndOfData, or (3) XRecordClientDied category without a client sequence and with attached data.</Note>
    </Notes>
    <CVE>CVE-2016-7952</CVE>
    <ProductStatuses>
      <Status Type="Fixed">
        <ProductID>openSUSE Leap 42.1:libX11-1.6.3-6.1</ProductID>
        <ProductID>openSUSE Leap 42.1:libX11-6-1.6.3-6.1</ProductID>
        <ProductID>openSUSE Leap 42.1:libX11-6-32bit-1.6.3-6.1</ProductID>
        <ProductID>openSUSE Leap 42.1:libX11-data-1.6.3-6.1</ProductID>
        <ProductID>openSUSE Leap 42.1:libX11-devel-1.6.3-6.1</ProductID>
        <ProductID>openSUSE Leap 42.1:libX11-devel-32bit-1.6.3-6.1</ProductID>
        <ProductID>openSUSE Leap 42.1:libX11-xcb1-1.6.3-6.1</ProductID>
        <ProductID>openSUSE Leap 42.1:libX11-xcb1-32bit-1.6.3-6.1</ProductID>
        <ProductID>openSUSE Leap 42.1:libXfixes-5.0.1-7.1</ProductID>
        <ProductID>openSUSE Leap 42.1:libXfixes-devel-32bit-5.0.1-7.1</ProductID>
        <ProductID>openSUSE Leap 42.1:libXfixes-devel-5.0.1-7.1</ProductID>
        <ProductID>openSUSE Leap 42.1:libXfixes3-32bit-5.0.1-7.1</ProductID>
        <ProductID>openSUSE Leap 42.1:libXfixes3-5.0.1-7.1</ProductID>
        <ProductID>openSUSE Leap 42.1:libXi-1.7.5-3.1</ProductID>
        <ProductID>openSUSE Leap 42.1:libXi-devel-1.7.5-3.1</ProductID>
        <ProductID>openSUSE Leap 42.1:libXi-devel-32bit-1.7.5-3.1</ProductID>
        <ProductID>openSUSE Leap 42.1:libXi6-1.7.5-3.1</ProductID>
        <ProductID>openSUSE Leap 42.1:libXi6-32bit-1.7.5-3.1</ProductID>
        <ProductID>openSUSE Leap 42.1:libXrandr-1.5.0-3.1</ProductID>
        <ProductID>openSUSE Leap 42.1:libXrandr-devel-1.5.0-3.1</ProductID>
        <ProductID>openSUSE Leap 42.1:libXrandr-devel-32bit-1.5.0-3.1</ProductID>
        <ProductID>openSUSE Leap 42.1:libXrandr2-1.5.0-3.1</ProductID>
        <ProductID>openSUSE Leap 42.1:libXrandr2-32bit-1.5.0-3.1</ProductID>
        <ProductID>openSUSE Leap 42.1:libXrender-0.9.9-3.1</ProductID>
        <ProductID>openSUSE Leap 42.1:libXrender-devel-0.9.9-3.1</ProductID>
        <ProductID>openSUSE Leap 42.1:libXrender-devel-32bit-0.9.9-3.1</ProductID>
        <ProductID>openSUSE Leap 42.1:libXrender1-0.9.9-3.1</ProductID>
        <ProductID>openSUSE Leap 42.1:libXrender1-32bit-0.9.9-3.1</ProductID>
        <ProductID>openSUSE Leap 42.1:libXtst-1.2.2-7.1</ProductID>
        <ProductID>openSUSE Leap 42.1:libXtst-devel-1.2.2-7.1</ProductID>
        <ProductID>openSUSE Leap 42.1:libXtst-devel-32bit-1.2.2-7.1</ProductID>
        <ProductID>openSUSE Leap 42.1:libXtst6-1.2.2-7.1</ProductID>
        <ProductID>openSUSE Leap 42.1:libXtst6-32bit-1.2.2-7.1</ProductID>
        <ProductID>openSUSE Leap 42.1:libXv-1.0.10-7.1</ProductID>
        <ProductID>openSUSE Leap 42.1:libXv-devel-1.0.10-7.1</ProductID>
        <ProductID>openSUSE Leap 42.1:libXv-devel-32bit-1.0.10-7.1</ProductID>
        <ProductID>openSUSE Leap 42.1:libXv1-1.0.10-7.1</ProductID>
        <ProductID>openSUSE Leap 42.1:libXv1-32bit-1.0.10-7.1</ProductID>
        <ProductID>openSUSE Leap 42.1:libXvMC-1.0.9-3.1</ProductID>
        <ProductID>openSUSE Leap 42.1:libXvMC-devel-1.0.9-3.1</ProductID>
        <ProductID>openSUSE Leap 42.1:libXvMC-devel-32bit-1.0.9-3.1</ProductID>
        <ProductID>openSUSE Leap 42.1:libXvMC1-1.0.9-3.1</ProductID>
        <ProductID>openSUSE Leap 42.1:libXvMC1-32bit-1.0.9-3.1</ProductID>
      </Status>
    </ProductStatuses>
    <Threats>
      <Threat Type="Impact">
        <Description>moderate</Description>
      </Threat>
    </Threats>
    <CVSSScoreSets>
      <ScoreSet>
        <BaseScore>5.1</BaseScore>
        <Vector>AV:N/AC:H/Au:N/C:P/I:P/A:P</Vector>
      </ScoreSet>
    </CVSSScoreSets>
    <Remediations>
      <Remediation Type="Vendor Fix">
        <Description xml:lang="en">Please Install the update.</Description>
        <URL>https://lists.opensuse.org/opensuse-updates/2016-10/msg00078.html</URL>
      </Remediation>
    </Remediations>
    <References>
      <Reference>
        <URL>https://www.suse.com/security/cve/CVE-2016-7952.html</URL>
        <Description>CVE-2016-7952</Description>
      </Reference>
      <Reference>
        <URL>https://bugzilla.suse.com/1003012</URL>
        <Description>SUSE Bug 1003012</Description>
      </Reference>
      <Reference>
        <URL>https://bugzilla.suse.com/1159415</URL>
        <Description>SUSE Bug 1159415</Description>
      </Reference>
    </References>
  </Vulnerability>
  <Vulnerability xmlns="http://www.icasi.org/CVRF/schema/vuln/1.1" Ordinal="12">
    <Notes>
      <Note Title="Vulnerability Description" Type="General" Ordinal="1" xml:lang="en">Buffer underflow in X.org libXvMC before 1.0.10 allows remote X servers to have unspecified impact via an empty string.</Note>
    </Notes>
    <CVE>CVE-2016-7953</CVE>
    <ProductStatuses>
      <Status Type="Fixed">
        <ProductID>openSUSE Leap 42.1:libX11-1.6.3-6.1</ProductID>
        <ProductID>openSUSE Leap 42.1:libX11-6-1.6.3-6.1</ProductID>
        <ProductID>openSUSE Leap 42.1:libX11-6-32bit-1.6.3-6.1</ProductID>
        <ProductID>openSUSE Leap 42.1:libX11-data-1.6.3-6.1</ProductID>
        <ProductID>openSUSE Leap 42.1:libX11-devel-1.6.3-6.1</ProductID>
        <ProductID>openSUSE Leap 42.1:libX11-devel-32bit-1.6.3-6.1</ProductID>
        <ProductID>openSUSE Leap 42.1:libX11-xcb1-1.6.3-6.1</ProductID>
        <ProductID>openSUSE Leap 42.1:libX11-xcb1-32bit-1.6.3-6.1</ProductID>
        <ProductID>openSUSE Leap 42.1:libXfixes-5.0.1-7.1</ProductID>
        <ProductID>openSUSE Leap 42.1:libXfixes-devel-32bit-5.0.1-7.1</ProductID>
        <ProductID>openSUSE Leap 42.1:libXfixes-devel-5.0.1-7.1</ProductID>
        <ProductID>openSUSE Leap 42.1:libXfixes3-32bit-5.0.1-7.1</ProductID>
        <ProductID>openSUSE Leap 42.1:libXfixes3-5.0.1-7.1</ProductID>
        <ProductID>openSUSE Leap 42.1:libXi-1.7.5-3.1</ProductID>
        <ProductID>openSUSE Leap 42.1:libXi-devel-1.7.5-3.1</ProductID>
        <ProductID>openSUSE Leap 42.1:libXi-devel-32bit-1.7.5-3.1</ProductID>
        <ProductID>openSUSE Leap 42.1:libXi6-1.7.5-3.1</ProductID>
        <ProductID>openSUSE Leap 42.1:libXi6-32bit-1.7.5-3.1</ProductID>
        <ProductID>openSUSE Leap 42.1:libXrandr-1.5.0-3.1</ProductID>
        <ProductID>openSUSE Leap 42.1:libXrandr-devel-1.5.0-3.1</ProductID>
        <ProductID>openSUSE Leap 42.1:libXrandr-devel-32bit-1.5.0-3.1</ProductID>
        <ProductID>openSUSE Leap 42.1:libXrandr2-1.5.0-3.1</ProductID>
        <ProductID>openSUSE Leap 42.1:libXrandr2-32bit-1.5.0-3.1</ProductID>
        <ProductID>openSUSE Leap 42.1:libXrender-0.9.9-3.1</ProductID>
        <ProductID>openSUSE Leap 42.1:libXrender-devel-0.9.9-3.1</ProductID>
        <ProductID>openSUSE Leap 42.1:libXrender-devel-32bit-0.9.9-3.1</ProductID>
        <ProductID>openSUSE Leap 42.1:libXrender1-0.9.9-3.1</ProductID>
        <ProductID>openSUSE Leap 42.1:libXrender1-32bit-0.9.9-3.1</ProductID>
        <ProductID>openSUSE Leap 42.1:libXtst-1.2.2-7.1</ProductID>
        <ProductID>openSUSE Leap 42.1:libXtst-devel-1.2.2-7.1</ProductID>
        <ProductID>openSUSE Leap 42.1:libXtst-devel-32bit-1.2.2-7.1</ProductID>
        <ProductID>openSUSE Leap 42.1:libXtst6-1.2.2-7.1</ProductID>
        <ProductID>openSUSE Leap 42.1:libXtst6-32bit-1.2.2-7.1</ProductID>
        <ProductID>openSUSE Leap 42.1:libXv-1.0.10-7.1</ProductID>
        <ProductID>openSUSE Leap 42.1:libXv-devel-1.0.10-7.1</ProductID>
        <ProductID>openSUSE Leap 42.1:libXv-devel-32bit-1.0.10-7.1</ProductID>
        <ProductID>openSUSE Leap 42.1:libXv1-1.0.10-7.1</ProductID>
        <ProductID>openSUSE Leap 42.1:libXv1-32bit-1.0.10-7.1</ProductID>
        <ProductID>openSUSE Leap 42.1:libXvMC-1.0.9-3.1</ProductID>
        <ProductID>openSUSE Leap 42.1:libXvMC-devel-1.0.9-3.1</ProductID>
        <ProductID>openSUSE Leap 42.1:libXvMC-devel-32bit-1.0.9-3.1</ProductID>
        <ProductID>openSUSE Leap 42.1:libXvMC1-1.0.9-3.1</ProductID>
        <ProductID>openSUSE Leap 42.1:libXvMC1-32bit-1.0.9-3.1</ProductID>
      </Status>
    </ProductStatuses>
    <Threats>
      <Threat Type="Impact">
        <Description>moderate</Description>
      </Threat>
    </Threats>
    <CVSSScoreSets>
      <ScoreSet>
        <BaseScore>5.1</BaseScore>
        <Vector>AV:N/AC:H/Au:N/C:P/I:P/A:P</Vector>
      </ScoreSet>
    </CVSSScoreSets>
    <Remediations>
      <Remediation Type="Vendor Fix">
        <Description xml:lang="en">Please Install the update.</Description>
        <URL>https://lists.opensuse.org/opensuse-updates/2016-10/msg00078.html</URL>
      </Remediation>
    </Remediations>
    <References>
      <Reference>
        <URL>https://www.suse.com/security/cve/CVE-2016-7953.html</URL>
        <Description>CVE-2016-7953</Description>
      </Reference>
      <Reference>
        <URL>https://bugzilla.suse.com/1003023</URL>
        <Description>SUSE Bug 1003023</Description>
      </Reference>
      <Reference>
        <URL>https://bugzilla.suse.com/1159415</URL>
        <Description>SUSE Bug 1159415</Description>
      </Reference>
    </References>
  </Vulnerability>
</cvrfdoc>
