← Back

Libsdl

libsdl

47 CVEs • 5 products

Products (5)

Click to collapse
Toggle
Sdl Image
sdl_image
Sdl2 Image
sdl2_image
Libsdl
libsdl
Sdl Ttf
sdl_ttf

CVEs (47)

CVE
VENDORS
PRODUCTS
UPDATED
PUBLISHED
CVSS
1Libsdl
1Sdl Image
Jul 24, 2026
Apr 6, 2026
N/A· v4
6.1 MEDIUM· v3
N/A· v2
SDL_image is a library to load images of various formats as SDL surfaces. In do_layer_surface() in src/IMG_xcf.c, pixel index values from decoded XCF tile data are used directly as colormap indices without validating the...Show more
SDL_image is a library to load images of various formats as SDL surfaces. In do_layer_surface() in src/IMG_xcf.c, pixel index values from decoded XCF tile data are used directly as colormap indices without validating them against the colormap size (cm_num). A crafted .xcf file with a small colormap and out-of-range pixel indices causes heap out-of-bounds reads of up to 762 bytes past the colormap allocation. Both IMAGE_INDEXED code paths are affected (bpp=1 and bpp=2). The leaked heap bytes are written into the output surface pixel data, making them potentially observable in the rendered image. This vulnerability is fixed with commit 996bf12888925932daace576e09c3053410896f8.Show less
2Libsdl
Redhat
2Enterprise Linux
Simple Directmedia Layer
Jun 17, 2026
Jan 12, 2023
N/A· v4
7.5 HIGH· v3
N/A· v2
A potential memory leak issue was discovered in SDL2 in GLES_CreateTexture() function in SDL_render_gles.c. The vulnerability allows an attacker to cause a denial of service attack. The vulnerability affects SDL2 v2.0.4...Show more
A potential memory leak issue was discovered in SDL2 in GLES_CreateTexture() function in SDL_render_gles.c. The vulnerability allows an attacker to cause a denial of service attack. The vulnerability affects SDL2 v2.0.4 and above. SDL-1.x are not affected.Show less
1Libsdl
1Simple Directmedia Layer
Jun 17, 2026
Jul 28, 2022
N/A· v4
7.5 HIGH· v3
N/A· v2
SDL v1.2 was discovered to contain a use-after-free via the XFree function at /src/video/x11/SDL_x11yuv.c.
2Fedoraproject
Libsdl
2Fedora
Sdl Ttf
Jun 17, 2026
May 4, 2022
N/A· v4
7.8 HIGH· v3
6.8 MEDIUM· v2
SDL_ttf v2.0.18 and below was discovered to contain an arbitrary memory write via the function TTF_RenderText_Solid(). This vulnerability is triggered via a crafted TTF file.
1Libsdl
1Simple Directmedia Layer
Jun 17, 2026
Apr 1, 2022
N/A· v4
8.8 HIGH· v3
6.8 MEDIUM· v2
There is a heap overflow problem in video/SDL_pixels.c in SDL (Simple DirectMedia Layer) 2.x to 2.0.18 versions. By crafting a malicious .BMP file, an attacker can cause the application using this library to crash, denia...Show more
There is a heap overflow problem in video/SDL_pixels.c in SDL (Simple DirectMedia Layer) 2.x to 2.0.18 versions. By crafting a malicious .BMP file, an attacker can cause the application using this library to crash, denial of service or Code execution.Show less
3Debian
FedoraprojectLibsdl
3Debian Linux
FedoraSimple Directmedia Layer
Jun 17, 2026
Jan 19, 2021
N/A· v4
5.4 MEDIUM· v3
5.8 MEDIUM· v2
SDL (Simple DirectMedia Layer) through 2.0.12 has a heap-based buffer over-read in Blit_3or4_to_3or4__inversed_rgb in video/SDL_blit_N.c via a crafted .BMP file.
4Debian
FedoraprojectLibsdl+1 more
4Debian Linux
FedoraSimple Directmedia Layer+1 more
Jun 17, 2026
Jan 19, 2021
N/A· v4
7.8 HIGH· v3
6.8 MEDIUM· v2
SDL (Simple DirectMedia Layer) through 2.0.12 has an Integer Overflow (and resultant SDL_memcpy heap corruption) in SDL_BlitCopy in video/SDL_blit_copy.c via a crafted .BMP file.
2Libsdl
Redhat
2Enterprise Linux
Simple Directmedia Layer
Jun 17, 2026
Jan 7, 2020
N/A· v4
9.8 CRITICAL· v3
7.5 HIGH· v2
A flaw was found with the RHSA-2019:3950 erratum, where it did not fix the CVE-2019-13616 SDL vulnerability. This issue only affects Red Hat SDL packages, SDL versions through 1.2.15 and 2.x through 2.0.9 has a heap-base...Show more
A flaw was found with the RHSA-2019:3950 erratum, where it did not fix the CVE-2019-13616 SDL vulnerability. This issue only affects Red Hat SDL packages, SDL versions through 1.2.15 and 2.x through 2.0.9 has a heap-based buffer overflow flaw while copying an existing surface into a new optimized one, due to a lack of validation while loading a BMP image, is possible. An application that uses SDL to parse untrusted input files may be vulnerable to this flaw, which could allow an attacker to make the application crash or execute code.Show less
2Libsdl
Opensuse
3Backports Sle
LeapSdl2 Image
Jun 17, 2026
Jul 31, 2019
N/A· v4
8.8 HIGH· v3
6.8 MEDIUM· v2
An exploitable code execution vulnerability exists in the XPM image rendering function of SDL2_image 2.0.4. A specially crafted XPM image can cause an integer overflow in the colorhash function, allocating too small of a...Show more
An exploitable code execution vulnerability exists in the XPM image rendering function of SDL2_image 2.0.4. A specially crafted XPM image can cause an integer overflow in the colorhash function, allocating too small of a buffer. This buffer can then be written out of bounds, resulting in a heap overflow, ultimately ending in code execution. An attacker can display a specially crafted image to trigger this vulnerability.Show less
2Libsdl
Opensuse
3Backports Sle
LeapSdl2 Image
Jun 17, 2026
Jul 31, 2019
N/A· v4
8.8 HIGH· v3
6.8 MEDIUM· v2
An exploitable code execution vulnerability exists in the XPM image rendering functionality of SDL2_image 2.0.4. A specially crafted XPM image can cause an integer overflow, allocating too small of a buffer. This buffer...Show more
An exploitable code execution vulnerability exists in the XPM image rendering functionality of SDL2_image 2.0.4. A specially crafted XPM image can cause an integer overflow, allocating too small of a buffer. This buffer can then be written out of bounds resulting in a heap overflow, ultimately ending in code execution. An attacker can display a specially crafted image to trigger this vulnerability.Show less
2Libsdl
Opensuse
3Backports Sle
LeapSdl2 Image
Jun 17, 2026
Jul 31, 2019
N/A· v4
8.8 HIGH· v3
6.8 MEDIUM· v2
An exploitable code execution vulnerability exists in the XCF image rendering functionality of SDL2_image 2.0.4. A specially crafted XCF image can cause a heap overflow, resulting in code execution. An attacker can displ...Show more
An exploitable code execution vulnerability exists in the XCF image rendering functionality of SDL2_image 2.0.4. A specially crafted XCF image can cause a heap overflow, resulting in code execution. An attacker can display a specially crafted image to trigger this vulnerability.Show less
2Libsdl
Opensuse
3Backports Sle
LeapSdl2 Image
Jun 17, 2026
Jul 31, 2019
N/A· v4
8.8 HIGH· v3
6.8 MEDIUM· v2
An exploitable code execution vulnerability exists in the PCX image-rendering functionality of SDL2_image 2.0.4. A specially crafted PCX image can cause a heap overflow, resulting in code execution. An attacker can displ...Show more
An exploitable code execution vulnerability exists in the PCX image-rendering functionality of SDL2_image 2.0.4. A specially crafted PCX image can cause a heap overflow, resulting in code execution. An attacker can display a specially crafted image to trigger this vulnerability.Show less
4Debian
FedoraprojectLibsdl+1 more
4Debian Linux
FedoraLeap+1 more
Jun 17, 2026
Jul 17, 2019
N/A· v4
6.5 MEDIUM· v3
4.3 MEDIUM· v2
SDL (Simple DirectMedia Layer) 2.x through 2.0.9 has a heap-based buffer over-read in Fill_IMA_ADPCM_block, caused by an integer overflow in IMA_ADPCM_decode() in audio/SDL_wave.c.
6Canonical
DebianFedoraproject+3 more
13Backports Sle
Debian LinuxEnterprise Linux+10 more
Jun 17, 2026
Jul 16, 2019
N/A· v4
8.1 HIGH· v3
5.8 MEDIUM· v2
SDL (Simple DirectMedia Layer) through 1.2.15 and 2.x through 2.0.9 has a heap-based buffer over-read in BlitNtoN in video/SDL_blit_N.c when called from SDL_SoftBlit in video/SDL_blit.c.
4Canonical
DebianLibsdl+1 more
5Backports Sle
Debian LinuxLeap+2 more
Jun 17, 2026
Jul 3, 2019
N/A· v4
8.8 HIGH· v3
6.8 MEDIUM· v2
An exploitable integer overflow vulnerability exists when loading a PCX file in SDL2_image 2.0.4. A specially crafted file can cause an integer overflow, resulting in too little memory being allocated, which can lead to...Show more
An exploitable integer overflow vulnerability exists when loading a PCX file in SDL2_image 2.0.4. A specially crafted file can cause an integer overflow, resulting in too little memory being allocated, which can lead to a buffer overflow and potential code execution. An attacker can provide a specially crafted image file to trigger this vulnerability.Show less
4Canonical
DebianLibsdl+1 more
5Backports Sle
Debian LinuxLeap+2 more
Jun 17, 2026
Jul 3, 2019
N/A· v4
8.8 HIGH· v3
6.8 MEDIUM· v2
An exploitable heap-based buffer overflow vulnerability exists when loading a PCX file in SDL2_image, version 2.0.4. A missing error handler can lead to a buffer overflow and potential code execution. An attacker can pro...Show more
An exploitable heap-based buffer overflow vulnerability exists when loading a PCX file in SDL2_image, version 2.0.4. A missing error handler can lead to a buffer overflow and potential code execution. An attacker can provide a specially crafted image file to trigger this vulnerability.Show less
1Libsdl
1Simple Directmedia Layer
Jun 17, 2026
May 20, 2019
N/A· v4
6.5 MEDIUM· v3
4.3 MEDIUM· v2
An issue was discovered in libSDL2.a in Simple DirectMedia Layer (SDL) 2.0.9. There is an out-of-bounds read in the function SDL_InvalidateMap at video/SDL_pixels.c.
5Canonical
DebianFedoraproject+2 more
7Backports Sle
Debian LinuxFedora+4 more
Jun 17, 2026
May 20, 2019
N/A· v4
6.5 MEDIUM· v3
4.3 MEDIUM· v2
An issue was discovered in libSDL2.a in Simple DirectMedia Layer (SDL) 2.0.9 when used in conjunction with libSDL2_image.a in SDL2_image 2.0.4. There is a SEGV in the SDL function SDL_free_REAL at stdlib/SDL_malloc.c.
1Libsdl
2Sdl2 Image
Simple Directmedia Layer
Jun 17, 2026
May 20, 2019
N/A· v4
6.5 MEDIUM· v3
4.3 MEDIUM· v2
An issue was discovered in libSDL2.a in Simple DirectMedia Layer (SDL) 2.0.9 when used in conjunction with libSDL2_image.a in SDL2_image 2.0.4. There is an out-of-bounds read in the SDL function SDL_FreePalette_REAL at v...Show more
An issue was discovered in libSDL2.a in Simple DirectMedia Layer (SDL) 2.0.9 when used in conjunction with libSDL2_image.a in SDL2_image 2.0.4. There is an out-of-bounds read in the SDL function SDL_FreePalette_REAL at video/SDL_pixels.c.Show less
1Libsdl
2Sdl2 Image
Simple Directmedia Layer
Jun 17, 2026
May 20, 2019
N/A· v4
8.8 HIGH· v3
6.8 MEDIUM· v2
An issue was discovered in libSDL2.a in Simple DirectMedia Layer (SDL) 2.0.9 when used in conjunction with libSDL2_image.a in SDL2_image 2.0.4. There is an invalid free error in the SDL function SDL_SetError_REAL at SDL_...Show more
An issue was discovered in libSDL2.a in Simple DirectMedia Layer (SDL) 2.0.9 when used in conjunction with libSDL2_image.a in SDL2_image 2.0.4. There is an invalid free error in the SDL function SDL_SetError_REAL at SDL_error.c.Show less