Cisco Systems Inc Simple Directmedia vulnerabilities

4 known vulnerabilities affecting cisco_systems_inc/simple_directmedia.

Total CVEs
4
CISA KEV
0
Public exploits
0
Exploited in wild
0
Severity breakdown
HIGH3MEDIUM1

Vulnerabilities

Page 1 of 1
CVE-2019-5051HIGHCVSS 8.8vSimple DirectMedia Layer SDL2_image 2.0.42019-07-03
CVE-2019-5051 [HIGH] CWE-390 CVE-2019-5051: An exploitable heap-based buffer overflow vulnerability exists when loading a PCX file in SDL2_image, version 2 An exploitable heap-based buffer overflow vulnerability exists when loading a PCX file in SDL2_image, version 2.0.4. A missing error handler can lead to a buffer overflow and potential code execution. An attacker can provide a specially crafted image file to trigger this vulnerability.
cvelistv5
CVE-2019-5052HIGHCVSS 8.8vSimple DirectMedia Layer SDL2_image 2.0.42019-07-03
CVE-2019-5052 [HIGH] CWE-190 CVE-2019-5052: An exploitable integer overflow vulnerability exists when loading a PCX file in SDL2_image 2 An exploitable integer overflow vulnerability exists when loading a PCX file in SDL2_image 2.0.4. A specially crafted file can cause an integer overflow, resulting in too little memory being allocated, which can lead to a buffer overflow and potential code execution. An attacker can provide a specially crafted image file to trigger this vulnerability.
cvelistv5
CVE-2018-3839HIGHCVSS 8.8vSimple DirectMedia Layer SDL2_image 2.0.22018-04-10
CVE-2018-3839 [HIGH] CWE-787 CVE-2018-3839: An exploitable code execution vulnerability exists in the XCF image rendering functionality of Simpl An exploitable code execution vulnerability exists in the XCF image rendering functionality of Simple DirectMedia Layer SDL2_image-2.0.2. A specially crafted XCF image can cause an out-of-bounds write on the heap, resulting in code execution. An attacker can display a specially crafted image to trigger this vulnerability.
cvelistv5nvd
CVE-2018-3838MEDIUMCVSS 6.5vSimple DirectMedia Layer SDL2_image 2.0.22018-04-10
CVE-2018-3838 [MEDIUM] CWE-125 CVE-2018-3838: An exploitable information vulnerability exists in the XCF image rendering functionality of Simple D An exploitable information vulnerability exists in the XCF image rendering functionality of Simple DirectMedia Layer SDL2_image-2.0.2. A specially crafted XCF image can cause an out-of-bounds read on the heap, resulting in information disclosure. An attacker can display a specially crafted image to trigger this vulnerability.
cvelistv5nvd