cbcvebase.

Libsdl Simple Directmedia Layer vulnerabilities

26 known vulnerabilities affecting libsdl/simple_directmedia_layer.

Total CVEs
26
CISA KEV
0
Public exploits
0
Exploited in wild
0
Severity breakdown
CRITICAL1HIGH18MEDIUM7

Vulnerabilities

Page 1 of 2
CVE-2019-14906P3CRITICALCVSS 9.8≤ 1.2.15≥ 2.0.0, ≤ 2.0.92020-01-07
CVE-2019-14906 [CRITICAL] CVE-2019-14906: A flaw was found with the RHSA-2019:3950 erratum, where it did not fix the CVE-2019-13616 SDL vulner A flaw was found with the RHSA-2019:3950 erratum, where it did not fix the CVE-2019-13616 SDL vulnerability. This issue only affects Red Hat SDL packages, SDL versions through 1.2.15 and 2.x through 2.0.9 has a heap-based buffer overflow flaw while copying an existing surface into a new optimized one, due to a lack of validation while loading a BMP image,
nvd
CVE-2019-7637P3HIGHCVSS 8.8≤ 1.2.15≥ 2.0.0, ≤ 2.0.92019-02-08
CVE-2019-7637 [HIGH] CWE-787 CVE-2019-7637: SDL (Simple DirectMedia Layer) through 1.2.15 and 2.x through 2.0.9 has a heap-based buffer overflow SDL (Simple DirectMedia Layer) through 1.2.15 and 2.x through 2.0.9 has a heap-based buffer overflow in SDL_FillRect in video/SDL_surface.c.
nvd
CVE-2017-2888P3HIGHCVSS 8.8v2.0.52017-10-11
CVE-2017-2888 [HIGH] CWE-190 CVE-2017-2888: An exploitable integer overflow vulnerability exists when creating a new RGB Surface in SDL 2.0.5. A An exploitable integer overflow vulnerability exists when creating a new RGB Surface in SDL 2.0.5. A specially crafted file can cause an integer overflow resulting in too little memory being allocated which can lead to a buffer overflow and potential code execution. An attacker can provide a specially crafted image file to trigger this vulnerability.
nvd
CVE-2019-7575P3HIGHCVSS 8.8≤ 1.2.15≥ 2.0.0, ≤ 2.0.92019-02-07
CVE-2019-7575 [HIGH] CWE-787 CVE-2019-7575: SDL (Simple DirectMedia Layer) through 1.2.15 and 2.x through 2.0.9 has a heap-based buffer overflow SDL (Simple DirectMedia Layer) through 1.2.15 and 2.x through 2.0.9 has a heap-based buffer overflow in MS_ADPCM_decode in audio/SDL_wave.c.
nvd
CVE-2021-33657P3HIGHCVSS 8.8≥ 2.0.0, ≤ 2.0.182022-04-01
CVE-2021-33657 [HIGH] CWE-787 CVE-2021-33657: There is a heap overflow problem in video/SDL_pixels.c in SDL (Simple DirectMedia Layer) 2.x to 2.0. There is a heap overflow problem in video/SDL_pixels.c in SDL (Simple DirectMedia Layer) 2.x to 2.0.18 versions. By crafting a malicious .BMP file, an attacker can cause the application using this library to crash, denial of service or Code execution.
nvd
CVE-2019-7576P3HIGHCVSS 8.8≤ 1.2.15≥ 2.0.0, ≤ 2.0.92019-02-07
CVE-2019-7576 [HIGH] CWE-125 CVE-2019-7576: SDL (Simple DirectMedia Layer) through 1.2.15 and 2.x through 2.0.9 has a heap-based buffer over-rea SDL (Simple DirectMedia Layer) through 1.2.15 and 2.x through 2.0.9 has a heap-based buffer over-read in InitMS_ADPCM in audio/SDL_wave.c (outside the wNumCoef loop).
nvd
CVE-2019-7577P3HIGHCVSS 8.8≤ 1.2.15≥ 2.0.0, ≤ 2.0.92019-02-07
CVE-2019-7577 [HIGH] CWE-125 CVE-2019-7577: SDL (Simple DirectMedia Layer) through 1.2.15 and 2.x through 2.0.9 has a buffer over-read in SDL_Lo SDL (Simple DirectMedia Layer) through 1.2.15 and 2.x through 2.0.9 has a buffer over-read in SDL_LoadWAV_RW in audio/SDL_wave.c.
nvd
CVE-2019-7573P3HIGHCVSS 8.8≤ 1.2.15≥ 2.0.0, ≤ 2.0.92019-02-07
CVE-2019-7573 [HIGH] CWE-125 CVE-2019-7573: SDL (Simple DirectMedia Layer) through 1.2.15 and 2.x through 2.0.9 has a heap-based buffer over-rea SDL (Simple DirectMedia Layer) through 1.2.15 and 2.x through 2.0.9 has a heap-based buffer over-read in InitMS_ADPCM in audio/SDL_wave.c (inside the wNumCoef loop).
nvd
CVE-2019-7638P3HIGHCVSS 8.8≤ 1.2.15≥ 2.0.0, ≤ 2.0.92019-02-08
CVE-2019-7638 [HIGH] CWE-125 CVE-2019-7638: SDL (Simple DirectMedia Layer) through 1.2.15 and 2.x through 2.0.9 has a heap-based buffer over-rea SDL (Simple DirectMedia Layer) through 1.2.15 and 2.x through 2.0.9 has a heap-based buffer over-read in Map1toN in video/SDL_pixels.c.
nvd
CVE-2019-7574P3HIGHCVSS 8.8≤ 1.2.15≥ 2.0.0, ≤ 2.0.92019-02-07
CVE-2019-7574 [HIGH] CWE-125 CVE-2019-7574: SDL (Simple DirectMedia Layer) through 1.2.15 and 2.x through 2.0.9 has a heap-based buffer over-rea SDL (Simple DirectMedia Layer) through 1.2.15 and 2.x through 2.0.9 has a heap-based buffer over-read in IMA_ADPCM_decode in audio/SDL_wave.c.
nvd
CVE-2019-7572P3HIGHCVSS 8.8≤ 1.2.15≥ 2.0.0, ≤ 2.0.92019-02-07
CVE-2019-7572 [HIGH] CWE-125 CVE-2019-7572: SDL (Simple DirectMedia Layer) through 1.2.15 and 2.x through 2.0.9 has a buffer over-read in IMA_AD SDL (Simple DirectMedia Layer) through 1.2.15 and 2.x through 2.0.9 has a buffer over-read in IMA_ADPCM_nibble in audio/SDL_wave.c.
nvd
CVE-2019-13616P3HIGHCVSS 8.1≤ 1.2.15≥ 2.0.0, ≤ 2.0.92019-07-16
CVE-2019-13616 [HIGH] CWE-125 CVE-2019-13616: SDL (Simple DirectMedia Layer) through 1.2.15 and 2.x through 2.0.9 has a heap-based buffer over-rea SDL (Simple DirectMedia Layer) through 1.2.15 and 2.x through 2.0.9 has a heap-based buffer over-read in BlitNtoN in video/SDL_blit_N.c when called from SDL_SoftBlit in video/SDL_blit.c.
nvd
CVE-2019-12219P3HIGHCVSS 8.8v2.0.92019-05-20
CVE-2019-12219 [HIGH] CWE-415 CVE-2019-12219: An issue was discovered in libSDL2.a in Simple DirectMedia Layer (SDL) 2.0.9 when used in conjunctio An issue was discovered in libSDL2.a in Simple DirectMedia Layer (SDL) 2.0.9 when used in conjunction with libSDL2_image.a in SDL2_image 2.0.4. There is an invalid free error in the SDL function SDL_SetError_REAL at SDL_error.c.
nvd
CVE-2019-7635P3HIGHCVSS 8.1≤ 1.2.15≥ 2.0.0, ≤ 2.0.92019-02-08
CVE-2019-7635 [HIGH] CWE-125 CVE-2019-7635: SDL (Simple DirectMedia Layer) through 1.2.15 and 2.x through 2.0.9 has a heap-based buffer over-rea SDL (Simple DirectMedia Layer) through 1.2.15 and 2.x through 2.0.9 has a heap-based buffer over-read in Blit1to4 in video/SDL_blit_1.c.
nvd
CVE-2019-7578P3HIGHCVSS 8.1≤ 1.2.15≥ 2.0.0, ≤ 2.0.92019-02-07
CVE-2019-7578 [HIGH] CWE-125 CVE-2019-7578: SDL (Simple DirectMedia Layer) through 1.2.15 and 2.x through 2.0.9 has a heap-based buffer over-rea SDL (Simple DirectMedia Layer) through 1.2.15 and 2.x through 2.0.9 has a heap-based buffer over-read in InitIMA_ADPCM in audio/SDL_wave.c.
nvd
CVE-2019-7636P3HIGHCVSS 8.1≤ 1.2.15≥ 2.0.0, ≤ 2.0.92019-02-08
CVE-2019-7636 [HIGH] CWE-125 CVE-2019-7636: SDL (Simple DirectMedia Layer) through 1.2.15 and 2.x through 2.0.9 has a heap-based buffer over-rea SDL (Simple DirectMedia Layer) through 1.2.15 and 2.x through 2.0.9 has a heap-based buffer over-read in SDL_GetRGB in video/SDL_pixels.c.
nvd
CVE-2020-14409P3HIGHCVSS 7.8≥ 2.0.12, ≤ 2.0.202021-01-19
CVE-2020-14409 [HIGH] CWE-190 CVE-2020-14409: SDL (Simple DirectMedia Layer) through 2.0.12 has an Integer Overflow (and resultant SDL_memcpy heap SDL (Simple DirectMedia Layer) through 2.0.12 has an Integer Overflow (and resultant SDL_memcpy heap corruption) in SDL_BlitCopy in video/SDL_blit_copy.c via a crafted .BMP file.
nvd
CVE-2022-34568P4HIGHCVSS 7.5≥ 1.2.1, ≤ 1.2.152022-07-28
CVE-2022-34568 [HIGH] CWE-416 CVE-2022-34568: SDL v1.2 was discovered to contain a use-after-free via the XFree function at /src/video/x11/SDL_x11 SDL v1.2 was discovered to contain a use-after-free via the XFree function at /src/video/x11/SDL_x11yuv.c.
nvd
CVE-2022-4743P4HIGHCVSS 7.5≥ 2.0.4, < 2.26.02023-01-12
CVE-2022-4743 [HIGH] CWE-401 CVE-2022-4743: A potential memory leak issue was discovered in SDL2 in GLES_CreateTexture() function in SDL_render_ A potential memory leak issue was discovered in SDL2 in GLES_CreateTexture() function in SDL_render_gles.c. The vulnerability allows an attacker to cause a denial of service attack. The vulnerability affects SDL2 v2.0.4 and above. SDL-1.x are not affected.
nvd
CVE-2019-12216P4MEDIUMCVSS 6.5v2.0.92019-05-20
CVE-2019-12216 [MEDIUM] CWE-787 CVE-2019-12216: An issue was discovered in libSDL2.a in Simple DirectMedia Layer (SDL) 2.0.9 when used in conjunctio An issue was discovered in libSDL2.a in Simple DirectMedia Layer (SDL) 2.0.9 when used in conjunction with libSDL2_image.a in SDL2_image 2.0.4. There is a heap-based buffer overflow in the SDL2_image function IMG_LoadPCX_RW at IMG_pcx.c.
nvd
Libsdl Simple Directmedia Layer vulnerabilities | cvebase