Libsdl is a cross-platform multimedia library that provides low-level graphics, audio, and input handling for game engines and media applications; its narrow product line—centered on the core Simple DirectMedia Layer library and specialized extensions such as SDL_Image and SDL_TTF—sits deep in the software supply chain and is embedded in a broad range of downstream games and applications. The vendor's vulnerability exposure concentrates in memory-safety weaknesses endemic to C-based graphics and format-parsing code: out-of-bounds reads and writes, integer overflows, double-free conditions, and heap-based buffer overflows that arise when processing image data, font files, and untrusted input streams. Defenders should treat vulnerabilities in this library as high-priority for remediation in dependent applications, since a single flaw can affect every game or tool that links the library; however, the patching burden typically falls on downstream vendors rather than on Libsdl itself. Live severity, exploitation, and exposure counts are shown alongside this summary.
The number and severity of CVEs published that impact products developed by Libsdl over time
Signals from CVEs in this vendor scope (47 CVEs).
47 CVEs · Highest risk first
| CVE | Published | CVSS | Risk | KEV | Exploit |
|---|---|---|---|---|---|
CVE-2019-14906CRITICAL A flaw was found with the RHSA-2019:3950 erratum, where it did not fix the CVE-2019-13616 SDL vulnerability. This issue only affects Red Hat SDL packages, SDL versions through 1.2. | Jan 7, 2020 | 9.8 | 29 | NO | NO |
CVE-2019-5059HIGH An exploitable code execution vulnerability exists in the XPM image rendering functionality of SDL2_image 2.0.4. A specially crafted XPM image can cause an integer overflow, alloca | Jul 31, 2019 | 8.8 | 29 | NO | NO |
CVE-2019-5058HIGH An exploitable code execution vulnerability exists in the XCF image rendering functionality of SDL2_image 2.0.4. A specially crafted XCF image can cause a heap overflow, resulting | Jul 31, 2019 | 8.8 | 29 | NO | NO |
CVE-2019-5057HIGH An exploitable code execution vulnerability exists in the PCX image-rendering functionality of SDL2_image 2.0.4. A specially crafted PCX image can cause a heap overflow, resulting | Jul 31, 2019 | 8.8 | 29 | NO | NO |
CVE-2019-5052HIGH An exploitable integer overflow vulnerability exists when loading a PCX file in SDL2_image 2.0.4. A specially crafted file can cause an integer overflow, resulting in too little me | Jul 3, 2019 | 8.8 | 29 | NO | NO |
CVE-2019-5051HIGH An exploitable heap-based buffer overflow vulnerability exists when loading a PCX file in SDL2_image, version 2.0.4. A missing error handler can lead to a buffer overflow and poten | Jul 3, 2019 | 8.8 | 29 | NO | NO |
CVE-2019-7574HIGH SDL (Simple DirectMedia Layer) through 1.2.15 and 2.x through 2.0.9 has a heap-based buffer over-read in IMA_ADPCM_decode in audio/SDL_wave.c. | Feb 7, 2019 | 8.8 | 29 | NO | NO |
CVE-2018-3977HIGH An exploitable code execution vulnerability exists in the XCF image rendering functionality of SDL2_image-2.0.3. A specially crafted XCF image can cause a heap overflow, resulting | Nov 1, 2018 | 8.8 | 29 | NO | NO |
CVE-2018-3839HIGH An exploitable code execution vulnerability exists in the XCF image rendering functionality of Simple DirectMedia Layer SDL2_image-2.0.2. A specially crafted XCF image can cause an | Apr 10, 2018 | 8.8 | 29 | NO | NO |
CVE-2017-2888HIGH An exploitable integer overflow vulnerability exists when creating a new RGB Surface in SDL 2.0.5. A specially crafted file can cause an integer overflow resulting in too little me | Oct 11, 2017 | 8.8 | 29 | NO | NO |
Signals from CVEs in this vendor scope (47 CVEs).
An overview of all social media posts that mention a CVE ID that affects a product developed by Libsdl.
Media articles that mention a CVE ID that affects a product developed by Libsdl — matched by CVE ID, not by vendor name.