Sdl2 Image
Vendor:
First CVE: May 20, 2019 · Active for 7 years
12
Total CVEs
More Total CVEs than 90% of tracked products
12.0
Avg CVEs / Year
Higher CVE frequency than 97% of tracked products
7.8
Avg CVSS
Higher Avg CVSS than 67% of tracked products
0.0%
KEV Rate
Bottom 1%
Trends Over Time
The number and severity of CVEs published that impact Sdl2 Image over time
Volume of CVEsAvg CVSS Base Score
First CVE
May 20, 2019
7 years ago
Most Recent CVE
Jul 31, 2019
2,550 days ago
CVE Severity & Scoring
Sdl2 Image12 CVEs
42%
58%
All CVEs352,294 CVEs
45%
40%
11%
MediumHigh
Attack Vector
Local0 (0.0%)
Network12 (100.0%)
Unknown0 (0.0%)
Physical0 (0.0%)
Adjacent Network0 (0.0%)
Attack Complexity
Low12 (100.0%)
High0 (0.0%)
Unknown0 (0.0%)
User Interaction
None0 (0.0%)
Unknown0 (0.0%)
Required12 (100.0%)
Privileges Required
Low0 (0.0%)
High0 (0.0%)
None12 (100.0%)
Unknown0 (0.0%)
Top CVEs
Signals from CVEs in this product scope (12 CVEs).
12 CVEs · Highest risk first
| CVE | Published | CVSS | Risk | KEV | Exploit |
|---|---|---|---|---|---|
CVE-2019-5059HIGH An exploitable code execution vulnerability exists in the XPM image rendering functionality of SDL2_image 2.0.4. A specially crafted XPM image can cause an integer overflow, alloca | Jul 31, 2019 | 8.8 | 29 | NO | NO |
CVE-2019-5058HIGH An exploitable code execution vulnerability exists in the XCF image rendering functionality of SDL2_image 2.0.4. A specially crafted XCF image can cause a heap overflow, resulting | Jul 31, 2019 | 8.8 | 29 | NO | NO |
CVE-2019-5057HIGH An exploitable code execution vulnerability exists in the PCX image-rendering functionality of SDL2_image 2.0.4. A specially crafted PCX image can cause a heap overflow, resulting | Jul 31, 2019 | 8.8 | 29 | NO | NO |
CVE-2019-5052HIGH An exploitable integer overflow vulnerability exists when loading a PCX file in SDL2_image 2.0.4. A specially crafted file can cause an integer overflow, resulting in too little me | Jul 3, 2019 | 8.8 | 29 | NO | NO |
CVE-2019-5051HIGH An exploitable heap-based buffer overflow vulnerability exists when loading a PCX file in SDL2_image, version 2.0.4. A missing error handler can lead to a buffer overflow and poten | Jul 3, 2019 | 8.8 | 29 | NO | NO |
CVE-2019-5060HIGH An exploitable code execution vulnerability exists in the XPM image rendering function of SDL2_image 2.0.4. A specially crafted XPM image can cause an integer overflow in the color | Jul 31, 2019 | 8.8 | 28 | NO | NO |
CVE-2019-12219HIGH An issue was discovered in libSDL2.a in Simple DirectMedia Layer (SDL) 2.0.9 when used in conjunction with libSDL2_image.a in SDL2_image 2.0.4. There is an invalid free error in th | May 20, 2019 | 8.8 | 28 | NO | NO |
CVE-2019-12221MEDIUM An issue was discovered in libSDL2.a in Simple DirectMedia Layer (SDL) 2.0.9 when used in conjunction with libSDL2_image.a in SDL2_image 2.0.4. There is a SEGV in the SDL function | May 20, 2019 | 6.5 | 23 | NO | NO |
CVE-2019-12220MEDIUM An issue was discovered in libSDL2.a in Simple DirectMedia Layer (SDL) 2.0.9 when used in conjunction with libSDL2_image.a in SDL2_image 2.0.4. There is an out-of-bounds read in th | May 20, 2019 | 6.5 | 23 | NO | NO |
CVE-2019-12218MEDIUM An issue was discovered in libSDL2.a in Simple DirectMedia Layer (SDL) 2.0.9 when used in conjunction with libSDL2_image.a in SDL2_image 2.0.4. There is a NULL pointer dereference | May 20, 2019 | 6.5 | 23 | NO | NO |
Exploit Exposure
Signals from CVEs in this product scope (12 CVEs).
CISA KEV
0 CVEs
0.0% of CVEs· Bottom 1%
Metasploit
0 CVEs
0.0% of CVEs· Bottom 1%
Nuclei
0 CVEs
0.0% of CVEs· Bottom 1%
ExploitDB
0 CVEs
0.0% of CVEs· Bottom 1%
Social Chatter
Signals from CVEs in this product scope (12 CVEs).
Media Mentions
Signals from CVEs in this product scope (12 CVEs).
Top CNAs Publishing CVEs For Sdl2 Image
Top CWEs
Versions
| Version | CVE Count | Avg CVSS | Avg EPSS | KEV | Exploits |
|---|---|---|---|---|---|
| 2.0.4 | 12 | 7.8 | 3.0% | 0 | 0 |