Sdl Image
Vendor:
First CVE: Oct 11, 2017 · Active for 8 years
13
Total CVEs
More Total CVEs than 91% of tracked products
4.3
Avg CVEs / Year
Higher CVE frequency than 86% of tracked products
8.0
Avg CVSS
Higher Avg CVSS than 70% of tracked products
0.0%
KEV Rate
Bottom 1%
Trends Over Time
The number and severity of CVEs published that impact Sdl Image over time
Volume of CVEsAvg CVSS Base Score
First CVE
Oct 11, 2017
8 years ago
Most Recent CVE
Apr 6, 2026
109 days ago
CVE Severity & Scoring
Sdl Image13 CVEs
23%
77%
All CVEs352,231 CVEs
45%
40%
11%
MediumHigh
Attack Vector
Local2 (15.4%)
Network11 (84.6%)
Unknown0 (0.0%)
Physical0 (0.0%)
Adjacent Network0 (0.0%)
Attack Complexity
Low13 (100.0%)
High0 (0.0%)
Unknown0 (0.0%)
User Interaction
None0 (0.0%)
Unknown0 (0.0%)
Required13 (100.0%)
Privileges Required
Low0 (0.0%)
High0 (0.0%)
None13 (100.0%)
Unknown0 (0.0%)
Top CVEs
Signals from CVEs in this product scope (13 CVEs).
13 CVEs · Highest risk first
| CVE | Published | CVSS | Risk | KEV | Exploit |
|---|---|---|---|---|---|
CVE-2018-3977HIGH An exploitable code execution vulnerability exists in the XCF image rendering functionality of SDL2_image-2.0.3. A specially crafted XCF image can cause a heap overflow, resulting | Nov 1, 2018 | 8.8 | 29 | NO | NO |
CVE-2018-3839HIGH An exploitable code execution vulnerability exists in the XCF image rendering functionality of Simple DirectMedia Layer SDL2_image-2.0.2. A specially crafted XCF image can cause an | Apr 10, 2018 | 8.8 | 29 | NO | NO |
CVE-2017-2887HIGH An exploitable buffer overflow vulnerability exists in the XCF property handling functionality of SDL_image 2.0.1. A specially crafted xcf file can cause a stack-based buffer overf | Oct 11, 2017 | 8.8 | 29 | NO | NO |
CVE-2017-14441HIGH An exploitable code execution vulnerability exists in the ICO image rendering functionality of SDL2_image-2.0.2. A specially crafted ICO image can cause an integer overflow, cascad | Apr 24, 2018 | 8.8 | 27 | NO | NO |
CVE-2017-14440HIGH An exploitable code execution vulnerability exists in the ILBM image rendering functionality of SDL2_image-2.0.2. A specially crafted ILBM image can cause a stack overflow resultin | Apr 24, 2018 | 8.8 | 27 | NO | NO |
CVE-2017-12122HIGH An exploitable code execution vulnerability exists in the ILBM image rendering functionality of SDL2_image-2.0.2. A specially crafted ILBM image can cause a heap overflow resulting | Apr 24, 2018 | 8.8 | 27 | NO | NO |
CVE-2017-14448HIGH An exploitable code execution vulnerability exists in the XCF image rendering functionality of SDL2_image-2.0.2. A specially crafted XCF image can cause a heap overflow resulting i | Apr 24, 2018 | 8.8 | 26 | NO | NO |
CVE-2017-14442HIGH An exploitable code execution vulnerability exists in the BMP image rendering functionality of SDL2_image-2.0.2. A specially crafted BMP image can cause a stack overflow resulting | Apr 24, 2018 | 8.8 | 26 | NO | NO |
CVE-2017-14449HIGH A double-Free vulnerability exists in the XCF image rendering functionality of SDL2_image-2.0.2. A specially crafted XCF image can cause a Double-Free situation to occur. An attack | Apr 24, 2018 | 8.8 | 25 | NO | NO |
CVE-2026-35444MEDIUM SDL_image is a library to load images of various formats as SDL surfaces. In do_layer_surface() in src/IMG_xcf.c, pixel index values from decoded XCF tile data are used directly as | Apr 6, 2026 | 6.1 | 23 | NO | NO |
Exploit Exposure
Signals from CVEs in this product scope (13 CVEs).
CISA KEV
0 CVEs
0.0% of CVEs· Bottom 1%
Metasploit
0 CVEs
0.0% of CVEs· Bottom 1%
Nuclei
0 CVEs
0.0% of CVEs· Bottom 1%
ExploitDB
0 CVEs
0.0% of CVEs· Bottom 1%
Social Chatter
Signals from CVEs in this product scope (13 CVEs).
Media Mentions
Signals from CVEs in this product scope (13 CVEs).
Top CNAs Publishing CVEs For Sdl Image
Top CWEs
Versions
| Version | CVE Count | Avg CVSS | Avg EPSS | KEV | Exploits |
|---|---|---|---|---|---|
| 2.0.3 | 1 | 8.8 | 3.5% | 0 | 0 |
| 2.0.2 | 10 | 8.1 | 2.1% | 0 | 0 |
| 2.0.1 | 1 | 8.8 | 2.7% | 0 | 0 |