SDL maintains a narrowly scoped portfolio around localization, content management, and media-handling products such as SDL Image and Web Content Manager, where vulnerabilities cluster around memory-safety and XML-processing issues. The recurring weakness classes—improper memory-buffer restrictions and XML external entity handling—reflect the parsing and data-interchange demands of these tools. Live severity, exploitation, and exposure counts are shown alongside this summary.
The number and severity of CVEs published that impact products developed by Sdl over time
Signals from CVEs in this vendor scope (3 CVEs).
3 CVEs · Highest risk first
| CVE | Published | CVSS | Risk | KEV | Exploit |
|---|---|---|---|---|---|
CVE-2018-19371MEDIUM The SaveUserSettings service in Content Manager in SDL Web 8.5.0 has an XXE Vulnerability that allows reading sensitive files from the system. | Jan 2, 2019 | 6.5 | 34 | NO | YES |
CVE-2007-6697HIGH Buffer overflow in the LWZReadByte function in IMG_gif.c in SDL_image before 1.2.7 allows remote attackers to cause a denial of service (application crash) or possibly execute arbi | Feb 1, 2008 | 7.5 | 33 | NO | YES |
CVE-2008-0544HIGH Heap-based buffer overflow in the IMG_LoadLBM_RW function in IMG_lbm.c in SDL_image before 1.2.7 allows remote attackers to cause a denial of service (application crash) or possibl | Feb 1, 2008 | 10.0 | 27 | NO | NO |
Signals from CVEs in this vendor scope (3 CVEs).
An overview of all social media posts that mention a CVE ID that affects a product developed by Sdl.
Media articles that mention a CVE ID that affects a product developed by Sdl — matched by CVE ID, not by vendor name.