CVEInsight.
TrendingZero-DayExploreBrowseSearchSaved
CVEInsight.

Free vulnerability intelligence for developers, security teams, and researchers. Data sourced from public databases for informational purposes only.

Explore

HomeTrendingZero-Day WatchAttack TypesBrowse CVEsSearch

Legal

Privacy PolicyTerms of ServiceData Disclaimer

© 2026CVEInsight. For informational use only — not a substitute for professional security advice.

CVE data sourced from NVD / NIST & public disclosures.

libsdl

simple_directmedia_layer

25 known vulnerabilities · sorted by CVSS score

CVE-2019-14906
CRITICAL9.8

A flaw was found with the RHSA-2019:3950 erratum, where it did not fix the CVE-2019-13616 SDL vulnerability. This issue only affects Red Hat SDL packages, SDL versions through 1.2.15 and 2.x through 2.0.9 has a heap-based buffer overflow flaw while copying an existing surface into a new optimized one, due to a lack of validation while loading a BMP image, is possible. An application that uses SDL to parse untrusted input files may be vulnerable to this flaw, which could allow an attacker to make the application crash or execute code.

libsdl / simple_directmedia_layer+2
Network
Published Jan 7, 2020
Page 1 of 2
CVE-2019-7573
HIGH8.8

SDL (Simple DirectMedia Layer) through 1.2.15 and 2.x through 2.0.9 has a heap-based buffer over-read in InitMS_ADPCM in audio/SDL_wave.c (inside the wNumCoef loop).

libsdl / simple_directmedia_layer+10
Network
Published Feb 7, 2019
CVE-2019-7637
HIGH8.8

SDL (Simple DirectMedia Layer) through 1.2.15 and 2.x through 2.0.9 has a heap-based buffer overflow in SDL_FillRect in video/SDL_surface.c.

libsdl / simple_directmedia_layer+12
Network
Published Feb 8, 2019
CVE-2019-7572
HIGH8.8

SDL (Simple DirectMedia Layer) through 1.2.15 and 2.x through 2.0.9 has a buffer over-read in IMA_ADPCM_nibble in audio/SDL_wave.c.

libsdl / simple_directmedia_layer+10
Network
Published Feb 7, 2019
CVE-2019-7638
HIGH8.8

SDL (Simple DirectMedia Layer) through 1.2.15 and 2.x through 2.0.9 has a heap-based buffer over-read in Map1toN in video/SDL_pixels.c.

libsdl / simple_directmedia_layer+9
Network
Published Feb 8, 2019
CVE-2019-7575
HIGH8.8

SDL (Simple DirectMedia Layer) through 1.2.15 and 2.x through 2.0.9 has a heap-based buffer overflow in MS_ADPCM_decode in audio/SDL_wave.c.

libsdl / simple_directmedia_layer+10
Network
Published Feb 7, 2019
CVE-2019-7574
HIGH8.8

SDL (Simple DirectMedia Layer) through 1.2.15 and 2.x through 2.0.9 has a heap-based buffer over-read in IMA_ADPCM_decode in audio/SDL_wave.c.

libsdl / simple_directmedia_layer+10
Network
Published Feb 7, 2019
CVE-2019-7576
HIGH8.8

SDL (Simple DirectMedia Layer) through 1.2.15 and 2.x through 2.0.9 has a heap-based buffer over-read in InitMS_ADPCM in audio/SDL_wave.c (outside the wNumCoef loop).

libsdl / simple_directmedia_layer+10
Network
Published Feb 7, 2019
CVE-2019-7577
HIGH8.8

SDL (Simple DirectMedia Layer) through 1.2.15 and 2.x through 2.0.9 has a buffer over-read in SDL_LoadWAV_RW in audio/SDL_wave.c.

libsdl / simple_directmedia_layer+12
Network
Published Feb 7, 2019
CVE-2021-33657
HIGH8.8

There is a heap overflow problem in video/SDL_pixels.c in SDL (Simple DirectMedia Layer) 2.x to 2.0.18 versions. By crafting a malicious .BMP file, an attacker can cause the application using this library to crash, denial of service or Code execution.

libsdl / simple_directmedia_layer
Network
Published Apr 1, 2022
CVE-2019-12219
HIGH8.8

An issue was discovered in libSDL2.a in Simple DirectMedia Layer (SDL) 2.0.9 when used in conjunction with libSDL2_image.a in SDL2_image 2.0.4. There is an invalid free error in the SDL function SDL_SetError_REAL at SDL_error.c.

libsdl / sdl2_image+1
Network
Published May 20, 2019
CVE-2019-7578
HIGH8.1

SDL (Simple DirectMedia Layer) through 1.2.15 and 2.x through 2.0.9 has a heap-based buffer over-read in InitIMA_ADPCM in audio/SDL_wave.c.

libsdl / simple_directmedia_layer+10
Network
Published Feb 7, 2019
CVE-2019-7636
HIGH8.1

SDL (Simple DirectMedia Layer) through 1.2.15 and 2.x through 2.0.9 has a heap-based buffer over-read in SDL_GetRGB in video/SDL_pixels.c.

libsdl / simple_directmedia_layer+11
Network
Published Feb 8, 2019
CVE-2019-7635
HIGH8.1

SDL (Simple DirectMedia Layer) through 1.2.15 and 2.x through 2.0.9 has a heap-based buffer over-read in Blit1to4 in video/SDL_blit_1.c.

libsdl / simple_directmedia_layer+14
Network
Published Feb 8, 2019
CVE-2019-13616
HIGH8.1

SDL (Simple DirectMedia Layer) through 1.2.15 and 2.x through 2.0.9 has a heap-based buffer over-read in BlitNtoN in video/SDL_blit_N.c when called from SDL_SoftBlit in video/SDL_blit.c.

libsdl / simple_directmedia_layer+22
Network
Published Jul 16, 2019
CVE-2020-14409
HIGH7.8

SDL (Simple DirectMedia Layer) through 2.0.12 has an Integer Overflow (and resultant SDL_memcpy heap corruption) in SDL_BlitCopy in video/SDL_blit_copy.c via a crafted .BMP file.

libsdl / simple_directmedia_layer+8
Local
Published Jan 19, 2021
CVE-2022-4743
HIGH7.5

A potential memory leak issue was discovered in SDL2 in GLES_CreateTexture() function in SDL_render_gles.c. The vulnerability allows an attacker to cause a denial of service attack. The vulnerability affects SDL2 v2.0.4 and above. SDL-1.x are not affected.

libsdl / simple_directmedia_layer+1
Network
Published Jan 12, 2023
CVE-2022-34568
HIGH7.5

SDL v1.2 was discovered to contain a use-after-free via the XFree function at /src/video/x11/SDL_x11yuv.c.

libsdl / simple_directmedia_layer
Network
Published Jul 28, 2022
CVE-2019-12216
MEDIUM6.5

An issue was discovered in libSDL2.a in Simple DirectMedia Layer (SDL) 2.0.9 when used in conjunction with libSDL2_image.a in SDL2_image 2.0.4. There is a heap-based buffer overflow in the SDL2_image function IMG_LoadPCX_RW at IMG_pcx.c.

libsdl / sdl2_image+6
Network
Published May 20, 2019
CVE-2019-12222
MEDIUM6.5

An issue was discovered in libSDL2.a in Simple DirectMedia Layer (SDL) 2.0.9. There is an out-of-bounds read in the function SDL_InvalidateMap at video/SDL_pixels.c.

libsdl / simple_directmedia_layer
Network
Published May 20, 2019