Vulnerabilidades
Resumen — últimos 7 días
Vulnerabilidades nuevas2847▼ 151 respecto a la semana anterior
Críticas / altas1373▲ 54 respecto a la semana anterior
Nueva explotación activa (KEV)5▼ 3 respecto a la semana anterior
Sin puntuar (sin CVSS)267▼ 257 respecto a la semana anterior
15 resultados, ordenados por fecha de publicación (más recientes primero)
| CVE | Estado | Severidad | EPSS | Explotación activa | Tecnologías afectadas | Publicada ▼ | Modificada | Descripción |
|---|---|---|---|---|---|---|---|---|
| Analizada | Media (6.1) | 0.30% | — | Libsdl SDL Image | 6/4/2026 | 24/7/2026 | SDL_image is a library to load images of various formats as SDL surfaces. In do_layer_surface() in src/IMG_xcf.c, pixel index values from decoded XCF tile data are used directly as colormap indices without validating them against the colormap size (cm_num). A crafted .xcf file with a small colormap and out-of-range… | |
| Modificada | Alta (8.8) | 3.5% | — | Libsdl SDL Image | 1/11/2018 | 17/6/2026 | An exploitable code execution vulnerability exists in the XCF image rendering functionality of SDL2_image-2.0.3. A specially crafted XCF image can cause a heap overflow, resulting in code execution. An attacker can display a specially crafted image to trigger this vulnerability. | |
| Modificada | Alta (7.1) | 1.5% | — | Libsdl SDL ImageDebian Linux | 24/4/2018 | 17/6/2026 | A buffer overflow vulnerability exists in the GIF image parsing functionality of SDL2_image-2.0.2. A specially crafted GIF image can lead to a buffer overflow on a global section. An attacker can display an image to trigger this vulnerability. | |
| Modificada | Alta (8.8) | 1.6% | — | Libsdl SDL ImageDebian Linux | 24/4/2018 | 17/6/2026 | A double-Free vulnerability exists in the XCF image rendering functionality of SDL2_image-2.0.2. A specially crafted XCF image can cause a Double-Free situation to occur. An attacker can display a specially crafted image to trigger this vulnerability. | |
| Modificada | Alta (8.8) | 2.4% | — | Libsdl SDL ImageDebian Linux | 24/4/2018 | 17/6/2026 | An exploitable code execution vulnerability exists in the XCF image rendering functionality of SDL2_image-2.0.2. A specially crafted XCF image can cause a heap overflow resulting in code execution. An attacker can display a specially crafted image to trigger this vulnerability. | |
| Modificada | Alta (8.8) | 2.4% | — | Libsdl SDL ImageDebian Linux | 24/4/2018 | 17/6/2026 | An exploitable code execution vulnerability exists in the BMP image rendering functionality of SDL2_image-2.0.2. A specially crafted BMP image can cause a stack overflow resulting in code execution. An attacker can display a specially crafted image to trigger this vulnerability. | |
| Modificada | Alta (8.8) | 2.6% | — | Libsdl SDL ImageDebian Linux | 24/4/2018 | 17/6/2026 | An exploitable code execution vulnerability exists in the ICO image rendering functionality of SDL2_image-2.0.2. A specially crafted ICO image can cause an integer overflow, cascading to a heap overflow resulting in code execution. An attacker can display a specially crafted image to trigger this vulnerability. | |
| Modificada | Alta (8.8) | 2.4% | — | Libsdl SDL ImageDebian Linux | 24/4/2018 | 17/6/2026 | An exploitable code execution vulnerability exists in the ILBM image rendering functionality of SDL2_image-2.0.2. A specially crafted ILBM image can cause a stack overflow resulting in code execution. An attacker can display a specially crafted image to trigger this vulnerability. | |
| Modificada | Alta (8.8) | 2.4% | — | Libsdl SDL ImageDebian Linux | 24/4/2018 | 17/6/2026 | An exploitable code execution vulnerability exists in the ILBM image rendering functionality of SDL2_image-2.0.2. A specially crafted ILBM image can cause a heap overflow resulting in code execution. An attacker can display a specially crafted image to trigger this vulnerability. | |
| Modificada | Alta (8.8) | 2.6% | — | Libsdl SDL ImageDebian LinuxStarwindsoftware Starwind Virtual SAN | 10/4/2018 | 17/6/2026 | An exploitable code execution vulnerability exists in the XCF image rendering functionality of Simple DirectMedia Layer SDL2_image-2.0.2. A specially crafted XCF image can cause an out-of-bounds write on the heap, resulting in code execution. An attacker can display a specially crafted image to trigger this… | |
| Modificada | Media (6.5) | 1.8% | — | Libsdl SDL ImageDebian Linux | 10/4/2018 | 17/6/2026 | An exploitable information vulnerability exists in the XCF image rendering functionality of Simple DirectMedia Layer SDL2_image-2.0.2. A specially crafted XCF image can cause an out-of-bounds read on the heap, resulting in information disclosure. An attacker can display a specially crafted image to trigger this… | |
| Modificada | Media (5.5) | 1.2% | — | Libsdl SDL ImageDebian LinuxStarwindsoftware Starwind Virtual SAN | 10/4/2018 | 17/6/2026 | An exploitable information disclosure vulnerability exists in the PCX image rendering functionality of Simple DirectMedia Layer SDL2_image-2.0.2. A specially crafted PCX image can cause an out-of-bounds read on the heap, resulting in information disclosure . An attacker can display a specially crafted image to trigger… | |
| Modificada | Alta (8.8) | 2.7% | — | Libsdl SDL ImageDebian Linux | 11/10/2017 | 17/6/2026 | An exploitable buffer overflow vulnerability exists in the XCF property handling functionality of SDL_image 2.0.1. A specially crafted xcf file can cause a stack-based buffer overflow resulting in potential code execution. An attacker can provide a specially crafted XCF file to trigger this vulnerability. | |
| Modificada | Alta (7.5) | 11% | — | SDL Image | 1/2/2008 | 16/6/2026 | Buffer overflow in the LWZReadByte function in IMG_gif.c in SDL_image before 1.2.7 allows remote attackers to cause a denial of service (application crash) or possibly execute arbitrary code via a crafted GIF file, a similar issue to CVE-2006-4484. NOTE: some of these details are obtained from third party information. | |
| Modificada | Alta (10) | 7.9% | — | SDL Image | 1/2/2008 | 16/6/2026 | Heap-based buffer overflow in the IMG_LoadLBM_RW function in IMG_lbm.c in SDL_image before 1.2.7 allows remote attackers to cause a denial of service (application crash) or possibly execute arbitrary code via a crafted IFF ILBM file. NOTE: some of these details are obtained from third party information. |