← Vulnerability feed

Vulnerability record · CVE-2019-12218 · published 20 May 2019

CVE-2019-12218: Libsdl sdl2 image null pointer dereference vulnerability

Libsdl · Sdl2 Image

An issue was discovered in libSDL2.a in Simple DirectMedia Layer (SDL) 2.0.9 when used in conjunction with libSDL2_image.a in SDL2_image 2.0.4. There is a NULL pointer dereference in the SDL2_image function IMG_LoadPCX_RW at IMG_pcx.c.

6.5 CVSS 3.0 Medium EPSS 2.0% · top 20.5% CWE-476 · NULL pointer dereference
6.5CVSS 3.0 base score, v2 4.3
2.0%EPSS exploitation probability, 30 days
NoNot in CISA KEV
2Affected product versions listed by NVD
16References, 2 tagged exploit
17 Jun 2026Last modified by NVD

Description

An issue was discovered in libSDL2.a in Simple DirectMedia Layer (SDL) 2.0.9 when used in conjunction with libSDL2_image.a in SDL2_image 2.0.4. There is a NULL pointer dereference in the SDL2_image function IMG_LoadPCX_RW at IMG_pcx.c.

CVSS:3.0/AV:N/AC:L/PR:N/UI:R/S:U/C:N/I:N/A:H

Affected products

2 vulnerable configurations from NVD's CPE data, grouped by vendor and product.

References

Track CVE-2019-12218 inside VULONE

Watch it alongside the ransomware crews, C2 infrastructure and forum chatter that reference it, query it through the API and pull it into your SIEM over TAXII.

Start free Open in platform

Related vulnerabilities

Same products first, then exploited flaws of the same weakness class.

9.8CVE-2019-14906Libsdl simple directmedia layer out-of-bounds read vulnerabilityA flaw was found with the RHSA-2019:3950 erratum, where it did not fix the CVE-2019-13616 SDL vulnerability. This issue only affects Red Hat SDL pack…EPSS 1.8%8.8CVE-2021-33657Libsdl simple directmedia layer out-of-bounds write vulnerabilityThere is a heap overflow problem in video/SDL_pixels.c in SDL (Simple DirectMedia Layer) 2.x to 2.0.18 versions. By crafting a malicious .BMP file, a…EPSS 2.1%8.8CVE-2019-5057Libsdl sdl2 image heap-based buffer overflow vulnerabilityAn exploitable code execution vulnerability exists in the PCX image-rendering functionality of SDL2_image 2.0.4. A specially crafted PCX image can ca…EPSS 3.6%8.8CVE-2019-5058Libsdl sdl2 image heap-based buffer overflow vulnerabilityAn exploitable code execution vulnerability exists in the XCF image rendering functionality of SDL2_image 2.0.4. A specially crafted XCF image can ca…EPSS 3.6%8.8CVE-2019-5059Libsdl sdl2 image integer overflow vulnerabilityAn exploitable code execution vulnerability exists in the XPM image rendering functionality of SDL2_image 2.0.4. A specially crafted XPM image can ca…EPSS 3.5%8.8CVE-2019-5060Libsdl sdl2 image integer overflow vulnerabilityAn exploitable code execution vulnerability exists in the XPM image rendering function of SDL2_image 2.0.4. A specially crafted XPM image can cause a…EPSS 4.0%8.8CVE-2019-5051Libsdl sdl2 image out-of-bounds write vulnerabilityAn exploitable heap-based buffer overflow vulnerability exists when loading a PCX file in SDL2_image, version 2.0.4. A missing error handler can lead…EPSS 3.9%8.8CVE-2019-5052Libsdl sdl2 image integer overflow vulnerabilityAn exploitable integer overflow vulnerability exists when loading a PCX file in SDL2_image 2.0.4. A specially crafted file can cause an integer overf…EPSS 4.5%

Source: NIST National Vulnerability Database (record CVE-2019-12218), CISA KEV, FIRST EPSS (scores of 2026-09-28). This page is refreshed as NVD updates the record.