Predictive Vulnerability Intelligence.

Product

  • Product
  • Pricing
  • Documentation

Company

  • About
  • Partnerships
  • Blog
  • Support

Legal

  • Terms
  • Privacy
  • Data Licensing

© 2026 FAUCET Technologies LLC. All rights reserved.

Sam2p Project

First CVE: Sep 21, 2017Active for: 9 yearsTotal CVEs: 18
55.4
VTI Score
TOP TARGET

Sam2p is a focused image-conversion and compression utility whose modest vulnerability footprint belies a concerning severity profile: vulnerabilities affecting the product skew strongly toward critical-severity outcomes, reflecting the memory-safety hazards intrinsic to legacy image-processing codebases. The recurring weakness classes—out-of-bounds writes, buffer-boundary violations, integer overflows, array-index validation failures, and use-after-free conditions—are characteristic of unsafe C/C++ implementations handling untrusted binary image formats, where parser flaws can readily lead to code execution. Defenders should treat Sam2p as a supply-chain risk in environments where it processes untrusted image inputs; current severity, exploitation activity, and exposure counts are shown alongside this summary.

FAUCET AI Generated
18
Total CVEs
More Total CVEs than 95% of tracked vendors
6.0
Avg CVEs / Product / Year
More Avg CVEs / Product / Year than 98% of tracked vendors
9.0
Avg CVSS Score
Higher Avg CVSS Score than 87% of tracked vendors
0.0%
In CISA KEV
Bottom 1%

Trends Over Time

The number and severity of CVEs published that impact products developed by Sam2p Project over time

Volume of CVEsAvg CVSS Base Score
First CVE
Sep 21, 2017
8 years ago
Most Recent CVE
Jul 21, 2021
1,829 days ago

Products(1 total)

Top CVEs

Signals from CVEs in this vendor scope (18 CVEs).

18 CVEs · Highest risk first

CVEPublishedCVSSRiskKEVExploit
CVE-2018-12601CRITICAL
There is a heap-based buffer overflow in ReadImage in input-tga.ci in sam2p 0.49.4 that leads to a denial of service or possibly unspecified other impact.
Jun 20, 20189.831NONO
CVE-2018-7553CRITICAL
There is a heap-based buffer overflow in the pcxLoadRaster function of in_pcx.cpp in sam2p 0.49.4. A crafted input will lead to a denial of service or possibly unspecified other im
Feb 28, 20189.831NONO
CVE-2018-7554CRITICAL
There is an invalid free in ReadImage in input-bmp.ci that leads to a Segmentation fault in sam2p 0.49.4. A crafted input will lead to a denial of service or possibly unspecified o
Feb 28, 20189.830NONO
CVE-2018-12578CRITICAL
There is a heap-based buffer overflow in bmp_compress1_row in appliers.cpp in sam2p 0.49.4 that leads to a denial of service or possibly unspecified other impact.
Jun 19, 20189.829NONO
CVE-2018-7552CRITICAL
There is an invalid free in Mapping::DoubleHash::clear in mapping.cpp that leads to a Segmentation fault in sam2p 0.49.4. A crafted input will lead to a denial of service or possib
Feb 28, 20189.829NONO
CVE-2018-7551CRITICAL
There is an invalid free in MiniPS::delete0 in minips.cpp that leads to a Segmentation fault in sam2p 0.49.4. A crafted input will lead to a denial of service or possibly unspecifi
Feb 28, 20189.829NONO
CVE-2017-14637CRITICAL
In sam2p 0.49.3, there is an invalid read of size 2 in the parse_rgb function in in_xpm.cpp. However, this can also cause a write to an illegal address.
Sep 22, 20179.829NONO
CVE-2017-14636CRITICAL
Because of an integer overflow in sam2p 0.49.3, a loop executes 0xffffffff times, ending with an invalid read of size 1 in the Image::Indexed::sortPal function in image.cpp. Howeve
Sep 22, 20179.828NONO
CVE-2017-14631CRITICAL
In sam2p 0.49.3, the pcxLoadRaster function in in_pcx.cpp has an integer signedness error leading to a heap-based buffer overflow.
Sep 21, 20179.828NONO
CVE-2017-14630CRITICAL
In sam2p 0.49.3, an integer overflow exists in the pcxLoadImage24 function of the file in_pcx.cpp, leading to an invalid write operation.
Sep 21, 20179.828NONO
View all 18 CVEs →

CVE Severity & Scoring

Severity distribution of CVEs that affect this vendor's products18 CVEs
33%
61%
Severity distribution among all CVEs352,294 CVEs
45%
40%
11%
MediumHighCritical
Attack Vector
Local4 (22.2%)
Network14 (77.8%)
Unknown0 (0.0%)
Physical0 (0.0%)
Adjacent Network0 (0.0%)
Attack Complexity
Low18 (100.0%)
High0 (0.0%)
Unknown0 (0.0%)
User Interaction
None12 (66.7%)
Unknown0 (0.0%)
Required6 (33.3%)
Privileges Required
Low0 (0.0%)
High0 (0.0%)
None18 (100.0%)
Unknown0 (0.0%)

Exploit Exposure

Signals from CVEs in this vendor scope (18 CVEs).

CISA KEV
0 CVEs
0.0% of CVEs· Bottom 1%
Metasploit
0 CVEs
0.0% of CVEs· Bottom 1%
Nuclei
0 CVEs
0.0% of CVEs· Bottom 1%
ExploitDB
0 CVEs
0.0% of CVEs· Bottom 1%

Social Chatter

An overview of all social media posts that mention a CVE ID that affects a product developed by Sam2p Project.

Media Mentions

Media articles that mention a CVE ID that affects a product developed by Sam2p Project — matched by CVE ID, not by vendor name.

Top CNAs Publishing CVEs For Sam2p Project's Products

View all 1 CNAs →

Top CWEs