Sam2p is a focused image-conversion and compression utility whose modest vulnerability footprint belies a concerning severity profile: vulnerabilities affecting the product skew strongly toward critical-severity outcomes, reflecting the memory-safety hazards intrinsic to legacy image-processing codebases. The recurring weakness classes—out-of-bounds writes, buffer-boundary violations, integer overflows, array-index validation failures, and use-after-free conditions—are characteristic of unsafe C/C++ implementations handling untrusted binary image formats, where parser flaws can readily lead to code execution. Defenders should treat Sam2p as a supply-chain risk in environments where it processes untrusted image inputs; current severity, exploitation activity, and exposure counts are shown alongside this summary.
The number and severity of CVEs published that impact products developed by Sam2p Project over time
Signals from CVEs in this vendor scope (18 CVEs).
18 CVEs · Highest risk first
| CVE | Published | CVSS | Risk | KEV | Exploit |
|---|---|---|---|---|---|
CVE-2018-12601CRITICAL There is a heap-based buffer overflow in ReadImage in input-tga.ci in sam2p 0.49.4 that leads to a denial of service or possibly unspecified other impact. | Jun 20, 2018 | 9.8 | 31 | NO | NO |
CVE-2018-7553CRITICAL There is a heap-based buffer overflow in the pcxLoadRaster function of in_pcx.cpp in sam2p 0.49.4. A crafted input will lead to a denial of service or possibly unspecified other im | Feb 28, 2018 | 9.8 | 31 | NO | NO |
CVE-2018-7554CRITICAL There is an invalid free in ReadImage in input-bmp.ci that leads to a Segmentation fault in sam2p 0.49.4. A crafted input will lead to a denial of service or possibly unspecified o | Feb 28, 2018 | 9.8 | 30 | NO | NO |
CVE-2018-12578CRITICAL There is a heap-based buffer overflow in bmp_compress1_row in appliers.cpp in sam2p 0.49.4 that leads to a denial of service or possibly unspecified other impact. | Jun 19, 2018 | 9.8 | 29 | NO | NO |
CVE-2018-7552CRITICAL There is an invalid free in Mapping::DoubleHash::clear in mapping.cpp that leads to a Segmentation fault in sam2p 0.49.4. A crafted input will lead to a denial of service or possib | Feb 28, 2018 | 9.8 | 29 | NO | NO |
CVE-2018-7551CRITICAL There is an invalid free in MiniPS::delete0 in minips.cpp that leads to a Segmentation fault in sam2p 0.49.4. A crafted input will lead to a denial of service or possibly unspecifi | Feb 28, 2018 | 9.8 | 29 | NO | NO |
CVE-2017-14637CRITICAL In sam2p 0.49.3, there is an invalid read of size 2 in the parse_rgb function in in_xpm.cpp. However, this can also cause a write to an illegal address. | Sep 22, 2017 | 9.8 | 29 | NO | NO |
CVE-2017-14636CRITICAL Because of an integer overflow in sam2p 0.49.3, a loop executes 0xffffffff times, ending with an invalid read of size 1 in the Image::Indexed::sortPal function in image.cpp. Howeve | Sep 22, 2017 | 9.8 | 28 | NO | NO |
CVE-2017-14631CRITICAL In sam2p 0.49.3, the pcxLoadRaster function in in_pcx.cpp has an integer signedness error leading to a heap-based buffer overflow. | Sep 21, 2017 | 9.8 | 28 | NO | NO |
CVE-2017-14630CRITICAL In sam2p 0.49.3, an integer overflow exists in the pcxLoadImage24 function of the file in_pcx.cpp, leading to an invalid write operation. | Sep 21, 2017 | 9.8 | 28 | NO | NO |
Signals from CVEs in this vendor scope (18 CVEs).
An overview of all social media posts that mention a CVE ID that affects a product developed by Sam2p Project.
Media articles that mention a CVE ID that affects a product developed by Sam2p Project — matched by CVE ID, not by vendor name.