Sam2p
Vendor:
First CVE: Sep 21, 2017 · Active for 8 years
18
Total CVEs
More Total CVEs than 93% of tracked products
6.0
Avg CVEs / Year
Higher CVE frequency than 90% of tracked products
9.0
Avg CVSS
Higher Avg CVSS than 83% of tracked products
0.0%
KEV Rate
Bottom 1%
Trends Over Time
The number and severity of CVEs published that impact Sam2p over time
Volume of CVEsAvg CVSS Base Score
First CVE
Sep 21, 2017
8 years ago
Most Recent CVE
Jul 21, 2021
1,831 days ago
CVE Severity & Scoring
Sam2p18 CVEs
33%
61%
All CVEs352,713 CVEs
45%
40%
11%
MediumHighCritical
Attack Vector
Local4 (22.2%)
Network14 (77.8%)
Unknown0 (0.0%)
Physical0 (0.0%)
Adjacent Network0 (0.0%)
Attack Complexity
Low18 (100.0%)
High0 (0.0%)
Unknown0 (0.0%)
User Interaction
None12 (66.7%)
Unknown0 (0.0%)
Required6 (33.3%)
Privileges Required
Low0 (0.0%)
High0 (0.0%)
None18 (100.0%)
Unknown0 (0.0%)
Top CVEs
Signals from CVEs in this product scope (18 CVEs).
18 CVEs · Highest risk first
| CVE | Published | CVSS | Risk | KEV | Exploit |
|---|---|---|---|---|---|
CVE-2018-12601CRITICAL There is a heap-based buffer overflow in ReadImage in input-tga.ci in sam2p 0.49.4 that leads to a denial of service or possibly unspecified other impact. | Jun 20, 2018 | 9.8 | 31 | NO | NO |
CVE-2018-7553CRITICAL There is a heap-based buffer overflow in the pcxLoadRaster function of in_pcx.cpp in sam2p 0.49.4. A crafted input will lead to a denial of service or possibly unspecified other im | Feb 28, 2018 | 9.8 | 31 | NO | NO |
CVE-2018-7554CRITICAL There is an invalid free in ReadImage in input-bmp.ci that leads to a Segmentation fault in sam2p 0.49.4. A crafted input will lead to a denial of service or possibly unspecified o | Feb 28, 2018 | 9.8 | 30 | NO | NO |
CVE-2018-12578CRITICAL There is a heap-based buffer overflow in bmp_compress1_row in appliers.cpp in sam2p 0.49.4 that leads to a denial of service or possibly unspecified other impact. | Jun 19, 2018 | 9.8 | 29 | NO | NO |
CVE-2018-7552CRITICAL There is an invalid free in Mapping::DoubleHash::clear in mapping.cpp that leads to a Segmentation fault in sam2p 0.49.4. A crafted input will lead to a denial of service or possib | Feb 28, 2018 | 9.8 | 29 | NO | NO |
CVE-2018-7551CRITICAL There is an invalid free in MiniPS::delete0 in minips.cpp that leads to a Segmentation fault in sam2p 0.49.4. A crafted input will lead to a denial of service or possibly unspecifi | Feb 28, 2018 | 9.8 | 29 | NO | NO |
CVE-2017-14637CRITICAL In sam2p 0.49.3, there is an invalid read of size 2 in the parse_rgb function in in_xpm.cpp. However, this can also cause a write to an illegal address. | Sep 22, 2017 | 9.8 | 29 | NO | NO |
CVE-2017-14636CRITICAL Because of an integer overflow in sam2p 0.49.3, a loop executes 0xffffffff times, ending with an invalid read of size 1 in the Image::Indexed::sortPal function in image.cpp. Howeve | Sep 22, 2017 | 9.8 | 28 | NO | NO |
CVE-2017-14631CRITICAL In sam2p 0.49.3, the pcxLoadRaster function in in_pcx.cpp has an integer signedness error leading to a heap-based buffer overflow. | Sep 21, 2017 | 9.8 | 28 | NO | NO |
CVE-2017-14630CRITICAL In sam2p 0.49.3, an integer overflow exists in the pcxLoadImage24 function of the file in_pcx.cpp, leading to an invalid write operation. | Sep 21, 2017 | 9.8 | 28 | NO | NO |
Exploit Exposure
Signals from CVEs in this product scope (18 CVEs).
CISA KEV
0 CVEs
0.0% of CVEs· Bottom 1%
Metasploit
0 CVEs
0.0% of CVEs· Bottom 1%
Nuclei
0 CVEs
0.0% of CVEs· Bottom 1%
ExploitDB
0 CVEs
0.0% of CVEs· Bottom 1%
Social Chatter
Signals from CVEs in this product scope (18 CVEs).
Media Mentions
Signals from CVEs in this product scope (18 CVEs).
Top CNAs Publishing CVEs For Sam2p
Top CWEs
Versions
| Version | CVE Count | Avg CVSS | Avg EPSS | KEV | Exploits |
|---|---|---|---|---|---|
| 0.49.4 | 12 | 8.8 | 1.9% | 0 | 0 |
| 0.49.3 | 6 | 9.4 | 1.6% | 0 | 0 |