Sammycage maintains a focused set of SVG rendering libraries, LunaSVG and PlutoSVG, that process untrusted vector graphics in web and embedded contexts. The vendor's vulnerabilities skew toward serious outcomes, concentrating in resource-handling and parsing logic where improper isolation, out-of-bounds reads, unbounded allocation, division-by-zero conditions, and integer overflow expose rendering engines to denial-of-service and memory-corruption risks. Current severity, exploitation status, and exposure counts are shown alongside this summary.
The number and severity of CVEs published that impact products developed by Sammycage over time
Signals from CVEs in this vendor scope (13 CVEs).
13 CVEs · Highest risk first
| CVE | Published | CVSS | Risk | KEV | Exploit |
|---|---|---|---|---|---|
CVE-2024-33768CRITICAL lunasvg v2.3.9 was discovered to contain a segmentation violation via the component composition_solid_source_over. | May 1, 2024 | 9.8 | 26 | NO | NO |
CVE-2023-44709CRITICAL PlutoSVG commit 336c02997277a1888e6ccbbbe674551a0582e5c4 and before was discovered to contain an integer overflow via the component plutosvg_load_from_memory. | Dec 14, 2023 | 9.8 | 24 | NO | NO |
CVE-2024-57722HIGH lunasvg v3.0.0 was discovered to contain a allocation-size-too-big bug via the component plutovg_surface_create. | Jan 23, 2025 | 7.5 | 21 | NO | NO |
CVE-2024-33763HIGH lunasvg v2.3.9 was discovered to contain a stack-buffer-underflow at lunasvg/source/layoutcontext.cpp. | May 1, 2024 | 7.5 | 21 | NO | NO |
CVE-2024-57723MEDIUM lunasvg v3.0.0 was discovered to contain a segmentation violation via the component composition_source_over. | Jan 23, 2025 | 6.5 | 19 | NO | NO |
CVE-2024-57721MEDIUM lunasvg v3.0.0 was discovered to contain a segmentation violation via the component plutovg_path_add_path. | Jan 23, 2025 | 6.5 | 19 | NO | NO |
CVE-2024-57720MEDIUM lunasvg v3.0.0 was discovered to contain a segmentation violation via the component plutovg_blend. | Jan 23, 2025 | 6.5 | 19 | NO | NO |
CVE-2024-55456MEDIUM lunasvg v3.0.1 was discovered to contain a segmentation violation via the component gray_find_cell | Feb 3, 2025 | 6.5 | 18 | NO | NO |
CVE-2024-57724MEDIUM lunasvg v3.0.0 was discovered to contain a segmentation violation via the component gray_record_cell. | Jan 23, 2025 | 6.5 | 18 | NO | NO |
CVE-2024-57719MEDIUM lunasvg v3.0.0 was discovered to contain a segmentation violation via the component blend_transformed_tiled_argb.isra.0. | Jan 23, 2025 | 6.5 | 17 | NO | NO |
Signals from CVEs in this vendor scope (13 CVEs).
An overview of all social media posts that mention a CVE ID that affects a product developed by Sammycage.
Media articles that mention a CVE ID that affects a product developed by Sammycage — matched by CVE ID, not by vendor name.