Sam2P Project Sam2P vulnerabilities
18 known vulnerabilities affecting sam2p_project/sam2p.
Total CVEs
18
CISA KEV
0
Public exploits
0
Exploited in wild
0
Severity breakdown
CRITICAL11HIGH6MEDIUM1
Vulnerabilities
Page 1 of 1
CVE-2020-19491HIGHCVSS 7.8v0.49.42021-07-21
CVE-2020-19491 [HIGH] CWE-787 CVE-2020-19491: There is an invalid memory access bug in cgif.c that leads to a Segmentation fault in sam2p 0.49.4.
There is an invalid memory access bug in cgif.c that leads to a Segmentation fault in sam2p 0.49.4. A crafted input will lead to a denial of service or possibly unspecified other impact.
nvd
CVE-2020-19492HIGHCVSS 7.8v0.49.42021-07-21
CVE-2020-19492 [HIGH] CVE-2020-19492: There is a floating point exception in ReadImage that leads to a Segmentation fault in sam2p 0.49.4.
There is a floating point exception in ReadImage that leads to a Segmentation fault in sam2p 0.49.4. A crafted input will lead to a denial of service or possibly unspecified other impact.
nvd
CVE-2018-12601CRITICALCVSS 9.8v0.49.42018-06-20
CVE-2018-12601 [CRITICAL] CWE-787 CVE-2018-12601: There is a heap-based buffer overflow in ReadImage in input-tga.ci in sam2p 0.49.4 that leads to a d
There is a heap-based buffer overflow in ReadImage in input-tga.ci in sam2p 0.49.4 that leads to a denial of service or possibly unspecified other impact.
nvdosv
CVE-2018-12578CRITICALCVSS 9.8v0.49.42018-06-19
CVE-2018-12578 [CRITICAL] CWE-787 CVE-2018-12578: There is a heap-based buffer overflow in bmp_compress1_row in appliers.cpp in sam2p 0.49.4 that lead
There is a heap-based buffer overflow in bmp_compress1_row in appliers.cpp in sam2p 0.49.4 that leads to a denial of service or possibly unspecified other impact.
nvdosv
CVE-2018-11489HIGHCVSS 8.8v0.49.42018-05-26
CVE-2018-11489 [HIGH] CWE-129 CVE-2018-11489: The DGifDecompressLine function in dgif_lib.c in GIFLIB (possibly version 3.0.x), as later shipped i
The DGifDecompressLine function in dgif_lib.c in GIFLIB (possibly version 3.0.x), as later shipped in cgif.c in sam2p 0.49.4, has a heap-based buffer overflow because a certain CrntCode array index is not checked. This will lead to a denial of service or possibly unspecified other impact.
nvd
CVE-2018-11490HIGHCVSS 8.8v0.49.42018-05-26
CVE-2018-11490 [HIGH] CWE-129 CVE-2018-11490: The DGifDecompressLine function in dgif_lib.c in GIFLIB (possibly version 3.0.x), as later shipped i
The DGifDecompressLine function in dgif_lib.c in GIFLIB (possibly version 3.0.x), as later shipped in cgif.c in sam2p 0.49.4, has a heap-based buffer overflow because a certain "Private->RunningCode - 2" array index is not checked. This will lead to a denial of service or possibly unspecified other impact.
nvd
CVE-2018-7553CRITICALCVSS 9.8v0.49.42018-02-28
CVE-2018-7553 [CRITICAL] CWE-787 CVE-2018-7553: There is a heap-based buffer overflow in the pcxLoadRaster function of in_pcx.cpp in sam2p 0.49.4. A
There is a heap-based buffer overflow in the pcxLoadRaster function of in_pcx.cpp in sam2p 0.49.4. A crafted input will lead to a denial of service or possibly unspecified other impact.
nvdosv
CVE-2018-7552CRITICALCVSS 9.8v0.49.42018-02-28
CVE-2018-7552 [CRITICAL] CWE-119 CVE-2018-7552: There is an invalid free in Mapping::DoubleHash::clear in mapping.cpp that leads to a Segmentation f
There is an invalid free in Mapping::DoubleHash::clear in mapping.cpp that leads to a Segmentation fault in sam2p 0.49.4. A crafted input will lead to a denial of service or possibly unspecified other impact.
nvdosv
CVE-2018-7554CRITICALCVSS 9.8v0.49.42018-02-28
CVE-2018-7554 [CRITICAL] CWE-416 CVE-2018-7554: There is an invalid free in ReadImage in input-bmp.ci that leads to a Segmentation fault in sam2p 0.
There is an invalid free in ReadImage in input-bmp.ci that leads to a Segmentation fault in sam2p 0.49.4. A crafted input will lead to a denial of service or possibly unspecified other impact.
nvdosv
CVE-2018-7551CRITICALCVSS 9.8v0.49.42018-02-28
CVE-2018-7551 [CRITICAL] CWE-416 CVE-2018-7551: There is an invalid free in MiniPS::delete0 in minips.cpp that leads to a Segmentation fault in sam2
There is an invalid free in MiniPS::delete0 in minips.cpp that leads to a Segmentation fault in sam2p 0.49.4. A crafted input will lead to a denial of service or possibly unspecified other impact.
nvdosv
CVE-2018-7487HIGHCVSS 7.8v0.49.42018-02-26
CVE-2018-7487 [HIGH] CWE-787 CVE-2018-7487: There is a heap-based buffer overflow in the LoadPCX function of in_pcx.cpp in sam2p 0.49.4. A Craft
There is a heap-based buffer overflow in the LoadPCX function of in_pcx.cpp in sam2p 0.49.4. A Crafted input will lead to a denial of service or possibly unspecified other impact.
nvdosv
CVE-2017-16663MEDIUMCVSS 5.5v0.49.42017-11-08
CVE-2017-16663 [MEDIUM] CWE-190 CVE-2017-16663: In sam2p 0.49.4, there are integer overflows (with resultant heap-based buffer overflows) in input-b
In sam2p 0.49.4, there are integer overflows (with resultant heap-based buffer overflows) in input-bmp.ci in the function ReadImage, because "width * height" multiplications occur unsafely.
nvdosv
CVE-2017-14636CRITICALCVSS 9.8v0.49.32017-09-22
CVE-2017-14636 [CRITICAL] CWE-190 CVE-2017-14636: Because of an integer overflow in sam2p 0.49.3, a loop executes 0xffffffff times, ending with an inv
Because of an integer overflow in sam2p 0.49.3, a loop executes 0xffffffff times, ending with an invalid read of size 1 in the Image::Indexed::sortPal function in image.cpp. However, this also causes memory corruption because of an attempted write to the invalid d[0xfffffffe] array element.
nvdosv
CVE-2017-14637CRITICALCVSS 9.8v0.49.32017-09-22
CVE-2017-14637 [CRITICAL] CWE-119 CVE-2017-14637: In sam2p 0.49.3, there is an invalid read of size 2 in the parse_rgb function in in_xpm.cpp. However
In sam2p 0.49.3, there is an invalid read of size 2 in the parse_rgb function in in_xpm.cpp. However, this can also cause a write to an illegal address.
nvdosv
CVE-2017-14631CRITICALCVSS 9.8v0.49.32017-09-21
CVE-2017-14631 [CRITICAL] CWE-119 CVE-2017-14631: In sam2p 0.49.3, the pcxLoadRaster function in in_pcx.cpp has an integer signedness error leading to
In sam2p 0.49.3, the pcxLoadRaster function in in_pcx.cpp has an integer signedness error leading to a heap-based buffer overflow.
nvdosv
CVE-2017-14628CRITICALCVSS 9.8v0.49.32017-09-21
CVE-2017-14628 [CRITICAL] CWE-119 CVE-2017-14628: In sam2p 0.49.3, a heap-based buffer overflow exists in the pcxLoadImage24 function of the file in_p
In sam2p 0.49.3, a heap-based buffer overflow exists in the pcxLoadImage24 function of the file in_pcx.cpp.
nvdosv
CVE-2017-14630CRITICALCVSS 9.8v0.49.32017-09-21
CVE-2017-14630 [CRITICAL] CWE-190 CVE-2017-14630: In sam2p 0.49.3, an integer overflow exists in the pcxLoadImage24 function of the file in_pcx.cpp, l
In sam2p 0.49.3, an integer overflow exists in the pcxLoadImage24 function of the file in_pcx.cpp, leading to an invalid write operation.
nvdosv
CVE-2017-14629HIGHCVSS 7.5v0.49.32017-09-21
CVE-2017-14629 [HIGH] CWE-190 CVE-2017-14629: In sam2p 0.49.3, the in_xpm_reader function in in_xpm.cpp has an integer signedness error, leading t
In sam2p 0.49.3, the in_xpm_reader function in in_xpm.cpp has an integer signedness error, leading to a crash when writing to an out-of-bounds array element.
nvdosv