CVE-2017-14637: SAM2P Project SAM2P

Critical severity, CVSS 9.8. EPSS: 1.7% chance of exploitation in the next 30 days.

In sam2p 0.49.3, there is an invalid read of size 2 in the parse_rgb function in in_xpm.cpp. However, this can also cause a write to an illegal address.

Affected products

Published 2017-09-22. Last modified 2026-06-17.