CVEs (83)
CVE VENDORS PRODUCTS UPDATED PUBLISHED CVSS |
|---|
GIMP XWD File Parsing Integer Overflow Remote Code Execution Vulnerability. This vulnerability allows remote attackers to execute arbitrary code on affected installations of GIMP. User interaction is required to exploit...Show more |
GIMP PSP File Parsing Off-By-One Remote Code Execution Vulnerability. This vulnerability allows remote attackers to execute arbitrary code on affected installations of GIMP. User interaction is required to exploit this v...Show more |
GIMP PSP File Parsing Integer Overflow Remote Code Execution Vulnerability. This vulnerability allows remote attackers to execute arbitrary code on affected installations of GIMP. User interaction is required to exploit...Show more |
GIMP PSD File Parsing Heap-based Buffer Overflow Remote Code Execution Vulnerability. This vulnerability allows remote attackers to execute arbitrary code on affected installations of GIMP. User interaction is required t...Show more |
GIMP DDS File Parsing Heap-based Buffer Overflow Remote Code Execution Vulnerability. This vulnerability allows remote attackers to execute arbitrary code on affected installations of GIMP. User interaction is required t...Show more |
An issue in gimp_layer_invalidate_boundary of GNOME GIMP 2.10.30 allows attackers to trigger an unhandled exception via a crafted XCF file, causing a Denial of Service (DoS). |
GIMP 2.10.30 and 2.99.10 are vulnerable to Buffer Overflow. Through a crafted XCF file, the program will allocate for a huge amount of memory, resulting in insufficient memory or program crash. |
4Fedoraproject GeglGimp+1 more4Enterprise Linux FedoraGegl+1 moreJun 17, 2026 Dec 23, 2021 N/A· v4 7.8 HIGH· v3 6.8 MEDIUM· v2 load_cache in GEGL before 0.4.34 allows shell expansion when a pathname in a constructed command line is not escaped or filtered. This is caused by use of the system library function for execution of the ImageMagick conv...Show more |
GIMP through 2.10.2 makes g_get_tmp_dir calls to establish temporary filenames, which may result in a filename that already exists, as demonstrated by the gimp_write_and_read_file function in app/tests/test-xcf.c. This m...Show more |
3Canonical DebianGimp3Debian Linux GimpUbuntu LinuxMay 13, 2026 Dec 20, 2017 N/A· v4 7.8 HIGH· v3 6.8 MEDIUM· v2 In GIMP 2.8.22, there is a heap-based buffer overflow in read_channel_data in plug-ins/common/file-psp.c. |
3Canonical DebianGimp3Debian Linux GimpUbuntu LinuxMay 13, 2026 Dec 20, 2017 N/A· v4 5.5 MEDIUM· v3 4.3 MEDIUM· v2 In GIMP 2.8.22, there is a stack-based buffer over-read in xcf_load_stream in app/xcf/xcf.c when there is no '\0' character after the version string. |
3Canonical DebianGimp3Debian Linux GimpUbuntu LinuxMay 13, 2026 Dec 20, 2017 N/A· v4 7.8 HIGH· v3 6.8 MEDIUM· v2 In GIMP 2.8.22, there is a heap-based buffer over-read in read_creator_block in plug-ins/common/file-psp.c. |
3Canonical DebianGimp3Debian Linux GimpUbuntu LinuxMay 13, 2026 Dec 20, 2017 N/A· v4 7.8 HIGH· v3 6.8 MEDIUM· v2 In GIMP 2.8.22, there is a heap-based buffer over-read in ReadImage in plug-ins/common/file-tga.c (related to bgr2rgb.part.1) via an unexpected bits-per-pixel value for an RGBA image. |
3Canonical DebianGimp3Debian Linux GimpUbuntu LinuxMay 13, 2026 Dec 20, 2017 N/A· v4 7.8 HIGH· v3 6.8 MEDIUM· v2 In GIMP 2.8.22, there is a heap-based buffer overflow in the fli_read_brun function in plug-ins/file-fli/fli.c. |
3Canonical DebianGimp3Debian Linux GimpUbuntu LinuxMay 13, 2026 Dec 20, 2017 N/A· v4 7.8 HIGH· v3 6.8 MEDIUM· v2 In GIMP 2.8.22, there is a heap-based buffer over-read in load_image in plug-ins/common/file-gbr.c in the gbr import parser, related to mishandling of UTF-8 data. |
Use-after-free vulnerability in the xcf_load_image function in app/xcf/xcf-load.c in GIMP allows remote attackers to cause a denial of service (program crash) or possibly execute arbitrary code via a crafted XCF file. |
Heap-based buffer overflow in the read_xwd_cols function in file-xwd.c in the X Window Dump (XWD) plug-in in GIMP 2.6.9 and earlier allows remote attackers to cause a denial of service (crash) and possibly execute arbitr...Show more |
Integer overflow in the load_image function in file-xwd.c in the X Window Dump (XWD) plug-in in GIMP 2.6.9 and earlier, when used with glib before 2.24, allows remote attackers to cause a denial of service (crash) and po...Show more |
Multiple stack-based buffer overflows in file-xwd.c in the X Window Dump (XWD) plug-in in GIMP 2.8.2 allow remote attackers to cause a denial of service (crash) and possibly execute arbitrary code via a large (1) red, (2...Show more |
The scriptfu network server in GIMP 2.6 does not require authentication, which allows remote attackers to execute arbitrary commands via the python-fu-eval command. |