VYPR

rpm package

almalinux/gimp

pkg:rpm/almalinux/gimp

Vulnerabilities (47)

  • CVE-2026-18308HigAug 20, 2026
    affected < 2:3.0.4-4.el9_8.10fixed 2:3.0.4-4.el9_8.10

    GIMP TIF File Parsing Integer Overflow Remote Code Execution Vulnerability. This vulnerability allows remote attackers to execute arbitrary code on affected installations of GIMP. User interaction is required to exploit this vulnerability in that the target must visit a malicious

  • CVE-2026-18307HigAug 20, 2026
    affected < 2:3.0.4-4.el9_8.10fixed 2:3.0.4-4.el9_8.10

    GIMP TIF File Parsing Heap-based Buffer Overflow Remote Code Execution Vulnerability. This vulnerability allows remote attackers to execute arbitrary code on affected installations of GIMP. User interaction is required to exploit this vulnerability in that the target must visit a

  • CVE-2026-18306HigAug 20, 2026
    affected < 2:3.0.4-4.el9_8.10fixed 2:3.0.4-4.el9_8.10

    GIMP SGI File Parsing Integer Overflow Remote Code Execution Vulnerability. This vulnerability allows remote attackers to execute arbitrary code on affected installations of GIMP. User interaction is required to exploit this vulnerability in that the target must visit a malicious

  • CVE-2026-18305HigAug 20, 2026
    affected < 2:3.0.4-4.el9_8.10fixed 2:3.0.4-4.el9_8.10

    GIMP TIF File Parsing Integer Overflow Remote Code Execution Vulnerability. This vulnerability allows remote attackers to execute arbitrary code on affected installations of GIMP. User interaction is required to exploit this vulnerability in that the target must visit a malicious

  • CVE-2026-18304HigAug 20, 2026
    affected < 2:3.0.4-4.el9_8.10fixed 2:3.0.4-4.el9_8.10

    GIMP TIF File Parsing Integer Overflow Remote Code Execution Vulnerability. This vulnerability allows remote attackers to execute arbitrary code on affected installations of GIMP. User interaction is required to exploit this vulnerability in that the target must visit a malicious

  • CVE-2026-18303HigAug 20, 2026
    affected < 2:3.0.4-4.el9_8.10fixed 2:3.0.4-4.el9_8.10

    GIMP TIF File Parsing Stack-based Buffer Overflow Remote Code Execution Vulnerability. This vulnerability allows remote attackers to execute arbitrary code on affected installations of GIMP. User interaction is required to exploit this vulnerability in that the target must visit

  • CVE-2026-18302HigAug 20, 2026
    affected < 2:3.0.4-4.el9_8.10fixed 2:3.0.4-4.el9_8.10

    GIMP TIF File Parsing Heap-based Buffer Overflow Remote Code Execution Vulnerability. This vulnerability allows remote attackers to execute arbitrary code on affected installations of GIMP. User interaction is required to exploit this vulnerability in that the target must visit a

  • CVE-2026-18301HigAug 20, 2026
    affected < 2:3.0.4-4.el9_8.10fixed 2:3.0.4-4.el9_8.10

    GIMP PSD File Parsing Integer Overflow Remote Code Execution Vulnerability. This vulnerability allows remote attackers to execute arbitrary code on affected installations of GIMP. User interaction is required to exploit this vulnerability in that the target must visit a malicious

  • CVE-2026-59090HigAug 10, 2026
    affected < 2:3.0.4-4.el9_8.10fixed 2:3.0.4-4.el9_8.10

    A flaw was found in GIMP's PSD file format plugin. This vulnerability, an unsigned integer underflow in the `block_rem` variable, occurs when a user opens a specially crafted `.psd` image file. The underflow leads to parser confusion, enabling an attacker to inject arbitrary data

  • CVE-2026-42169HigAug 4, 2026
    affected < 2:3.0.4-4.el9_8.9fixed 2:3.0.4-4.el9_8.9

    A heap-buffer-overflow vulnerability exists in the APNG (Animated PNG) file loader of GIMP. This flaw occurs when the `fcTL` width exceeds the `IHDR` width, leading to pixel data being written past the end of a heap allocation. Additionally, a heap-based buffer overflow exists in

  • CVE-2026-66759HigJul 27, 2026
    affected < 2:3.0.4-4.el9_8.9fixed 2:3.0.4-4.el9_8.9

    A flaw was found in the file-icns plugin in GIMP. When applying a decompressed mask during ICNS image processing, the plugin reads from the mask data buffer without verifying if the cursor exceeds the allocated resource size. If a crafted file contains a truncated mask resource,

  • CVE-2026-66758HigJul 27, 2026
    affected < 2:3.0.4-4.el9_8.9fixed 2:3.0.4-4.el9_8.9

    A flaw was found in the file-fits plugin in GIMP. When processing a FITS image file, the plugin calculates memory allocation sizes using signed 32-bit integers for width and height. If a crafted file sets both values to large values, their product exceeds 2^31 and overflows, resu

  • CVE-2026-58384HigJul 7, 2026
    affected < 2:3.0.4-4.el9_8.7fixed 2:3.0.4-4.el9_8.7

    A flaw was found in GIMP's PSD parser. An integer overflow in read_RLE_channel() can cause an undersized heap allocation for the RLE row-length table, after which subsequent per-row writes corrupt heap memory. This could lead to memory corruption, potentially resulting in denial

  • CVE-2026-58380HigJul 6, 2026
    affected < 2:3.0.4-4.el9_8.7fixed 2:3.0.4-4.el9_8.7

    A flaw was found in GIMP's PNM file format parser. When parsing a specially crafted PNM file, the pnmscanner_gettoken() function writes a null terminator one byte past the end of a stack-allocated buffer due to an off-by-one error in the loop boundary check. This could lead to me

  • CVE-2026-58379HigJul 3, 2026
    affected < 2:3.0.4-4.el9_8.5fixed 2:3.0.4-4.el9_8.5

    A flaw was found in GIMP's Paint Shop Pro (PSP) file format parser. This heap buffer overflow vulnerability allows a remote attacker to cause arbitrary code execution or a denial of service (DoS) by tricking a user into opening a specially crafted PSP image file. The vulnerabilit

  • CVE-2026-4154HigApr 11, 2026
    affected < 2:3.0.4-1.el9_7.5fixed 2:3.0.4-1.el9_7.5

    GIMP XPM File Parsing Integer Overflow Remote Code Execution Vulnerability. This vulnerability allows remote attackers to execute arbitrary code on affected installations of GIMP. User interaction is required to exploit this vulnerability in that the target must visit a malicious

  • CVE-2026-4153HigApr 11, 2026
    affected < 2:3.0.4-1.el9_7.5fixed 2:3.0.4-1.el9_7.5

    GIMP PSP File Parsing Heap-based Buffer Overflow Remote Code Execution Vulnerability. This vulnerability allows remote attackers to execute arbitrary code on affected installations of GIMP. User interaction is required to exploit this vulnerability in that the target must visit a

  • CVE-2026-4152HigApr 11, 2026
    affected < 2:3.0.4-1.el9_7.5fixed 2:3.0.4-1.el9_7.5

    GIMP JP2 File Parsing Heap-based Buffer Overflow Remote Code Execution Vulnerability. This vulnerability allows remote attackers to execute arbitrary code on affected installations of GIMP. User interaction is required to exploit this vulnerability in that the target must visit a

  • CVE-2026-4151HigApr 11, 2026
    affected < 2:3.0.4-1.el9_7.5fixed 2:3.0.4-1.el9_7.5

    GIMP ANI File Parsing Integer Overflow Remote Code Execution Vulnerability. This vulnerability allows remote attackers to execute arbitrary code on affected installations of GIMP. User interaction is required to exploit this vulnerability in that the target must visit a malicious

  • CVE-2026-4150HigApr 11, 2026
    affected < 2:3.0.4-1.el9_7.5fixed 2:3.0.4-1.el9_7.5

    GIMP PSD File Parsing Integer Overflow Remote Code Execution Vulnerability. This vulnerability allows remote attackers to execute arbitrary code on affected installations of GIMP. User interaction is required to exploit this vulnerability in that the target must visit a malicious

Page 1 of 3