rpm package
almalinux/gimp
pkg:rpm/almalinux/gimp
Vulnerabilities (38)
| CVE | Sev | CVSS | KEV | Affected versions | Fixed in | Published | Description |
|---|---|---|---|---|---|---|---|
| CVE-2025-14423 | Hig | 7.8 | < 2:3.0.4-1.el9_7.2 | 2:3.0.4-1.el9_7.2 | Dec 23, 2025 | GIMP LBM File Parsing Stack-based Buffer Overflow Remote Code Execution Vulnerability. This vulnerability allows remote attackers to execute arbitrary code on affected installations of GIMP. User interaction is required to exploit this vulnerability in that the target must visit | |
| CVE-2025-14422 | Hig | 7.8 | < 2:3.0.4-1.el9_7.2 | 2:3.0.4-1.el9_7.2 | Dec 23, 2025 | GIMP PNM File Parsing Integer Overflow Remote Code Execution Vulnerability. This vulnerability allows remote attackers to execute arbitrary code on affected installations of GIMP. User interaction is required to exploit this vulnerability in that the target must visit a malicious | |
| CVE-2025-10934 | Hig | 7.8 | < 2:3.0.4-1.el9_7.1 | 2:3.0.4-1.el9_7.1 | Oct 29, 2025 | GIMP XWD File Parsing Heap-based Buffer Overflow Remote Code Execution Vulnerability. This vulnerability allows remote attackers to execute arbitrary code on affected installations of GIMP. User interaction is required to exploit this vulnerability in that the target must visit a | |
| CVE-2025-10925 | Hig | 7.8 | < 2:3.0.4-1.el9_7.1 | 2:3.0.4-1.el9_7.1 | Oct 29, 2025 | GIMP ILBM File Parsing Stack-based Buffer Overflow Remote Code Execution Vulnerability. This vulnerability allows remote attackers to execute arbitrary code on affected installations of GIMP. User interaction is required to exploit this vulnerability in that the target must visit | |
| CVE-2025-10924 | Hig | 7.8 | < 2:3.0.4-1.el9_7.1 | 2:3.0.4-1.el9_7.1 | Oct 29, 2025 | GIMP FF File Parsing Integer Overflow Remote Code Execution Vulnerability. This vulnerability allows remote attackers to execute arbitrary code on affected installations of GIMP. User interaction is required to exploit this vulnerability in that the target must visit a malicious | |
| CVE-2025-10923 | Hig | 7.8 | < 2:3.0.4-1.el9_7.1 | 2:3.0.4-1.el9_7.1 | Oct 29, 2025 | GIMP WBMP File Parsing Integer Overflow Remote Code Execution Vulnerability. This vulnerability allows remote attackers to execute arbitrary code on affected installations of GIMP. User interaction is required to exploit this vulnerability in that the target must visit a maliciou | |
| CVE-2025-10922 | Hig | 7.8 | < 2:3.0.4-1.el9_7.1 | 2:3.0.4-1.el9_7.1 | Oct 29, 2025 | GIMP DCM File Parsing Heap-based Buffer Overflow Remote Code Execution Vulnerability. This vulnerability allows remote attackers to execute arbitrary code on affected installations of GIMP. User interaction is required to exploit this vulnerability in that the target must visit a | |
| CVE-2025-10921 | Hig | 7.8 | < 2:3.0.4-1.el9_7.1 | 2:3.0.4-1.el9_7.1 | Oct 29, 2025 | GIMP HDR File Parsing Heap-based Buffer Overflow Remote Code Execution Vulnerability. This vulnerability allows remote attackers to execute arbitrary code on affected installations of GIMP. User interaction is required to exploit this vulnerability in that the target must visit a | |
| CVE-2025-10920 | Hig | 7.8 | < 2:3.0.4-1.el9_7.1 | 2:3.0.4-1.el9_7.1 | Oct 29, 2025 | GIMP ICNS File Parsing Out-Of-Bounds Write Remote Code Execution Vulnerability. This vulnerability allows remote attackers to execute arbitrary code on affected installations of GIMP. User interaction is required to exploit this vulnerability in that the target must visit a malic | |
| CVE-2025-5473 | Hig | 8.8 | < 2:2.99.8-4.el9_6.2 | 2:2.99.8-4.el9_6.2 | Jun 6, 2025 | GIMP ICO File Parsing Integer Overflow Remote Code Execution Vulnerability. This vulnerability allows remote attackers to execute arbitrary code on affected installations of GIMP. User interaction is required to exploit this vulnerability in that the target must visit a malicious | |
| CVE-2025-48798 | Hig | 7.3 | < 2:2.99.8-4.el9_6.2 | 2:2.99.8-4.el9_6.2 | May 27, 2025 | A flaw was found in GIMP when processing XCF image files. If a user opens one of these image files that has been specially crafted by an attacker, GIMP can be tricked into making serious memory errors, potentially leading to crashes and causing use-after-free issues. | |
| CVE-2025-48797 | Hig | 7.3 | < 2:2.99.8-4.el9_6.2 | 2:2.99.8-4.el9_6.2 | May 27, 2025 | A flaw was found in GIMP when processing certain TGA image files. If a user opens one of these image files that has been specially crafted by an attacker, GIMP can be tricked into making serious memory errors, potentially leading to crashes and causing a heap buffer overflow. | |
| CVE-2023-44444 | Hig | 7.8 | < 2:2.99.8-4.el9_3 | 2:2.99.8-4.el9_3 | May 3, 2024 | GIMP PSP File Parsing Off-By-One Remote Code Execution Vulnerability. This vulnerability allows remote attackers to execute arbitrary code on affected installations of GIMP. User interaction is required to exploit this vulnerability in that the target must visit a malicious page | |
| CVE-2023-44443 | Hig | 7.8 | < 2:2.99.8-4.el9_3 | 2:2.99.8-4.el9_3 | May 3, 2024 | GIMP PSP File Parsing Integer Overflow Remote Code Execution Vulnerability. This vulnerability allows remote attackers to execute arbitrary code on affected installations of GIMP. User interaction is required to exploit this vulnerability in that the target must visit a malicious | |
| CVE-2023-44442 | Hig | 7.8 | < 2:2.99.8-4.el9_3 | 2:2.99.8-4.el9_3 | May 3, 2024 | GIMP PSD File Parsing Heap-based Buffer Overflow Remote Code Execution Vulnerability. This vulnerability allows remote attackers to execute arbitrary code on affected installations of GIMP. User interaction is required to exploit this vulnerability in that the target must visit a | |
| CVE-2023-44441 | Hig | 7.8 | < 2:2.99.8-4.el9_3 | 2:2.99.8-4.el9_3 | May 3, 2024 | GIMP DDS File Parsing Heap-based Buffer Overflow Remote Code Execution Vulnerability. This vulnerability allows remote attackers to execute arbitrary code on affected installations of GIMP. User interaction is required to exploit this vulnerability in that the target must visit a | |
| CVE-2022-32990 | Med | 5.5 | < 2:2.99.8-3.el9 | 2:2.99.8-3.el9 | Jun 24, 2022 | An issue in gimp_layer_invalidate_boundary of GNOME GIMP 2.10.30 allows attackers to trigger an unhandled exception via a crafted XCF file, causing a Denial of Service (DoS). | |
| CVE-2022-30067 | Med | 5.5 | < 2:2.99.8-3.el9 | 2:2.99.8-3.el9 | May 17, 2022 | GIMP 2.10.30 and 2.99.10 are vulnerable to Buffer Overflow. Through a crafted XCF file, the program will allocate for a huge amount of memory, resulting in insufficient memory or program crash. |
- affected < 2:3.0.4-1.el9_7.2fixed 2:3.0.4-1.el9_7.2
GIMP LBM File Parsing Stack-based Buffer Overflow Remote Code Execution Vulnerability. This vulnerability allows remote attackers to execute arbitrary code on affected installations of GIMP. User interaction is required to exploit this vulnerability in that the target must visit
- affected < 2:3.0.4-1.el9_7.2fixed 2:3.0.4-1.el9_7.2
GIMP PNM File Parsing Integer Overflow Remote Code Execution Vulnerability. This vulnerability allows remote attackers to execute arbitrary code on affected installations of GIMP. User interaction is required to exploit this vulnerability in that the target must visit a malicious
- affected < 2:3.0.4-1.el9_7.1fixed 2:3.0.4-1.el9_7.1
GIMP XWD File Parsing Heap-based Buffer Overflow Remote Code Execution Vulnerability. This vulnerability allows remote attackers to execute arbitrary code on affected installations of GIMP. User interaction is required to exploit this vulnerability in that the target must visit a
- affected < 2:3.0.4-1.el9_7.1fixed 2:3.0.4-1.el9_7.1
GIMP ILBM File Parsing Stack-based Buffer Overflow Remote Code Execution Vulnerability. This vulnerability allows remote attackers to execute arbitrary code on affected installations of GIMP. User interaction is required to exploit this vulnerability in that the target must visit
- affected < 2:3.0.4-1.el9_7.1fixed 2:3.0.4-1.el9_7.1
GIMP FF File Parsing Integer Overflow Remote Code Execution Vulnerability. This vulnerability allows remote attackers to execute arbitrary code on affected installations of GIMP. User interaction is required to exploit this vulnerability in that the target must visit a malicious
- affected < 2:3.0.4-1.el9_7.1fixed 2:3.0.4-1.el9_7.1
GIMP WBMP File Parsing Integer Overflow Remote Code Execution Vulnerability. This vulnerability allows remote attackers to execute arbitrary code on affected installations of GIMP. User interaction is required to exploit this vulnerability in that the target must visit a maliciou
- affected < 2:3.0.4-1.el9_7.1fixed 2:3.0.4-1.el9_7.1
GIMP DCM File Parsing Heap-based Buffer Overflow Remote Code Execution Vulnerability. This vulnerability allows remote attackers to execute arbitrary code on affected installations of GIMP. User interaction is required to exploit this vulnerability in that the target must visit a
- affected < 2:3.0.4-1.el9_7.1fixed 2:3.0.4-1.el9_7.1
GIMP HDR File Parsing Heap-based Buffer Overflow Remote Code Execution Vulnerability. This vulnerability allows remote attackers to execute arbitrary code on affected installations of GIMP. User interaction is required to exploit this vulnerability in that the target must visit a
- affected < 2:3.0.4-1.el9_7.1fixed 2:3.0.4-1.el9_7.1
GIMP ICNS File Parsing Out-Of-Bounds Write Remote Code Execution Vulnerability. This vulnerability allows remote attackers to execute arbitrary code on affected installations of GIMP. User interaction is required to exploit this vulnerability in that the target must visit a malic
- affected < 2:2.99.8-4.el9_6.2fixed 2:2.99.8-4.el9_6.2
GIMP ICO File Parsing Integer Overflow Remote Code Execution Vulnerability. This vulnerability allows remote attackers to execute arbitrary code on affected installations of GIMP. User interaction is required to exploit this vulnerability in that the target must visit a malicious
- affected < 2:2.99.8-4.el9_6.2fixed 2:2.99.8-4.el9_6.2
A flaw was found in GIMP when processing XCF image files. If a user opens one of these image files that has been specially crafted by an attacker, GIMP can be tricked into making serious memory errors, potentially leading to crashes and causing use-after-free issues.
- affected < 2:2.99.8-4.el9_6.2fixed 2:2.99.8-4.el9_6.2
A flaw was found in GIMP when processing certain TGA image files. If a user opens one of these image files that has been specially crafted by an attacker, GIMP can be tricked into making serious memory errors, potentially leading to crashes and causing a heap buffer overflow.
- affected < 2:2.99.8-4.el9_3fixed 2:2.99.8-4.el9_3
GIMP PSP File Parsing Off-By-One Remote Code Execution Vulnerability. This vulnerability allows remote attackers to execute arbitrary code on affected installations of GIMP. User interaction is required to exploit this vulnerability in that the target must visit a malicious page
- affected < 2:2.99.8-4.el9_3fixed 2:2.99.8-4.el9_3
GIMP PSP File Parsing Integer Overflow Remote Code Execution Vulnerability. This vulnerability allows remote attackers to execute arbitrary code on affected installations of GIMP. User interaction is required to exploit this vulnerability in that the target must visit a malicious
- affected < 2:2.99.8-4.el9_3fixed 2:2.99.8-4.el9_3
GIMP PSD File Parsing Heap-based Buffer Overflow Remote Code Execution Vulnerability. This vulnerability allows remote attackers to execute arbitrary code on affected installations of GIMP. User interaction is required to exploit this vulnerability in that the target must visit a
- affected < 2:2.99.8-4.el9_3fixed 2:2.99.8-4.el9_3
GIMP DDS File Parsing Heap-based Buffer Overflow Remote Code Execution Vulnerability. This vulnerability allows remote attackers to execute arbitrary code on affected installations of GIMP. User interaction is required to exploit this vulnerability in that the target must visit a
- affected < 2:2.99.8-3.el9fixed 2:2.99.8-3.el9
An issue in gimp_layer_invalidate_boundary of GNOME GIMP 2.10.30 allows attackers to trigger an unhandled exception via a crafted XCF file, causing a Denial of Service (DoS).
- affected < 2:2.99.8-3.el9fixed 2:2.99.8-3.el9
GIMP 2.10.30 and 2.99.10 are vulnerable to Buffer Overflow. Through a crafted XCF file, the program will allocate for a huge amount of memory, resulting in insufficient memory or program crash.
Page 2 of 2