VYPR

rpm package

opensuse/gimp&distro=openSUSE Tumbleweed

pkg:rpm/opensuse/gimp&distro=openSUSE%20Tumbleweed

Vulnerabilities (44)

  • CVE-2026-82330MedAug 28, 2026
    affected < 3.2.6-1.1fixed 3.2.6-1.1

    A flaw was found in the file-pvr plugin in GIMP. When processing a specially crafted PVR image file, the VQ (compressed) decoder does not properly perform memory bounds checking. This missing validation results in a heap out-of-bounds read. This issue can result in an application

  • CVE-2026-79902MedAug 26, 2026
    affected < 3.2.6-1.1fixed 3.2.6-1.1

    A flaw was found in the Seattle FilmWorks plugin in GIMP. When processing a specially crafted SFW image file, the plugin allocates a Variable-Length Array (VLA) on the stack without integer overflow checks, causing an unbounded stack allocation. This issue leads to an application

  • CVE-2026-80101MedAug 25, 2026
    affected < 3.2.6-1.1fixed 3.2.6-1.1

    A flaw was found in the file-xwd plugin in GIMP. When processing a specially crafted XWD image file, the plugin validates the image width and bytes-per-line parameters independently rather than ensuring their combined values are consistent with the allocated buffer size. This inc

  • CVE-2026-78475MedAug 24, 2026
    affected < 3.2.6-1.1fixed 3.2.6-1.1

    A flaw was found in the file-pix (ESM) plugin in GIMP. When processing a specially crafted PIX image file, the plugin allocates a Variable-Length Array (VLA) on the stack without proper bounds checking, causing an unbounded stack allocation followed by a 21-byte stack over-read.

  • CVE-2026-78465HigAug 24, 2026
    affected < 3.2.6-1.1fixed 3.2.6-1.1

    A flaw was found in the file-pcx plugin in GIMP, affecting 32-bit builds only. When processing a PCX image file, the plugin calculates memory allocation sizes based on the image dimensions and the number of color planes. If a crafted file sets the number of planes to 4 alongside

  • CVE-2026-18309HigAug 20, 2026
    affected < 3.2.6-1.1fixed 3.2.6-1.1

    GIMP APNG File Parsing Integer Overflow Remote Code Execution Vulnerability. This vulnerability allows remote attackers to execute arbitrary code on affected installations of GIMP. User interaction is required to exploit this vulnerability in that the target must visit a maliciou

  • CVE-2026-18306HigAug 20, 2026
    affected < 3.2.6-1.1fixed 3.2.6-1.1

    GIMP SGI File Parsing Integer Overflow Remote Code Execution Vulnerability. This vulnerability allows remote attackers to execute arbitrary code on affected installations of GIMP. User interaction is required to exploit this vulnerability in that the target must visit a malicious

  • CVE-2026-18302HigAug 20, 2026
    affected < 3.2.6-1.1fixed 3.2.6-1.1

    GIMP TIF File Parsing Heap-based Buffer Overflow Remote Code Execution Vulnerability. This vulnerability allows remote attackers to execute arbitrary code on affected installations of GIMP. User interaction is required to exploit this vulnerability in that the target must visit a

  • CVE-2026-18301HigAug 20, 2026
    affected < 3.2.6-1.1fixed 3.2.6-1.1

    GIMP PSD File Parsing Integer Overflow Remote Code Execution Vulnerability. This vulnerability allows remote attackers to execute arbitrary code on affected installations of GIMP. User interaction is required to exploit this vulnerability in that the target must visit a malicious

  • CVE-2026-59091HigAug 10, 2026
    affected < 3.2.4-4.1fixed 3.2.4-4.1

    A flaw was found in GIMP's file format plugins, including those for PSD and PAA files. A remote attacker could exploit these vulnerabilities by tricking a user into opening a specially crafted image file. This could lead to unexpected application behavior or other potential secur

  • CVE-2026-59090HigAug 10, 2026
    affected < 3.2.4-4.1fixed 3.2.4-4.1

    A flaw was found in GIMP's PSD file format plugin. This vulnerability, an unsigned integer underflow in the `block_rem` variable, occurs when a user opens a specially crafted `.psd` image file. The underflow leads to parser confusion, enabling an attacker to inject arbitrary data

  • CVE-2026-59088MedAug 10, 2026
    affected < 3.2.4-4.1fixed 3.2.4-4.1

    A flaw was found in GIMP. A signed integer overflow vulnerability exists in the `file-fli` plugin when processing FLI image files. This occurs due to an incorrect calculation during memory allocation for image buffers, where the multiplication of image width and height can exceed

  • CVE-2026-59087HigAug 10, 2026
    affected < 3.2.4-4.1fixed 3.2.4-4.1

    A flaw was found in the GIMP image manipulation program, specifically within its Seattle Filmworks file loader. A remote attacker could exploit this vulnerability by tricking a user into opening a specially crafted Seattle Filmworks file. This could lead to a heap overflow, allow

  • CVE-2026-66759HigJul 27, 2026
    affected < 3.2.4-3.1fixed 3.2.4-3.1

    A flaw was found in the file-icns plugin in GIMP. When applying a decompressed mask during ICNS image processing, the plugin reads from the mask data buffer without verifying if the cursor exceeds the allocated resource size. If a crafted file contains a truncated mask resource,

  • CVE-2026-66758HigJul 27, 2026
    affected < 3.2.4-3.1fixed 3.2.4-3.1

    A flaw was found in the file-fits plugin in GIMP. When processing a FITS image file, the plugin calculates memory allocation sizes using signed 32-bit integers for width and height. If a crafted file sets both values to large values, their product exceeds 2^31 and overflows, resu

  • CVE-2026-66757MedJul 27, 2026
    affected < 3.2.4-3.1fixed 3.2.4-3.1

    A flaw was found in the file-sgi plugin in GIMP. When processing an RLE-compressed SGI image, the plugin allocates memory for a row table. The image header dimensions (ysize and zsize) are read as 16-bit unsigned integers. If a crafted file sets both dimensions to their maximum v

  • CVE-2026-59089MedJul 6, 2026
    affected < 3.2.4-2.1fixed 3.2.4-2.1

    A flaw was found in GIMP. The PlayStation TIM loader, responsible for handling PlayStation image files, incorrectly calculates the size of the Color Look-Up Table (CLUT) due to an integer overflow. This occurs when multiplying num_colors and num_cluts, both 16-bit unsigned short

  • CVE-2026-58379HigJul 3, 2026
    affected < 3.2.4-2.1fixed 3.2.4-2.1

    A flaw was found in GIMP's Paint Shop Pro (PSP) file format parser. This heap buffer overflow vulnerability allows a remote attacker to cause arbitrary code execution or a denial of service (DoS) by tricking a user into opening a specially crafted PSP image file. The vulnerabilit

  • CVE-2026-2239LowMar 26, 2026
    affected < 3.0.8-2.1fixed 3.0.8-2.1

    A flaw was found in GIMP. Heap-buffer-overflow vulnerability exists in the fread_pascal_string function when processing a specially crafted PSD (Photoshop Document) file. This occurs because the buffer allocated for a Pascal string is not properly null-terminated, leading to an o

  • CVE-2025-15059HigJan 23, 2026
    affected < 3.0.6-4.1fixed 3.0.6-4.1

    GIMP PSP File Parsing Heap-based Buffer Overflow Remote Code Execution Vulnerability. This vulnerability allows remote attackers to execute arbitrary code on affected installations of GIMP. User interaction is required to exploit this vulnerability in that the target must visit a

Page 1 of 3