VYPR

rpm package

opensuse/gimp&distro=openSUSE Tumbleweed

pkg:rpm/opensuse/gimp&distro=openSUSE%20Tumbleweed

Vulnerabilities (31)

  • CVE-2026-66759HigJul 27, 2026
    affected < 3.2.4-3.1fixed 3.2.4-3.1

    A flaw was found in the file-icns plugin in GIMP. When applying a decompressed mask during ICNS image processing, the plugin reads from the mask data buffer without verifying if the cursor exceeds the allocated resource size. If a crafted file contains a truncated mask resource,

  • CVE-2026-66758HigJul 27, 2026
    affected < 3.2.4-3.1fixed 3.2.4-3.1

    A flaw was found in the file-fits plugin in GIMP. When processing a FITS image file, the plugin calculates memory allocation sizes using signed 32-bit integers for width and height. If a crafted file sets both values to large values, their product exceeds 2^31 and overflows, resu

  • CVE-2026-66757MedJul 27, 2026
    affected < 3.2.4-3.1fixed 3.2.4-3.1

    A flaw was found in the file-sgi plugin in GIMP. When processing an RLE-compressed SGI image, the plugin allocates memory for a row table. The image header dimensions (ysize and zsize) are read as 16-bit unsigned integers. If a crafted file sets both dimensions to their maximum v

  • CVE-2026-59089MedJul 6, 2026
    affected < 3.2.4-2.1fixed 3.2.4-2.1

    A flaw was found in GIMP. The PlayStation TIM loader, responsible for handling PlayStation image files, incorrectly calculates the size of the Color Look-Up Table (CLUT) due to an integer overflow. This occurs when multiplying num_colors and num_cluts, both 16-bit unsigned short

  • CVE-2026-58379HigJul 3, 2026
    affected < 3.2.4-2.1fixed 3.2.4-2.1

    A flaw was found in GIMP's Paint Shop Pro (PSP) file format parser. This heap buffer overflow vulnerability allows a remote attacker to cause arbitrary code execution or a denial of service (DoS) by tricking a user into opening a specially crafted PSP image file. The vulnerabilit

  • CVE-2026-2239LowMar 26, 2026
    affected < 3.0.8-2.1fixed 3.0.8-2.1

    A flaw was found in GIMP. Heap-buffer-overflow vulnerability exists in the fread_pascal_string function when processing a specially crafted PSD (Photoshop Document) file. This occurs because the buffer allocated for a Pascal string is not properly null-terminated, leading to an o

  • CVE-2025-15059HigJan 23, 2026
    affected < 3.0.6-4.1fixed 3.0.6-4.1

    GIMP PSP File Parsing Heap-based Buffer Overflow Remote Code Execution Vulnerability. This vulnerability allows remote attackers to execute arbitrary code on affected installations of GIMP. User interaction is required to exploit this vulnerability in that the target must visit a

  • CVE-2025-14425HigDec 23, 2025
    affected < 3.0.6-5.1fixed 3.0.6-5.1

    GIMP JP2 File Parsing Heap-based Buffer Overflow Remote Code Execution Vulnerability. This vulnerability allows remote attackers to execute arbitrary code on affected installations of GIMP. User interaction is required to exploit this vulnerability in that the target must visit a

  • CVE-2025-14424HigDec 23, 2025
    affected < 3.0.6-5.1fixed 3.0.6-5.1

    GIMP XCF File Parsing Use-After-Free Remote Code Execution Vulnerability. This vulnerability allows remote attackers to execute arbitrary code on affected installations of GIMP. User interaction is required to exploit this vulnerability in that the target must visit a malicious p

  • CVE-2025-14423HigDec 23, 2025
    affected < 3.0.6-5.1fixed 3.0.6-5.1

    GIMP LBM File Parsing Stack-based Buffer Overflow Remote Code Execution Vulnerability. This vulnerability allows remote attackers to execute arbitrary code on affected installations of GIMP. User interaction is required to exploit this vulnerability in that the target must visit

  • CVE-2025-14422HigDec 23, 2025
    affected < 3.0.6-5.1fixed 3.0.6-5.1

    GIMP PNM File Parsing Integer Overflow Remote Code Execution Vulnerability. This vulnerability allows remote attackers to execute arbitrary code on affected installations of GIMP. User interaction is required to exploit this vulnerability in that the target must visit a malicious

  • CVE-2025-10925HigOct 29, 2025
    affected < 3.0.4-4.1fixed 3.0.4-4.1

    GIMP ILBM File Parsing Stack-based Buffer Overflow Remote Code Execution Vulnerability. This vulnerability allows remote attackers to execute arbitrary code on affected installations of GIMP. User interaction is required to exploit this vulnerability in that the target must visit

  • CVE-2025-10924HigOct 29, 2025
    affected < 3.0.4-3.1fixed 3.0.4-3.1

    GIMP FF File Parsing Integer Overflow Remote Code Execution Vulnerability. This vulnerability allows remote attackers to execute arbitrary code on affected installations of GIMP. User interaction is required to exploit this vulnerability in that the target must visit a malicious

  • CVE-2025-10922HigOct 29, 2025
    affected < 3.0.4-4.1fixed 3.0.4-4.1

    GIMP DCM File Parsing Heap-based Buffer Overflow Remote Code Execution Vulnerability. This vulnerability allows remote attackers to execute arbitrary code on affected installations of GIMP. User interaction is required to exploit this vulnerability in that the target must visit a

  • CVE-2025-10920HigOct 29, 2025
    affected < 3.0.4-4.1fixed 3.0.4-4.1

    GIMP ICNS File Parsing Out-Of-Bounds Write Remote Code Execution Vulnerability. This vulnerability allows remote attackers to execute arbitrary code on affected installations of GIMP. User interaction is required to exploit this vulnerability in that the target must visit a malic

  • CVE-2025-2760HigApr 23, 2025
    affected < 3.0.4-2.1fixed 3.0.4-2.1

    GIMP XWD File Parsing Integer Overflow Remote Code Execution Vulnerability. This vulnerability allows remote attackers to execute arbitrary code on affected installations of GIMP. User interaction is required to exploit this vulnerability in that the target must visit a malicious

  • CVE-2023-44443HigMay 3, 2024
    affected < 2.10.38-4.1fixed 2.10.38-4.1

    GIMP PSP File Parsing Integer Overflow Remote Code Execution Vulnerability. This vulnerability allows remote attackers to execute arbitrary code on affected installations of GIMP. User interaction is required to exploit this vulnerability in that the target must visit a malicious

  • CVE-2022-32990MedJun 24, 2022
    affected < 2.10.38-4.1fixed 2.10.38-4.1

    An issue in gimp_layer_invalidate_boundary of GNOME GIMP 2.10.30 allows attackers to trigger an unhandled exception via a crafted XCF file, causing a Denial of Service (DoS).

  • CVE-2022-30067MedMay 17, 2022
    affected < 2.10.30-3.1fixed 2.10.30-3.1

    GIMP 2.10.30 and 2.99.10 are vulnerable to Buffer Overflow. Through a crafted XCF file, the program will allocate for a huge amount of memory, resulting in insufficient memory or program crash.

  • CVE-2016-4994HigJul 12, 2016
    affected < 2.8.18-1.4fixed 2.8.18-1.4

    Use-after-free vulnerability in the xcf_load_image function in app/xcf/xcf-load.c in GIMP allows remote attackers to cause a denial of service (program crash) or possibly execute arbitrary code via a crafted XCF file.

Page 1 of 2