rpm package
suse/gimp&distro=SUSE Linux Enterprise Workstation Extension 15 SP7
pkg:rpm/suse/gimp&distro=SUSE%20Linux%20Enterprise%20Workstation%20Extension%2015%20SP7
Vulnerabilities (21)
| CVE | Sev | CVSS | KEV | Affected versions | Fixed in | Published | Description |
|---|---|---|---|---|---|---|---|
| CVE-2026-4154 | Hig | 7.8 | < 2.10.30-150400.3.50.1 | 2.10.30-150400.3.50.1 | Apr 11, 2026 | GIMP XPM File Parsing Integer Overflow Remote Code Execution Vulnerability. This vulnerability allows remote attackers to execute arbitrary code on affected installations of GIMP. User interaction is required to exploit this vulnerability in that the target must visit a malicious | |
| CVE-2026-4153 | Hig | 7.8 | < 2.10.30-150400.3.50.1 | 2.10.30-150400.3.50.1 | Apr 11, 2026 | GIMP PSP File Parsing Heap-based Buffer Overflow Remote Code Execution Vulnerability. This vulnerability allows remote attackers to execute arbitrary code on affected installations of GIMP. User interaction is required to exploit this vulnerability in that the target must visit a | |
| CVE-2026-4150 | Hig | 7.8 | < 2.10.30-150400.3.50.1 | 2.10.30-150400.3.50.1 | Apr 11, 2026 | GIMP PSD File Parsing Integer Overflow Remote Code Execution Vulnerability. This vulnerability allows remote attackers to execute arbitrary code on affected installations of GIMP. User interaction is required to exploit this vulnerability in that the target must visit a malicious | |
| CVE-2026-2272 | Med | 4.3 | < 2.10.30-150400.3.44.1 | 2.10.30-150400.3.44.1 | Mar 26, 2026 | A flaw was found in GIMP. An integer overflow vulnerability exists when processing ICO image files, specifically in the `ico_read_info` and `ico_read_icon` functions. This issue arises because a size calculation for image buffers can wrap around due to a 32-bit integer evaluation | |
| CVE-2026-2271 | Low | 3.3 | < 2.10.30-150400.3.44.1 | 2.10.30-150400.3.44.1 | Mar 26, 2026 | A flaw was found in GIMP's PSP (Paint Shop Pro) file parser. A remote attacker could exploit an integer overflow vulnerability in the read_creator_block() function by providing a specially crafted PSP image file. This vulnerability occurs when a 32-bit length value from the file | |
| CVE-2026-2239 | Low | 2.8 | < 2.10.30-150400.3.44.1 | 2.10.30-150400.3.44.1 | Mar 26, 2026 | A flaw was found in GIMP. Heap-buffer-overflow vulnerability exists in the fread_pascal_string function when processing a specially crafted PSD (Photoshop Document) file. This occurs because the buffer allocated for a Pascal string is not properly null-terminated, leading to an o | |
| CVE-2026-2048 | — | < 2.10.30-150400.3.47.1 | 2.10.30-150400.3.47.1 | Feb 20, 2026 | GIMP XWD File Parsing Out-Of-Bounds Write Remote Code Execution Vulnerability. This vulnerability allows remote attackers to execute arbitrary code on affected installations of GIMP. User interaction is required to exploit this vulnerability in that the target must visit a malici | ||
| CVE-2026-2045 | — | < 2.10.30-150400.3.47.1 | 2.10.30-150400.3.47.1 | Feb 20, 2026 | GIMP XWD File Parsing Out-Of-Bounds Write Remote Code Execution Vulnerability. This vulnerability allows remote attackers to execute arbitrary code on affected installations of GIMP. User interaction is required to exploit this vulnerability in that the target must visit a malici | ||
| CVE-2026-2044 | — | < 2.10.30-150400.3.47.1 | 2.10.30-150400.3.47.1 | Feb 20, 2026 | GIMP PGM File Parsing Uninitialized Memory Remote Code Execution Vulnerability. This vulnerability allows remote attackers to execute arbitrary code on affected installations of GIMP. User interaction is required to exploit this vulnerability in that the target must visit a malic | ||
| CVE-2026-0797 | — | < 2.10.30-150400.3.41.1 | 2.10.30-150400.3.41.1 | Feb 20, 2026 | GIMP ICO File Parsing Heap-based Buffer Overflow Remote Code Execution Vulnerability. This vulnerability allows remote attackers to execute arbitrary code on affected installations of GIMP. User interaction is required to exploit this vulnerability in that the target must visit a | ||
| CVE-2025-15059 | — | < 2.10.30-150400.3.35.1 | 2.10.30-150400.3.35.1 | Jan 23, 2026 | GIMP PSP File Parsing Heap-based Buffer Overflow Remote Code Execution Vulnerability. This vulnerability allows remote attackers to execute arbitrary code on affected installations of GIMP. User interaction is required to exploit this vulnerability in that the target must visit a | ||
| CVE-2025-14425 | — | < 2.10.30-150400.3.38.1 | 2.10.30-150400.3.38.1 | Dec 23, 2025 | GIMP JP2 File Parsing Heap-based Buffer Overflow Remote Code Execution Vulnerability. This vulnerability allows remote attackers to execute arbitrary code on affected installations of GIMP. User interaction is required to exploit this vulnerability in that the target must visit a | ||
| CVE-2025-14422 | — | < 2.10.30-150400.3.38.1 | 2.10.30-150400.3.38.1 | Dec 23, 2025 | GIMP PNM File Parsing Integer Overflow Remote Code Execution Vulnerability. This vulnerability allows remote attackers to execute arbitrary code on affected installations of GIMP. User interaction is required to exploit this vulnerability in that the target must visit a malicious | ||
| CVE-2025-10934 | — | < 2.10.30-150400.3.29.1 | 2.10.30-150400.3.29.1 | Oct 29, 2025 | GIMP XWD File Parsing Heap-based Buffer Overflow Remote Code Execution Vulnerability. This vulnerability allows remote attackers to execute arbitrary code on affected installations of GIMP. User interaction is required to exploit this vulnerability in that the target must visit a | ||
| CVE-2025-10922 | — | < 2.10.30-150400.3.32.1 | 2.10.30-150400.3.32.1 | Oct 29, 2025 | GIMP DCM File Parsing Heap-based Buffer Overflow Remote Code Execution Vulnerability. This vulnerability allows remote attackers to execute arbitrary code on affected installations of GIMP. User interaction is required to exploit this vulnerability in that the target must visit a | ||
| CVE-2025-6035 | — | < 2.10.30-150400.3.23.1 | 2.10.30-150400.3.23.1 | Jun 13, 2025 | A flaw was found in GIMP. An integer overflow vulnerability exists in the GIMP "Despeckle" plug-in. The issue occurs due to unchecked multiplication of image dimensions, such as width, height, and bytes-per-pixel (img_bpp), which can result in allocating insufficient memory and | ||
| CVE-2025-5473 | — | < 2.10.30-150400.3.17.1 | 2.10.30-150400.3.17.1 | Jun 6, 2025 | GIMP ICO File Parsing Integer Overflow Remote Code Execution Vulnerability. This vulnerability allows remote attackers to execute arbitrary code on affected installations of GIMP. User interaction is required to exploit this vulnerability in that the target must visit a malicious | ||
| CVE-2025-48798 | Hig | 7.3 | < 2.10.30-150400.3.20.1 | 2.10.30-150400.3.20.1 | May 27, 2025 | A flaw was found in GIMP when processing XCF image files. If a user opens one of these image files that has been specially crafted by an attacker, GIMP can be tricked into making serious memory errors, potentially leading to crashes and causing use-after-free issues. | |
| CVE-2025-48797 | Hig | 7.3 | < 2.10.30-150400.3.20.1 | 2.10.30-150400.3.20.1 | May 27, 2025 | A flaw was found in GIMP when processing certain TGA image files. If a user opens one of these image files that has been specially crafted by an attacker, GIMP can be tricked into making serious memory errors, potentially leading to crashes and causing a heap buffer overflow. | |
| CVE-2025-2761 | — | < 2.10.30-150400.3.14.1 | 2.10.30-150400.3.14.1 | Apr 23, 2025 | GIMP FLI File Parsing Out-Of-Bounds Write Remote Code Execution Vulnerability. This vulnerability allows remote attackers to execute arbitrary code on affected installations of GIMP. User interaction is required to exploit this vulnerability in that the target must visit a malici |
- affected < 2.10.30-150400.3.50.1fixed 2.10.30-150400.3.50.1
GIMP XPM File Parsing Integer Overflow Remote Code Execution Vulnerability. This vulnerability allows remote attackers to execute arbitrary code on affected installations of GIMP. User interaction is required to exploit this vulnerability in that the target must visit a malicious
- affected < 2.10.30-150400.3.50.1fixed 2.10.30-150400.3.50.1
GIMP PSP File Parsing Heap-based Buffer Overflow Remote Code Execution Vulnerability. This vulnerability allows remote attackers to execute arbitrary code on affected installations of GIMP. User interaction is required to exploit this vulnerability in that the target must visit a
- affected < 2.10.30-150400.3.50.1fixed 2.10.30-150400.3.50.1
GIMP PSD File Parsing Integer Overflow Remote Code Execution Vulnerability. This vulnerability allows remote attackers to execute arbitrary code on affected installations of GIMP. User interaction is required to exploit this vulnerability in that the target must visit a malicious
- affected < 2.10.30-150400.3.44.1fixed 2.10.30-150400.3.44.1
A flaw was found in GIMP. An integer overflow vulnerability exists when processing ICO image files, specifically in the `ico_read_info` and `ico_read_icon` functions. This issue arises because a size calculation for image buffers can wrap around due to a 32-bit integer evaluation
- affected < 2.10.30-150400.3.44.1fixed 2.10.30-150400.3.44.1
A flaw was found in GIMP's PSP (Paint Shop Pro) file parser. A remote attacker could exploit an integer overflow vulnerability in the read_creator_block() function by providing a specially crafted PSP image file. This vulnerability occurs when a 32-bit length value from the file
- affected < 2.10.30-150400.3.44.1fixed 2.10.30-150400.3.44.1
A flaw was found in GIMP. Heap-buffer-overflow vulnerability exists in the fread_pascal_string function when processing a specially crafted PSD (Photoshop Document) file. This occurs because the buffer allocated for a Pascal string is not properly null-terminated, leading to an o
- CVE-2026-2048Feb 20, 2026affected < 2.10.30-150400.3.47.1fixed 2.10.30-150400.3.47.1
GIMP XWD File Parsing Out-Of-Bounds Write Remote Code Execution Vulnerability. This vulnerability allows remote attackers to execute arbitrary code on affected installations of GIMP. User interaction is required to exploit this vulnerability in that the target must visit a malici
- CVE-2026-2045Feb 20, 2026affected < 2.10.30-150400.3.47.1fixed 2.10.30-150400.3.47.1
GIMP XWD File Parsing Out-Of-Bounds Write Remote Code Execution Vulnerability. This vulnerability allows remote attackers to execute arbitrary code on affected installations of GIMP. User interaction is required to exploit this vulnerability in that the target must visit a malici
- CVE-2026-2044Feb 20, 2026affected < 2.10.30-150400.3.47.1fixed 2.10.30-150400.3.47.1
GIMP PGM File Parsing Uninitialized Memory Remote Code Execution Vulnerability. This vulnerability allows remote attackers to execute arbitrary code on affected installations of GIMP. User interaction is required to exploit this vulnerability in that the target must visit a malic
- CVE-2026-0797Feb 20, 2026affected < 2.10.30-150400.3.41.1fixed 2.10.30-150400.3.41.1
GIMP ICO File Parsing Heap-based Buffer Overflow Remote Code Execution Vulnerability. This vulnerability allows remote attackers to execute arbitrary code on affected installations of GIMP. User interaction is required to exploit this vulnerability in that the target must visit a
- CVE-2025-15059Jan 23, 2026affected < 2.10.30-150400.3.35.1fixed 2.10.30-150400.3.35.1
GIMP PSP File Parsing Heap-based Buffer Overflow Remote Code Execution Vulnerability. This vulnerability allows remote attackers to execute arbitrary code on affected installations of GIMP. User interaction is required to exploit this vulnerability in that the target must visit a
- CVE-2025-14425Dec 23, 2025affected < 2.10.30-150400.3.38.1fixed 2.10.30-150400.3.38.1
GIMP JP2 File Parsing Heap-based Buffer Overflow Remote Code Execution Vulnerability. This vulnerability allows remote attackers to execute arbitrary code on affected installations of GIMP. User interaction is required to exploit this vulnerability in that the target must visit a
- CVE-2025-14422Dec 23, 2025affected < 2.10.30-150400.3.38.1fixed 2.10.30-150400.3.38.1
GIMP PNM File Parsing Integer Overflow Remote Code Execution Vulnerability. This vulnerability allows remote attackers to execute arbitrary code on affected installations of GIMP. User interaction is required to exploit this vulnerability in that the target must visit a malicious
- CVE-2025-10934Oct 29, 2025affected < 2.10.30-150400.3.29.1fixed 2.10.30-150400.3.29.1
GIMP XWD File Parsing Heap-based Buffer Overflow Remote Code Execution Vulnerability. This vulnerability allows remote attackers to execute arbitrary code on affected installations of GIMP. User interaction is required to exploit this vulnerability in that the target must visit a
- CVE-2025-10922Oct 29, 2025affected < 2.10.30-150400.3.32.1fixed 2.10.30-150400.3.32.1
GIMP DCM File Parsing Heap-based Buffer Overflow Remote Code Execution Vulnerability. This vulnerability allows remote attackers to execute arbitrary code on affected installations of GIMP. User interaction is required to exploit this vulnerability in that the target must visit a
- CVE-2025-6035Jun 13, 2025affected < 2.10.30-150400.3.23.1fixed 2.10.30-150400.3.23.1
A flaw was found in GIMP. An integer overflow vulnerability exists in the GIMP "Despeckle" plug-in. The issue occurs due to unchecked multiplication of image dimensions, such as width, height, and bytes-per-pixel (img_bpp), which can result in allocating insufficient memory and
- CVE-2025-5473Jun 6, 2025affected < 2.10.30-150400.3.17.1fixed 2.10.30-150400.3.17.1
GIMP ICO File Parsing Integer Overflow Remote Code Execution Vulnerability. This vulnerability allows remote attackers to execute arbitrary code on affected installations of GIMP. User interaction is required to exploit this vulnerability in that the target must visit a malicious
- affected < 2.10.30-150400.3.20.1fixed 2.10.30-150400.3.20.1
A flaw was found in GIMP when processing XCF image files. If a user opens one of these image files that has been specially crafted by an attacker, GIMP can be tricked into making serious memory errors, potentially leading to crashes and causing use-after-free issues.
- affected < 2.10.30-150400.3.20.1fixed 2.10.30-150400.3.20.1
A flaw was found in GIMP when processing certain TGA image files. If a user opens one of these image files that has been specially crafted by an attacker, GIMP can be tricked into making serious memory errors, potentially leading to crashes and causing a heap buffer overflow.
- CVE-2025-2761Apr 23, 2025affected < 2.10.30-150400.3.14.1fixed 2.10.30-150400.3.14.1
GIMP FLI File Parsing Out-Of-Bounds Write Remote Code Execution Vulnerability. This vulnerability allows remote attackers to execute arbitrary code on affected installations of GIMP. User interaction is required to exploit this vulnerability in that the target must visit a malici
Page 1 of 2