VYPR

gimp

by Debian

Source repositories

CVEs (2)

  • CVE-2026-6695MedAug 3, 2026
    risk 0.00cvss 5.5epss 0.00

    A flaw was found in GIMP. A remote attacker could exploit this by tricking a user into opening a specially crafted PAA (Paint Shop Pro Array) image file. This vulnerability, a heap-based out-of-bounds write in the decode_lzss() function of the PAA file format plugin, allows data…

  • CVE-2026-6694MedAug 3, 2026
    risk 0.00cvss 5.5epss 0.00

    A flaw was found in GIMP's file-png plugin. A remote attacker can exploit this by crafting a malicious Animated Portable Network Graphics (APNG) image containing an oversized tRNS chunk. This can lead to a stack-based buffer overflow (CWE-121), causing the file-png plugin to…