VYPR

Gimp

by GIMP

Source repositories

CVEs (125)

  • CVE-2018-12713CriJun 24, 2018
    risk 0.59cvss 9.1epss 0.02

    GIMP through 2.10.2 makes g_get_tmp_dir calls to establish temporary filenames, which may result in a filename that already exists, as demonstrated by the gimp_write_and_read_file function in app/tests/test-xcf.c. This might be leveraged by attackers to overwrite files or read…

  • CVE-2025-5473HigJun 6, 2025
    risk 0.58cvss 8.8epss 0.23

    GIMP ICO File Parsing Integer Overflow Remote Code Execution Vulnerability. This vulnerability allows remote attackers to execute arbitrary code on affected installations of GIMP. User interaction is required to exploit this vulnerability in that the target must visit a…

  • CVE-2023-44443HigMay 3, 2024
    risk 0.58cvss 7.8epss 0.94

    GIMP PSP File Parsing Integer Overflow Remote Code Execution Vulnerability. This vulnerability allows remote attackers to execute arbitrary code on affected installations of GIMP. User interaction is required to exploit this vulnerability in that the target must visit a…

  • CVE-2026-2044HigFeb 20, 2026
    risk 0.57cvss 8.8epss 0.01

    GIMP PGM File Parsing Uninitialized Memory Remote Code Execution Vulnerability. This vulnerability allows remote attackers to execute arbitrary code on affected installations of GIMP. User interaction is required to exploit this vulnerability in that the target must visit a…

  • CVE-2026-0797HigFeb 20, 2026
    risk 0.57cvss 8.8epss 0.01

    GIMP ICO File Parsing Heap-based Buffer Overflow Remote Code Execution Vulnerability. This vulnerability allows remote attackers to execute arbitrary code on affected installations of GIMP. User interaction is required to exploit this vulnerability in that the target must visit…

  • CVE-2023-44442HigMay 3, 2024
    risk 0.56cvss 7.8epss 0.61

    GIMP PSD File Parsing Heap-based Buffer Overflow Remote Code Execution Vulnerability. This vulnerability allows remote attackers to execute arbitrary code on affected installations of GIMP. User interaction is required to exploit this vulnerability in that the target must visit…

  • CVE-2026-59090HigAug 10, 2026
    risk 0.55cvss 8.4epss 0.01

    A flaw was found in GIMP's PSD file format plugin. This vulnerability, an unsigned integer underflow in the `block_rem` variable, occurs when a user opens a specially crafted `.psd` image file. The underflow leads to parser confusion, enabling an attacker to inject arbitrary…

  • CVE-2023-44444HigMay 3, 2024
    risk 0.55cvss 7.8epss 0.56

    GIMP PSP File Parsing Off-By-One Remote Code Execution Vulnerability. This vulnerability allows remote attackers to execute arbitrary code on affected installations of GIMP. User interaction is required to exploit this vulnerability in that the target must visit a malicious page…

  • CVE-2023-44441HigMay 3, 2024
    risk 0.53cvss 7.8epss 0.27

    GIMP DDS File Parsing Heap-based Buffer Overflow Remote Code Execution Vulnerability. This vulnerability allows remote attackers to execute arbitrary code on affected installations of GIMP. User interaction is required to exploit this vulnerability in that the target must visit…

  • CVE-2026-97185HigSep 24, 2026
    risk 0.51cvss 7.8epss 0.00

    A flaw was found in GIMP. When processing a specially crafted GIMPressionist preset file, the plug-in does not properly validate vector indices before writing into fixed-size arrays. This can lead to an out-of-bounds write, corrupting memory. An attacker could exploit this by…

  • CVE-2026-96543impSep 19, 2026
    risk 0.51cvss 7.8epss —

    gimp: gimp: out-of-bounds heap write when loading non-square PVR images

  • CVE-2026-92248HigSep 15, 2026
    risk 0.51cvss 7.8epss 0.00

    A flaw was found in the file-psd plugin in GIMP. When generating a thumbnail preview for a specially crafted PSD (Photoshop Document) image file, an integer overflow occurs during the multiplication of values from an embedded JPEG header. This leads to an undersized heap…

  • CVE-2026-90947HigSep 14, 2026
    risk 0.51cvss 7.8epss 0.00

    A flaw was found in GIMP. When processing a specially crafted lighting preset file, the Lighting Effects filter does not properly validate the number of light sources. This can lead to an out-of-bounds write, corrupting memory. An attacker could exploit this by convincing a user…

  • CVE-2026-90949HigSep 14, 2026
    risk 0.51cvss 7.8epss 0.00

    A flaw was found in GIMP's PSP (Paint Shop Pro) file loader. When processing a compressed selection channel, a heap-based buffer overflow can occur due to a mismatch between the allocated buffer size and the amount of data decompressed. A remote attacker could exploit this…

  • CVE-2026-90948HigSep 14, 2026
    risk 0.51cvss 7.8epss 0.00

    A flaw was found in GIMP's ICO file loader. When processing an ICO file containing an embedded PNG image, an integer overflow can occur during the calculation of the required buffer size. This leads to an undersized buffer being allocated, causing a heap-based buffer overflow…

  • CVE-2026-18308HigAug 20, 2026
    risk 0.51cvss 7.8epss 0.00

    GIMP TIF File Parsing Integer Overflow Remote Code Execution Vulnerability. This vulnerability allows remote attackers to execute arbitrary code on affected installations of GIMP. User interaction is required to exploit this vulnerability in that the target must visit a…

  • CVE-2026-18307HigAug 20, 2026
    risk 0.51cvss 7.8epss 0.00

    GIMP TIF File Parsing Heap-based Buffer Overflow Remote Code Execution Vulnerability. This vulnerability allows remote attackers to execute arbitrary code on affected installations of GIMP. User interaction is required to exploit this vulnerability in that the target must visit…

  • CVE-2026-18306HigAug 20, 2026
    risk 0.51cvss 7.8epss 0.00

    GIMP SGI File Parsing Integer Overflow Remote Code Execution Vulnerability. This vulnerability allows remote attackers to execute arbitrary code on affected installations of GIMP. User interaction is required to exploit this vulnerability in that the target must visit a…

  • CVE-2026-18305HigAug 20, 2026
    risk 0.51cvss 7.8epss 0.00

    GIMP TIF File Parsing Integer Overflow Remote Code Execution Vulnerability. This vulnerability allows remote attackers to execute arbitrary code on affected installations of GIMP. User interaction is required to exploit this vulnerability in that the target must visit a…

  • CVE-2026-18304HigAug 20, 2026
    risk 0.51cvss 7.8epss 0.00

    GIMP TIF File Parsing Integer Overflow Remote Code Execution Vulnerability. This vulnerability allows remote attackers to execute arbitrary code on affected installations of GIMP. User interaction is required to exploit this vulnerability in that the target must visit a…

Page 1 of 7