CVE-2022-30067
- EPSS 0.06%
- Published 17.05.2022 17:15:08
- Last modified 21.11.2024 07:02:09
GIMP 2.10.30 and 2.99.10 are vulnerable to Buffer Overflow. Through a crafted XCF file, the program will allocate for a huge amount of memory, resulting in insufficient memory or program crash.
CVE-2021-45463
- EPSS 1.39%
- Published 23.12.2021 06:15:06
- Last modified 21.11.2024 06:32:15
load_cache in GEGL before 0.4.34 allows shell expansion when a pathname in a constructed command line is not escaped or filtered. This is caused by use of the system library function for execution of the ImageMagick convert fallback in magick-load. N...
CVE-2018-12713
- EPSS 0.34%
- Published 24.06.2018 22:29:00
- Last modified 21.11.2024 03:45:43
GIMP through 2.10.2 makes g_get_tmp_dir calls to establish temporary filenames, which may result in a filename that already exists, as demonstrated by the gimp_write_and_read_file function in app/tests/test-xcf.c. This might be leveraged by attackers...
CVE-2017-17789
- EPSS 0.5%
- Published 20.12.2017 09:29:01
- Last modified 20.04.2025 01:37:25
In GIMP 2.8.22, there is a heap-based buffer overflow in read_channel_data in plug-ins/common/file-psp.c.
CVE-2017-17788
- EPSS 0.5%
- Published 20.12.2017 09:29:01
- Last modified 20.04.2025 01:37:25
In GIMP 2.8.22, there is a stack-based buffer over-read in xcf_load_stream in app/xcf/xcf.c when there is no '\0' character after the version string.
CVE-2017-17787
- EPSS 0.35%
- Published 20.12.2017 09:29:01
- Last modified 20.04.2025 01:37:25
In GIMP 2.8.22, there is a heap-based buffer over-read in read_creator_block in plug-ins/common/file-psp.c.
CVE-2017-17786
- EPSS 0.33%
- Published 20.12.2017 09:29:01
- Last modified 20.04.2025 01:37:25
In GIMP 2.8.22, there is a heap-based buffer over-read in ReadImage in plug-ins/common/file-tga.c (related to bgr2rgb.part.1) via an unexpected bits-per-pixel value for an RGBA image.
CVE-2017-17785
- EPSS 0.37%
- Published 20.12.2017 09:29:00
- Last modified 20.04.2025 01:37:25
In GIMP 2.8.22, there is a heap-based buffer overflow in the fli_read_brun function in plug-ins/file-fli/fli.c.
CVE-2017-17784
- EPSS 0.39%
- Published 20.12.2017 09:29:00
- Last modified 20.04.2025 01:37:25
In GIMP 2.8.22, there is a heap-based buffer over-read in load_image in plug-ins/common/file-gbr.c in the gbr import parser, related to mishandling of UTF-8 data.
CVE-2016-4994
- EPSS 0.64%
- Published 12.07.2016 19:59:05
- Last modified 12.04.2025 10:46:40
Use-after-free vulnerability in the xcf_load_image function in app/xcf/xcf-load.c in GIMP allows remote attackers to cause a denial of service (program crash) or possibly execute arbitrary code via a crafted XCF file.