Debian Gdk-Pixbuf vulnerabilities
32 known vulnerabilities affecting debian/gdk-pixbuf.
Total CVEs
32
CISA KEV
0
Public exploits
0
Exploited in wild
0
Severity breakdown
HIGH14MEDIUM10LOW8
Vulnerabilities
Page 1 of 2
CVE-2021-20240P3HIGHCVSS 8.8fixed in gdk-pixbuf 2.42.2+dfsg-1 (bookworm)2021
CVE-2021-20240 [HIGH] CVE-2021-20240: gdk-pixbuf - A flaw was found in gdk-pixbuf in versions before 2.42.0. An integer wraparound ...
A flaw was found in gdk-pixbuf in versions before 2.42.0. An integer wraparound leading to an out of bounds write can occur when a crafted GIF image is loaded. An attacker may cause applications to crash or could potentially execute code on the victim system. The highest threat from this vulnerability is to data confidentiality and integrity as well as system ava
debian
CVE-2021-44648P3HIGHCVSS 8.8fixed in gdk-pixbuf 2.42.9+dfsg-1 (bookworm)2021
CVE-2021-44648 [HIGH] CVE-2021-44648: gdk-pixbuf - GNOME gdk-pixbuf 2.42.6 is vulnerable to a heap-buffer overflow vulnerability wh...
GNOME gdk-pixbuf 2.42.6 is vulnerable to a heap-buffer overflow vulnerability when decoding the lzw compressed stream of image data in GIF files with lzw minimum code size equals to 12.
Scope: local
bookworm: resolved (fixed in 2.42.9+dfsg-1)
bullseye: resolved (fixed in 2.42.2+dfsg-1+deb11u1)
forky: resolved (fixed in 2.42.9+dfsg-1)
sid: resolved (fixed in 2.42.
debian
CVE-2026-5201P3HIGHCVSS 7.5fixed in gdk-pixbuf 2.44.6+dfsg-1 (forky)2026
CVE-2026-5201 [HIGH] CVE-2026-5201: gdk-pixbuf - A flaw was found in the gdk-pixbuf library. This heap-based buffer overflow vuln...
A flaw was found in the gdk-pixbuf library. This heap-based buffer overflow vulnerability occurs in the JPEG image loader due to improper validation of color component counts when processing a specially crafted JPEG image. A remote attacker can exploit this flaw without user interaction, for example, via thumbnail generation. Successful exploitation leads to applic
debian
CVE-2025-7345P3HIGHCVSS 7.5fixed in gdk-pixbuf 2.42.10+dfsg-1+deb12u3 (bookworm)2025
CVE-2025-7345 [HIGH] CVE-2025-7345: gdk-pixbuf - A flaw exists in gdk‑pixbuf within the gdk_pixbuf__jpeg_image_load_increment fun...
A flaw exists in gdk‑pixbuf within the gdk_pixbuf__jpeg_image_load_increment function (io-jpeg.c) and in glib’s g_base64_encode_step (glib/gbase64.c). When processing maliciously crafted JPEG images, a heap buffer overflow can occur during Base64 encoding, allowing out-of-bounds reads from heap memory, potentially causing application crashes or arbitrary code execu
debian
CVE-2017-2862P3HIGHCVSS 7.8fixed in gdk-pixbuf 2.36.10-1 (bookworm)2017
CVE-2017-2862 [HIGH] CVE-2017-2862: gdk-pixbuf - An exploitable heap overflow vulnerability exists in the gdk_pixbuf__jpeg_image_...
An exploitable heap overflow vulnerability exists in the gdk_pixbuf__jpeg_image_load_increment functionality of Gdk-Pixbuf 2.36.6. A specially crafted jpeg file can cause a heap overflow resulting in remote code execution. An attacker can send a file or url to trigger this vulnerability.
Scope: local
bookworm: resolved (fixed in 2.36.10-1)
bullseye: resolved (fixed
debian
CVE-2017-1000422P3HIGHCVSS 8.8fixed in gdk-pixbuf 2.36.11-1 (bookworm)2017
CVE-2017-1000422 [HIGH] CVE-2017-1000422: gdk-pixbuf - Gnome gdk-pixbuf 2.36.8 and older is vulnerable to several integer overflow in t...
Gnome gdk-pixbuf 2.36.8 and older is vulnerable to several integer overflow in the gif_get_lzw function resulting in memory corruption and potential code execution
Scope: local
bookworm: resolved (fixed in 2.36.11-1)
bullseye: resolved (fixed in 2.36.11-1)
forky: resolved (fixed in 2.36.11-1)
sid: resolved (fixed in 2.36.11-1)
trixie: resolved (fixed in 2.36.
debian
CVE-2017-2870P3LOWCVSS 7.8fixed in gdk-pixbuf 2.36.10-1 (bookworm)2017
CVE-2017-2870 [HIGH] CVE-2017-2870: gdk-pixbuf - An exploitable integer overflow vulnerability exists in the tiff_image_parse fun...
An exploitable integer overflow vulnerability exists in the tiff_image_parse functionality of Gdk-Pixbuf 2.36.6 when compiled with Clang. A specially crafted tiff file can cause a heap-overflow resulting in remote code execution. An attacker can send a file or a URL to trigger this vulnerability.
Scope: local
bookworm: resolved (fixed in 2.36.10-1)
bullseye: resolv
debian
CVE-2015-4491P3MEDIUMCVSS 6.8fixed in gdk-pixbuf 2.31.7-1 (bookworm)2015
CVE-2015-4491 [MEDIUM] CVE-2015-4491: gdk-pixbuf - Integer overflow in the make_filter_table function in pixops/pixops.c in gdk-pix...
Integer overflow in the make_filter_table function in pixops/pixops.c in gdk-pixbuf before 2.31.5, as used in Mozilla Firefox before 40.0 and Firefox ESR 38.x before 38.2 on Linux, Google Chrome on Linux, and other products, allows remote attackers to execute arbitrary code or cause a denial of service (heap-based buffer overflow and application crash) via crafte
debian
CVE-2015-7552P3HIGHCVSS 7.8fixed in gdk-pixbuf 2.32.0-1 (bookworm)2015
CVE-2015-7552 [HIGH] CVE-2015-7552: gdk-pixbuf - Heap-based buffer overflow in the gdk_pixbuf_flip function in gdk-pixbuf-scale.c...
Heap-based buffer overflow in the gdk_pixbuf_flip function in gdk-pixbuf-scale.c in gdk-pixbuf 2.30.x allows remote attackers to cause a denial of service or possibly execute arbitrary code via a crafted BMP file.
Scope: local
bookworm: resolved (fixed in 2.32.0-1)
bullseye: resolved (fixed in 2.32.0-1)
forky: resolved (fixed in 2.32.0-1)
sid: resolved (fixed in 2.
debian
CVE-2004-0782P3HIGHCVSS 7.5fixed in gdk-pixbuf 0.22.0-7 (bookworm)2004
CVE-2004-0782 [HIGH] CVE-2004-0782: gdk-pixbuf - Integer overflow in pixbuf_create_from_xpm (io-xpm.c) in the XPM image decoder f...
Integer overflow in pixbuf_create_from_xpm (io-xpm.c) in the XPM image decoder for gtk+ 2.4.4 (gtk2) and earlier, and gdk-pixbuf before 0.22, allows remote attackers to execute arbitrary code via certain n_col and cpp values that enable a heap-based buffer overflow. NOTE: this identifier is ONLY for gtk+. It was incorrectly referenced in an advisory for a different
debian
CVE-2016-6352P3HIGHCVSS 7.5fixed in gdk-pixbuf 2.35.4-1 (bookworm)2016
CVE-2016-6352 [HIGH] CVE-2016-6352: gdk-pixbuf - The OneLine32 function in io-ico.c in gdk-pixbuf before 2.35.3 allows remote att...
The OneLine32 function in io-ico.c in gdk-pixbuf before 2.35.3 allows remote attackers to cause a denial of service (out-of-bounds write and crash) via crafted dimensions in an ICO file.
Scope: local
bookworm: resolved (fixed in 2.35.4-1)
bullseye: resolved (fixed in 2.35.4-1)
forky: resolved (fixed in 2.35.4-1)
sid: resolved (fixed in 2.35.4-1)
trixie: resolved (f
debian
CVE-2021-46829P3HIGHCVSS 7.8fixed in gdk-pixbuf 2.42.8+dfsg-1 (bookworm)2021
CVE-2021-46829 [HIGH] CVE-2021-46829: gdk-pixbuf - GNOME GdkPixbuf (aka GDK-PixBuf) before 2.42.8 allows a heap-based buffer overfl...
GNOME GdkPixbuf (aka GDK-PixBuf) before 2.42.8 allows a heap-based buffer overflow when compositing or clearing frames in GIF files, as demonstrated by io-gif-animation.c composite_frame. This overflow is controllable and could be abused for code execution, especially on 32-bit systems.
Scope: local
bookworm: resolved (fixed in 2.42.8+dfsg-1)
bullseye: resolved (
debian
CVE-2022-48622P3HIGHCVSS 7.8fixed in gdk-pixbuf 2.42.10+dfsg-1+deb12u1 (bookworm)2022
CVE-2022-48622 [HIGH] CVE-2022-48622: gdk-pixbuf - In GNOME GdkPixbuf (aka gdk-pixbuf) through 2.42.10, the ANI (Windows animated c...
In GNOME GdkPixbuf (aka gdk-pixbuf) through 2.42.10, the ANI (Windows animated cursor) decoder encounters heap memory corruption (in ani_load_chunk in io-ani.c) when parsing chunks in a crafted .ani file. A crafted file could allow an attacker to overwrite heap metadata, leading to a denial of service or code execution attack. This occurs in gdk_pixbuf_set_option
debian
CVE-2015-7673P3MEDIUMCVSS 6.8fixed in gdk-pixbuf 2.32.0-1 (bookworm)2015
CVE-2015-7673 [MEDIUM] CVE-2015-7673: gdk-pixbuf - io-tga.c in gdk-pixbuf before 2.32.0 uses heap memory after its allocation faile...
io-tga.c in gdk-pixbuf before 2.32.0 uses heap memory after its allocation failed, which allows remote attackers to cause a denial of service (heap-based buffer overflow and application crash) and possibly execute arbitrary code via a crafted Truevision TGA (TARGA) file.
Scope: local
bookworm: resolved (fixed in 2.32.0-1)
bullseye: resolved (fixed in 2.32.0-1)
fo
debian
CVE-2015-8875P3HIGHCVSS 7.8fixed in gdk-pixbuf 2.34.0-1 (bookworm)2015
CVE-2015-8875 [HIGH] CVE-2015-8875: gdk-pixbuf - Multiple integer overflows in the (1) pixops_composite_nearest, (2) pixops_compo...
Multiple integer overflows in the (1) pixops_composite_nearest, (2) pixops_composite_color_nearest, and (3) pixops_process functions in pixops/pixops.c in gdk-pixbuf before 2.33.1 allow remote attackers to cause a denial of service (application crash) or possibly execute arbitrary code via a crafted image, which triggers a heap-based buffer overflow.
Scope: local
b
debian
CVE-2015-7674P4MEDIUMCVSS 6.8fixed in gdk-pixbuf 2.32.1-1 (bookworm)2015
CVE-2015-7674 [MEDIUM] CVE-2015-7674: gdk-pixbuf - Integer overflow in the pixops_scale_nearest function in pixops/pixops.c in gdk-...
Integer overflow in the pixops_scale_nearest function in pixops/pixops.c in gdk-pixbuf before 2.32.1 allows remote attackers to cause a denial of service (application crash) and possibly execute arbitrary code via a crafted GIF image file, which triggers a heap-based buffer overflow.
Scope: local
bookworm: resolved (fixed in 2.32.1-1)
bullseye: resolved (fixed in
debian
CVE-2005-3186P4MEDIUMCVSS 7.5fixed in gdk-pixbuf 0.22.0-11 (bookworm)2005
CVE-2005-3186 [HIGH] CVE-2005-3186: gdk-pixbuf - Integer overflow in the GTK+ gdk-pixbuf XPM image rendering library in GTK+ 2.4....
Integer overflow in the GTK+ gdk-pixbuf XPM image rendering library in GTK+ 2.4.0 allows attackers to execute arbitrary code via an XPM file with a number of colors that causes insufficient memory to be allocated, which leads to a heap-based buffer overflow.
Scope: local
bookworm: resolved (fixed in 0.22.0-11)
bullseye: resolved (fixed in 0.22.0-11)
forky: resolved
debian
CVE-2017-6311P4LOWCVSS 7.5fixed in gdk-pixbuf 2.36.10-1 (bookworm)2017
CVE-2017-6311 [HIGH] CVE-2017-6311: gdk-pixbuf - gdk-pixbuf-thumbnailer.c in gdk-pixbuf allows context-dependent attackers to cau...
gdk-pixbuf-thumbnailer.c in gdk-pixbuf allows context-dependent attackers to cause a denial of service (NULL pointer dereference and application crash) via vectors related to printing an error message.
Scope: local
bookworm: resolved (fixed in 2.36.10-1)
bullseye: resolved (fixed in 2.36.10-1)
forky: resolved (fixed in 2.36.10-1)
sid: resolved (fixed in 2.36.10-1)
debian
CVE-2017-12447P4HIGHCVSS 7.8fixed in gdk-pixbuf 2.34.0-1 (bookworm)2017
CVE-2017-12447 [HIGH] CVE-2017-12447: gdk-pixbuf - GdkPixBuf (aka gdk-pixbuf), possibly 2.32.2, as used by GNOME Nautilus 3.14.3 on...
GdkPixBuf (aka gdk-pixbuf), possibly 2.32.2, as used by GNOME Nautilus 3.14.3 on Ubuntu 16.04, allows attackers to cause a denial of service (stack corruption) or possibly have unspecified other impact via a crafted file folder.
Scope: local
bookworm: resolved (fixed in 2.34.0-1)
bullseye: resolved (fixed in 2.34.0-1)
forky: resolved (fixed in 2.34.0-1)
sid: reso
debian
CVE-2005-2976P4MEDIUMCVSS 7.5fixed in gdk-pixbuf 0.22.0-11 (bookworm)2005
CVE-2005-2976 [HIGH] CVE-2005-2976: gdk-pixbuf - Integer overflow in io-xpm.c in gdk-pixbuf 0.22.0 in GTK+ before 2.8.7 allows at...
Integer overflow in io-xpm.c in gdk-pixbuf 0.22.0 in GTK+ before 2.8.7 allows attackers to cause a denial of service (crash) or execute arbitrary code via an XPM file with large height, width, and colour values, a different vulnerability than CVE-2005-3186.
Scope: local
bookworm: resolved (fixed in 0.22.0-11)
bullseye: resolved (fixed in 0.22.0-11)
forky: resolved
debian
1 / 2Next →