cbcvebase.

Debian Gdk-Pixbuf vulnerabilities

32 known vulnerabilities affecting debian/gdk-pixbuf.

Total CVEs
32
CISA KEV
0
Public exploits
0
Exploited in wild
0
Severity breakdown
HIGH14MEDIUM10LOW8

Vulnerabilities

Page 2 of 2
CVE-2005-0891P4HIGHCVSS 7.5fixed in gdk-pixbuf 0.22.0-7.1 (bookworm)2005
CVE-2005-0891 [HIGH] CVE-2005-0891: gdk-pixbuf - Double free vulnerability in gtk 2 (gtk2) before 2.2.4 allows remote attackers t... Double free vulnerability in gtk 2 (gtk2) before 2.2.4 allows remote attackers to cause a denial of service (crash) via a crafted BMP image. Scope: local bookworm: resolved (fixed in 0.22.0-7.1) bullseye: resolved (fixed in 0.22.0-7.1) forky: resolved (fixed in 0.22.0-7.1) sid: resolved (fixed in 0.22.0-7.1) trixie: resolved (fixed in 0.22.0-7.1)
debian
CVE-2017-6313P4LOWCVSS 7.1fixed in gdk-pixbuf 2.36.11-2 (bookworm)2017
CVE-2017-6313 [HIGH] CVE-2017-6313: gdk-pixbuf - Integer underflow in the load_resources function in io-icns.c in gdk-pixbuf allo... Integer underflow in the load_resources function in io-icns.c in gdk-pixbuf allows context-dependent attackers to cause a denial of service (out-of-bounds read and program crash) via a crafted image entry size in an ICO file. Scope: local bookworm: resolved (fixed in 2.36.11-2) bullseye: resolved (fixed in 2.36.11-2) forky: resolved (fixed in 2.36.11-2) sid: resolv
debian
CVE-2005-2975P4LOWCVSS 7.8fixed in gdk-pixbuf 0.22.0-11 (bookworm)2005
CVE-2005-2975 [HIGH] CVE-2005-2975: gdk-pixbuf - io-xpm.c in the gdk-pixbuf XPM image rendering library in GTK+ before 2.8.7 allo... io-xpm.c in the gdk-pixbuf XPM image rendering library in GTK+ before 2.8.7 allows attackers to cause a denial of service (infinite loop) via a crafted XPM image with a large number of colors. Scope: local bookworm: resolved (fixed in 0.22.0-11) bullseye: resolved (fixed in 0.22.0-11) forky: resolved (fixed in 0.22.0-11) sid: resolved (fixed in 0.22.0-11) trixie: r
debian
CVE-2012-2370P4LOWCVSS 5.0fixed in gdk-pixbuf 2.26.1-1 (bookworm)2012
CVE-2012-2370 [MEDIUM] CVE-2012-2370: gdk-pixbuf - Multiple integer overflows in the read_bitmap_file_data function in io-xbm.c in ... Multiple integer overflows in the read_bitmap_file_data function in io-xbm.c in gdk-pixbuf before 2.26.1 allow remote attackers to cause a denial of service (application crash) via a negative (1) height or (2) width in an XBM file, which triggers a heap-based buffer overflow. Scope: local bookworm: resolved (fixed in 2.26.1-1) bullseye: resolved (fixed in 2.26.1-
debian
CVE-2020-29385P4MEDIUMCVSS 5.5fixed in gdk-pixbuf 2.42.2+dfsg-1 (bookworm)2020
CVE-2020-29385 [MEDIUM] CVE-2020-29385: gdk-pixbuf - GNOME gdk-pixbuf (aka GdkPixbuf) before 2.42.2 allows a denial of service (infin... GNOME gdk-pixbuf (aka GdkPixbuf) before 2.42.2 allows a denial of service (infinite loop) in lzw.c in the function write_indexes. if c->self_code equals 10, self->code_table[10].extends will assign the value 11 to c. The next execution in the loop will assign self->code_table[11].extends to c, which will give the value of 10. This will make the loop run infinit
debian
CVE-2011-2485P4MEDIUMCVSS 4.3fixed in gdk-pixbuf 2.23.3-3.1 (bookworm)2011
CVE-2011-2485 [MEDIUM] CVE-2011-2485: gdk-pixbuf - The gdk_pixbuf__gif_image_load function in gdk-pixbuf/io-gif.c in gdk-pixbuf bef... The gdk_pixbuf__gif_image_load function in gdk-pixbuf/io-gif.c in gdk-pixbuf before 2.23.5 does not properly handle certain return values, which allows remote attackers to cause a denial of service (memory consumption) via a crafted GIF image file. Scope: local bookworm: resolved (fixed in 2.23.3-3.1) bullseye: resolved (fixed in 2.23.3-3.1) forky: resolved (fixe
debian
CVE-2017-6312P4LOWCVSS 5.5fixed in gdk-pixbuf 2.36.11-2 (bookworm)2017
CVE-2017-6312 [MEDIUM] CVE-2017-6312: gdk-pixbuf - Integer overflow in io-ico.c in gdk-pixbuf allows context-dependent attackers to... Integer overflow in io-ico.c in gdk-pixbuf allows context-dependent attackers to cause a denial of service (segmentation fault and application crash) via a crafted image entry offset in an ICO file, which triggers an out-of-bounds read, related to compiler optimizations. Scope: local bookworm: resolved (fixed in 2.36.11-2) bullseye: resolved (fixed in 2.36.11-2)
debian
CVE-2017-6314P4LOWCVSS 5.5fixed in gdk-pixbuf 2.36.11-2 (bookworm)2017
CVE-2017-6314 [MEDIUM] CVE-2017-6314: gdk-pixbuf - The make_available_at_least function in io-tiff.c in gdk-pixbuf allows context-d... The make_available_at_least function in io-tiff.c in gdk-pixbuf allows context-dependent attackers to cause a denial of service (infinite loop) via a large TIFF file. Scope: local bookworm: resolved (fixed in 2.36.11-2) bullseye: resolved (fixed in 2.36.11-2) forky: resolved (fixed in 2.36.11-2) sid: resolved (fixed in 2.36.11-2) trixie: resolved (fixed in 2.36.1
debian
CVE-2004-0753P4MEDIUMCVSS 5.0fixed in gdk-pixbuf 0.22.0-7 (bookworm)2004
CVE-2004-0753 [MEDIUM] CVE-2004-0753: gdk-pixbuf - The BMP image processor for (1) gdk-pixbuf before 0.22 and (2) gtk2 before 2.2.4... The BMP image processor for (1) gdk-pixbuf before 0.22 and (2) gtk2 before 2.2.4 allows remote attackers to cause a denial of service (infinite loop) via a crafted BMP file. Scope: local bookworm: resolved (fixed in 0.22.0-7) bullseye: resolved (fixed in 0.22.0-7) forky: resolved (fixed in 0.22.0-7) sid: resolved (fixed in 0.22.0-7) trixie: resolved (fixed in 0.2
debian
CVE-2004-0788P4MEDIUMCVSS 5.0fixed in gdk-pixbuf 0.22.0-7 (bookworm)2004
CVE-2004-0788 [MEDIUM] CVE-2004-0788: gdk-pixbuf - Integer overflow in the ICO image decoder for (1) gdk-pixbuf before 0.22 and (2)... Integer overflow in the ICO image decoder for (1) gdk-pixbuf before 0.22 and (2) gtk2 before 2.2.4 allows remote attackers to cause a denial of service (application crash) via a crafted ICO file. Scope: local bookworm: resolved (fixed in 0.22.0-7) bullseye: resolved (fixed in 0.22.0-7) forky: resolved (fixed in 0.22.0-7) sid: resolved (fixed in 0.22.0-7) trixie:
debian
CVE-2025-6199P4LOWCVSS 3.3fixed in gdk-pixbuf 2.42.10+dfsg-1+deb12u2 (bookworm)2025
CVE-2025-6199 [LOW] CVE-2025-6199: gdk-pixbuf - A flaw was found in the GIF parser of GdkPixbuf’s LZW decoder. When an invalid s... A flaw was found in the GIF parser of GdkPixbuf’s LZW decoder. When an invalid symbol is encountered during decompression, the decoder sets the reported output size to the full buffer length rather than the actual number of written bytes. This logic error results in uninitialized sections of the buffer being included in the output, potentially leaking arbitrary memo
debian
CVE-2004-0111P4MEDIUMCVSS 5.0fixed in gdk-pixbuf 0.22.0-3 (bookworm)2004
CVE-2004-0111 [MEDIUM] CVE-2004-0111: gdk-pixbuf - gdk-pixbuf before 0.20 allows attackers to cause a denial of service (crash) via... gdk-pixbuf before 0.20 allows attackers to cause a denial of service (crash) via a malformed bitmap (BMP) file. Scope: local bookworm: resolved (fixed in 0.22.0-3) bullseye: resolved (fixed in 0.22.0-3) forky: resolved (fixed in 0.22.0-3) sid: resolved (fixed in 0.22.0-3) trixie: resolved (fixed in 0.22.0-3)
debian
Debian Gdk-Pixbuf vulnerabilities | cvebase