Debian Gimp vulnerabilities
66 known vulnerabilities affecting debian/gimp.
Total CVEs
66
CISA KEV
0
Public exploits
4
Exploited in wild
0
Severity breakdown
CRITICAL1HIGH24MEDIUM14LOW27
Vulnerabilities
Page 1 of 4
CVE-2012-2763P2LOWCVSS 7.5PoCfixed in gimp 2.8.0-1 (bookworm)2012
CVE-2012-2763 [HIGH] CVE-2012-2763: gimp - Buffer overflow in the readstr_upto function in plug-ins/script-fu/tinyscheme/sc...
Buffer overflow in the readstr_upto function in plug-ins/script-fu/tinyscheme/scheme.c in GIMP 2.6.12 and earlier, and possibly 2.6.13, allows remote attackers to execute arbitrary code via a long string in a command to the script-fu server.
Scope: local
bookworm: resolved (fixed in 2.8.0-1)
bullseye: resolved (fixed in 2.8.0-1)
forky: resolved (fixed in 2.8.0-1)
sid: re
debian
CVE-2023-44443P2HIGHCVSS 7.8fixed in gimp 2.10.34-1+deb12u1 (bookworm)2023
CVE-2023-44443 [HIGH] CVE-2023-44443: gimp - GIMP PSP File Parsing Integer Overflow Remote Code Execution Vulnerability. This...
GIMP PSP File Parsing Integer Overflow Remote Code Execution Vulnerability. This vulnerability allows remote attackers to execute arbitrary code on affected installations of GIMP. User interaction is required to exploit this vulnerability in that the target must visit a malicious page or open a malicious file. The specific flaw exists within the parsing of PSP files. T
debian
CVE-2010-4543P3LOWCVSS 7.5PoCfixed in gimp 2.6.11-2 (bookworm)2010
CVE-2010-4543 [HIGH] CVE-2010-4543: gimp - Heap-based buffer overflow in the read_channel_data function in file-psp.c in th...
Heap-based buffer overflow in the read_channel_data function in file-psp.c in the Paint Shop Pro (PSP) plugin in GIMP 2.6.11 allows remote attackers to cause a denial of service (application crash) or possibly execute arbitrary code via a PSP_COMP_RLE (aka RLE compression) image file that begins a long run count at the end of the image. NOTE: some of these details are ob
debian
CVE-2023-44442P2HIGHCVSS 7.8fixed in gimp 2.10.34-1+deb12u1 (bookworm)2023
CVE-2023-44442 [HIGH] CVE-2023-44442: gimp - GIMP PSD File Parsing Heap-based Buffer Overflow Remote Code Execution Vulnerabi...
GIMP PSD File Parsing Heap-based Buffer Overflow Remote Code Execution Vulnerability. This vulnerability allows remote attackers to execute arbitrary code on affected installations of GIMP. User interaction is required to exploit this vulnerability in that the target must visit a malicious page or open a malicious file. The specific flaw exists within the parsing of PS
debian
CVE-2023-44444P3HIGHCVSS 7.8fixed in gimp 2.10.34-1+deb12u1 (bookworm)2023
CVE-2023-44444 [HIGH] CVE-2023-44444: gimp - GIMP PSP File Parsing Off-By-One Remote Code Execution Vulnerability. This vulne...
GIMP PSP File Parsing Off-By-One Remote Code Execution Vulnerability. This vulnerability allows remote attackers to execute arbitrary code on affected installations of GIMP. User interaction is required to exploit this vulnerability in that the target must visit a malicious page or open a malicious file. The specific flaw exists within the parsing of PSP files. Crafted
debian
CVE-2025-5473P2HIGHCVSS 8.8fixed in gimp 2.10.34-1+deb12u3 (bookworm)2025
CVE-2025-5473 [HIGH] CVE-2025-5473: gimp - GIMP ICO File Parsing Integer Overflow Remote Code Execution Vulnerability. This...
GIMP ICO File Parsing Integer Overflow Remote Code Execution Vulnerability. This vulnerability allows remote attackers to execute arbitrary code on affected installations of GIMP. User interaction is required to exploit this vulnerability in that the target must visit a malicious page or open a malicious file. The specific flaw exists within the parsing of ICO files. The
debian
CVE-2007-2356P3MEDIUMCVSS 6.8PoCfixed in gimp 2.2.14-2 (bookworm)2007
CVE-2007-2356 [MEDIUM] CVE-2007-2356: gimp - Stack-based buffer overflow in the set_color_table function in sunras.c in the S...
Stack-based buffer overflow in the set_color_table function in sunras.c in the SUNRAS plugin in Gimp 2.2.14 allows user-assisted remote attackers to execute arbitrary code via a crafted RAS file.
Scope: local
bookworm: resolved (fixed in 2.2.14-2)
bullseye: resolved (fixed in 2.2.14-2)
forky: resolved (fixed in 2.2.14-2)
sid: resolved (fixed in 2.2.14-2)
trixie: resolv
debian
CVE-2023-44441P3HIGHCVSS 7.8fixed in gimp 2.10.34-1+deb12u1 (bookworm)2023
CVE-2023-44441 [HIGH] CVE-2023-44441: gimp - GIMP DDS File Parsing Heap-based Buffer Overflow Remote Code Execution Vulnerabi...
GIMP DDS File Parsing Heap-based Buffer Overflow Remote Code Execution Vulnerability. This vulnerability allows remote attackers to execute arbitrary code on affected installations of GIMP. User interaction is required to exploit this vulnerability in that the target must visit a malicious page or open a malicious file. The specific flaw exists within the parsing of DD
debian
CVE-2026-0797P3HIGHCVSS 7.8fixed in gimp 2.10.34-1+deb12u9 (bookworm)2026
CVE-2026-0797 [HIGH] CVE-2026-0797: gimp - GIMP ICO File Parsing Heap-based Buffer Overflow Remote Code Execution Vulnerabi...
GIMP ICO File Parsing Heap-based Buffer Overflow Remote Code Execution Vulnerability. This vulnerability allows remote attackers to execute arbitrary code on affected installations of GIMP. User interaction is required to exploit this vulnerability in that the target must visit a malicious page or open a malicious file. The specific flaw exists within the parsing of ICO
debian
CVE-2026-2044P3HIGHCVSS 7.8fixed in gimp 2.10.34-1+deb12u9 (bookworm)2026
CVE-2026-2044 [HIGH] CVE-2026-2044: gimp - GIMP PGM File Parsing Uninitialized Memory Remote Code Execution Vulnerability. ...
GIMP PGM File Parsing Uninitialized Memory Remote Code Execution Vulnerability. This vulnerability allows remote attackers to execute arbitrary code on affected installations of GIMP. User interaction is required to exploit this vulnerability in that the target must visit a malicious page or open a malicious file. The specific flaw exists within the parsing of PGM files.
debian
CVE-2025-2760P3HIGHCVSS 7.8fixed in gimp 2.10.34-1+deb12u4 (bookworm)2025
CVE-2025-2760 [HIGH] CVE-2025-2760: gimp - GIMP XWD File Parsing Integer Overflow Remote Code Execution Vulnerability. This...
GIMP XWD File Parsing Integer Overflow Remote Code Execution Vulnerability. This vulnerability allows remote attackers to execute arbitrary code on affected installations of GIMP. User interaction is required to exploit this vulnerability in that the target must visit a malicious page or open a malicious file. The specific flaw exists within the parsing of XWD files. The
debian
CVE-2025-10925P3LOWCVSS 7.8fixed in gimp 3.2.0~RC2-1 (forky)2025
CVE-2025-10925 [HIGH] CVE-2025-10925: gimp - GIMP ILBM File Parsing Stack-based Buffer Overflow Remote Code Execution Vulnera...
GIMP ILBM File Parsing Stack-based Buffer Overflow Remote Code Execution Vulnerability. This vulnerability allows remote attackers to execute arbitrary code on affected installations of GIMP. User interaction is required to exploit this vulnerability in that the target must visit a malicious page or open a malicious file. The specific flaw exists within the parsing of
debian
CVE-2026-2045P3HIGHCVSS 7.8fixed in gimp 2.10.34-1+deb12u9 (bookworm)2026
CVE-2026-2045 [HIGH] CVE-2026-2045: gimp - GIMP XWD File Parsing Out-Of-Bounds Write Remote Code Execution Vulnerability. T...
GIMP XWD File Parsing Out-Of-Bounds Write Remote Code Execution Vulnerability. This vulnerability allows remote attackers to execute arbitrary code on affected installations of GIMP. User interaction is required to exploit this vulnerability in that the target must visit a malicious page or open a malicious file. The specific flaw exists within the parsing of XWD files.
debian
CVE-2025-14422P3HIGHCVSS 7.8fixed in gimp 2.10.34-1+deb12u6 (bookworm)2025
CVE-2025-14422 [HIGH] CVE-2025-14422: gimp - GIMP PNM File Parsing Integer Overflow Remote Code Execution Vulnerability. This...
GIMP PNM File Parsing Integer Overflow Remote Code Execution Vulnerability. This vulnerability allows remote attackers to execute arbitrary code on affected installations of GIMP. User interaction is required to exploit this vulnerability in that the target must visit a malicious page or open a malicious file. The specific flaw exists within the parsing of PNM files. T
debian
CVE-2025-15059P3HIGHCVSS 7.8fixed in gimp 2.10.34-1+deb12u7 (bookworm)2025
CVE-2025-15059 [HIGH] CVE-2025-15059: gimp - GIMP PSP File Parsing Heap-based Buffer Overflow Remote Code Execution Vulnerabi...
GIMP PSP File Parsing Heap-based Buffer Overflow Remote Code Execution Vulnerability. This vulnerability allows remote attackers to execute arbitrary code on affected installations of GIMP. User interaction is required to exploit this vulnerability in that the target must visit a malicious page or open a malicious file. The specific flaw exists within the parsing of PS
debian
CVE-2025-10922P3HIGHCVSS 7.8fixed in gimp 2.10.34-1+deb12u4 (bookworm)2025
CVE-2025-10922 [HIGH] CVE-2025-10922: gimp - GIMP DCM File Parsing Heap-based Buffer Overflow Remote Code Execution Vulnerabi...
GIMP DCM File Parsing Heap-based Buffer Overflow Remote Code Execution Vulnerability. This vulnerability allows remote attackers to execute arbitrary code on affected installations of GIMP. User interaction is required to exploit this vulnerability in that the target must visit a malicious page or open a malicious file. The specific flaw exists within the parsing of DC
debian
CVE-2026-2047P3LOWCVSS 7.8fixed in gimp 3.2.0~RC3-1 (forky)2026
CVE-2026-2047 [HIGH] CVE-2026-2047: gimp - GIMP ICNS File Parsing Heap-based Buffer Overflow Remote Code Execution Vulnerab...
GIMP ICNS File Parsing Heap-based Buffer Overflow Remote Code Execution Vulnerability. This vulnerability allows remote attackers to execute arbitrary code on affected installations of GIMP. User interaction is required to exploit this vulnerability in that the target must visit a malicious page or open a malicious file. The specific flaw exists within the parsing of ICN
debian
CVE-2025-14423P3LOWCVSS 7.8fixed in gimp 3.2.0~RC2-1 (forky)2025
CVE-2025-14423 [HIGH] CVE-2025-14423: gimp - GIMP LBM File Parsing Stack-based Buffer Overflow Remote Code Execution Vulnerab...
GIMP LBM File Parsing Stack-based Buffer Overflow Remote Code Execution Vulnerability. This vulnerability allows remote attackers to execute arbitrary code on affected installations of GIMP. User interaction is required to exploit this vulnerability in that the target must visit a malicious page or open a malicious file. The specific flaw exists within the parsing of L
debian
CVE-2025-14424P3LOWCVSS 7.8fixed in gimp 3.2.0~RC2-1 (forky)2025
CVE-2025-14424 [HIGH] CVE-2025-14424: gimp - GIMP XCF File Parsing Use-After-Free Remote Code Execution Vulnerability. This v...
GIMP XCF File Parsing Use-After-Free Remote Code Execution Vulnerability. This vulnerability allows remote attackers to execute arbitrary code on affected installations of GIMP. User interaction is required to exploit this vulnerability in that the target must visit a malicious page or open a malicious file. The specific flaw exists within the parsing of XCF files. The
debian
CVE-2009-3909P3MEDIUMCVSS 9.3fixed in gimp 2.6.7-1.1 (bookworm)2009
CVE-2009-3909 [CRITICAL] CVE-2009-3909: gimp - Integer overflow in the read_channel_data function in plug-ins/file-psd/psd-load...
Integer overflow in the read_channel_data function in plug-ins/file-psd/psd-load.c in GIMP 2.6.7 might allow remote attackers to execute arbitrary code via a crafted PSD file that triggers a heap-based buffer overflow.
Scope: local
bookworm: resolved (fixed in 2.6.7-1.1)
bullseye: resolved (fixed in 2.6.7-1.1)
forky: resolved (fixed in 2.6.7-1.1)
sid: resolved (fixed
debian
1 / 4Next →