cbcvebase.

Debian Gimp vulnerabilities

66 known vulnerabilities affecting debian/gimp.

Total CVEs
66
CISA KEV
0
Public exploits
4
Exploited in wild
0
Severity breakdown
CRITICAL1HIGH24MEDIUM14LOW27

Vulnerabilities

Page 3 of 4
CVE-2025-48796P3LOWCVSS 7.3fixed in gimp 3.0.0~RC1-4 (forky)2025
CVE-2025-48796 [HIGH] CVE-2025-48796: gimp - A flaw was found in GIMP. The GIMP ani_load_image() function is vulnerable to a ... A flaw was found in GIMP. The GIMP ani_load_image() function is vulnerable to a stack-based overflow. If a user opens.ANI files, GIMP may be used to store more information than the capacity allows. This flaw allows a malicious ANI file to trigger arbitrary code execution. Scope: local bookworm: resolved bullseye: resolved forky: resolved (fixed in 3.0.0~RC1-4) sid: res
debian
CVE-2026-2272P3MEDIUMCVSS 4.3fixed in gimp 2.10.34-1+deb12u8 (bookworm)2026
CVE-2026-2272 [MEDIUM] CVE-2026-2272: gimp - A flaw was found in GIMP. An integer overflow vulnerability exists when processi... A flaw was found in GIMP. An integer overflow vulnerability exists when processing ICO image files, specifically in the `ico_read_info` and `ico_read_icon` functions. This issue arises because a size calculation for image buffers can wrap around due to a 32-bit integer evaluation, allowing oversized image headers to bypass security checks. A remote attacker could explo
debian
CVE-2012-3403P3MEDIUMCVSS 6.8fixed in gimp 2.8.2-1 (bookworm)2012
CVE-2012-3403 [MEDIUM] CVE-2012-3403: gimp - Heap-based buffer overflow in the KiSS CEL file format plug-in in GIMP 2.8.x and... Heap-based buffer overflow in the KiSS CEL file format plug-in in GIMP 2.8.x and earlier allows remote attackers to cause a denial of service and possibly execute arbitrary code via a crafted KiSS palette file, which triggers an "invalid free." Scope: local bookworm: resolved (fixed in 2.8.2-1) bullseye: resolved (fixed in 2.8.2-1) forky: resolved (fixed in 2.8.2-1) si
debian
CVE-2017-17789P3HIGHCVSS 7.8fixed in gimp 2.8.20-1.1 (bookworm)2017
CVE-2017-17789 [HIGH] CVE-2017-17789: gimp - In GIMP 2.8.22, there is a heap-based buffer overflow in read_channel_data in pl... In GIMP 2.8.22, there is a heap-based buffer overflow in read_channel_data in plug-ins/common/file-psp.c. Scope: local bookworm: resolved (fixed in 2.8.20-1.1) bullseye: resolved (fixed in 2.8.20-1.1) forky: resolved (fixed in 2.8.20-1.1) sid: resolved (fixed in 2.8.20-1.1) trixie: resolved (fixed in 2.8.20-1.1)
debian
CVE-2007-2949P3MEDIUMCVSS 6.8fixed in gimp 2.2.16-1 (bookworm)2007
CVE-2007-2949 [MEDIUM] CVE-2007-2949: gimp - Integer overflow in the seek_to_and_unpack_pixeldata function in the psd.c plugi... Integer overflow in the seek_to_and_unpack_pixeldata function in the psd.c plugin in Gimp 2.2.15 allows remote attackers to execute arbitrary code via a crafted PSD file that contains a large (1) width or (2) height value. Scope: local bookworm: resolved (fixed in 2.2.16-1) bullseye: resolved (fixed in 2.2.16-1) forky: resolved (fixed in 2.2.16-1) sid: resolved (fixed
debian
CVE-2011-1178P4MEDIUMCVSS 6.8fixed in gimp 2.6.10-1 (bookworm)2011
CVE-2011-1178 [MEDIUM] CVE-2011-1178: gimp - Multiple integer overflows in the load_image function in file-pcx.c in the Perso... Multiple integer overflows in the load_image function in file-pcx.c in the Personal Computer Exchange (PCX) plugin in GIMP 2.6.x and earlier allow remote attackers to cause a denial of service (application crash) or possibly execute arbitrary code via a crafted PCX image that triggers a heap-based buffer overflow. Scope: local bookworm: resolved (fixed in 2.6.10-1) bul
debian
CVE-2012-3481P4MEDIUMCVSS 6.8fixed in gimp 2.8.2-1 (bookworm)2012
CVE-2012-3481 [MEDIUM] CVE-2012-3481: gimp - Integer overflow in the ReadImage function in plug-ins/common/file-gif-load.c in... Integer overflow in the ReadImage function in plug-ins/common/file-gif-load.c in the GIF image format plug-in in GIMP 2.8.x and earlier allows remote attackers to cause a denial of service (application crash) and possibly execute arbitrary code via crafted height and len properties in a GIF image file, which triggers a heap-based buffer overflow. NOTE: some of these de
debian
CVE-2017-17784P4LOWCVSS 7.8fixed in gimp 2.8.20-1.1 (bookworm)2017
CVE-2017-17784 [HIGH] CVE-2017-17784: gimp - In GIMP 2.8.22, there is a heap-based buffer over-read in load_image in plug-ins... In GIMP 2.8.22, there is a heap-based buffer over-read in load_image in plug-ins/common/file-gbr.c in the gbr import parser, related to mishandling of UTF-8 data. Scope: local bookworm: resolved (fixed in 2.8.20-1.1) bullseye: resolved (fixed in 2.8.20-1.1) forky: resolved (fixed in 2.8.20-1.1) sid: resolved (fixed in 2.8.20-1.1) trixie: resolved (fixed in 2.8.20-1.1)
debian
CVE-2017-17786P4LOWCVSS 7.8fixed in gimp 2.8.20-1.1 (bookworm)2017
CVE-2017-17786 [HIGH] CVE-2017-17786: gimp - In GIMP 2.8.22, there is a heap-based buffer over-read in ReadImage in plug-ins/... In GIMP 2.8.22, there is a heap-based buffer over-read in ReadImage in plug-ins/common/file-tga.c (related to bgr2rgb.part.1) via an unexpected bits-per-pixel value for an RGBA image. Scope: local bookworm: resolved (fixed in 2.8.20-1.1) bullseye: resolved (fixed in 2.8.20-1.1) forky: resolved (fixed in 2.8.20-1.1) sid: resolved (fixed in 2.8.20-1.1) trixie: resolved (
debian
CVE-2017-17785P4HIGHCVSS 7.8fixed in gimp 2.8.20-1.1 (bookworm)2017
CVE-2017-17785 [HIGH] CVE-2017-17785: gimp - In GIMP 2.8.22, there is a heap-based buffer overflow in the fli_read_brun funct... In GIMP 2.8.22, there is a heap-based buffer overflow in the fli_read_brun function in plug-ins/file-fli/fli.c. Scope: local bookworm: resolved (fixed in 2.8.20-1.1) bullseye: resolved (fixed in 2.8.20-1.1) forky: resolved (fixed in 2.8.20-1.1) sid: resolved (fixed in 2.8.20-1.1) trixie: resolved (fixed in 2.8.20-1.1)
debian
CVE-2010-4540P4LOWCVSS 6.8fixed in gimp 2.6.11-2 (bookworm)2010
CVE-2010-4540 [MEDIUM] CVE-2010-4540: gimp - Stack-based buffer overflow in the load_preset_response function in plug-ins/lig... Stack-based buffer overflow in the load_preset_response function in plug-ins/lighting/lighting-ui.c in the "LIGHTING EFFECTS > LIGHT" plugin in GIMP 2.6.11 allows user-assisted remote attackers to cause a denial of service (application crash) or possibly execute arbitrary code via a long Position field in a plugin configuration file. NOTE: it may be uncommon to obtain
debian
CVE-2006-4519P4MEDIUMCVSS 6.8fixed in gimp 2.2.16-1 (bookworm)2006
CVE-2006-4519 [MEDIUM] CVE-2006-4519: gimp - Multiple integer overflows in the image loader plug-ins in GIMP before 2.2.16 al... Multiple integer overflows in the image loader plug-ins in GIMP before 2.2.16 allow user-assisted remote attackers to execute arbitrary code via crafted length values in (1) DICOM, (2) PNM, (3) PSD, (4) PSP, (5) Sun RAS, (6) XBM, and (7) XWD files. Scope: local bookworm: resolved (fixed in 2.2.16-1) bullseye: resolved (fixed in 2.2.16-1) forky: resolved (fixed in 2.2.1
debian
CVE-2010-4542P4LOWCVSS 6.8fixed in gimp 2.6.11-2 (bookworm)2010
CVE-2010-4542 [MEDIUM] CVE-2010-4542: gimp - Stack-based buffer overflow in the gfig_read_parameter_gimp_rgb function in plug... Stack-based buffer overflow in the gfig_read_parameter_gimp_rgb function in plug-ins/gfig/gfig-style.c in the GFIG plugin in GIMP 2.6.11 allows user-assisted remote attackers to cause a denial of service (application crash) or possibly execute arbitrary code via a long Foreground field in a plugin configuration file. NOTE: it may be uncommon to obtain a GIMP plugin con
debian
CVE-2013-1913P4MEDIUMCVSS 6.8fixed in gimp 2.8.10-0.1 (bookworm)2013
CVE-2013-1913 [MEDIUM] CVE-2013-1913: gimp - Integer overflow in the load_image function in file-xwd.c in the X Window Dump (... Integer overflow in the load_image function in file-xwd.c in the X Window Dump (XWD) plug-in in GIMP 2.6.9 and earlier, when used with glib before 2.24, allows remote attackers to cause a denial of service (crash) and possibly execute arbitrary code via a large color entries value in an X Window System (XWD) image dump. Scope: local bookworm: resolved (fixed in 2.8.10-
debian
CVE-2017-17787P4LOWCVSS 7.8fixed in gimp 2.8.20-1.1 (bookworm)2017
CVE-2017-17787 [HIGH] CVE-2017-17787: gimp - In GIMP 2.8.22, there is a heap-based buffer over-read in read_creator_block in ... In GIMP 2.8.22, there is a heap-based buffer over-read in read_creator_block in plug-ins/common/file-psp.c. Scope: local bookworm: resolved (fixed in 2.8.20-1.1) bullseye: resolved (fixed in 2.8.20-1.1) forky: resolved (fixed in 2.8.20-1.1) sid: resolved (fixed in 2.8.20-1.1) trixie: resolved (fixed in 2.8.20-1.1)
debian
CVE-2026-4887P4LOWCVSS 6.1fixed in gimp 3.2.0-1 (forky)2026
CVE-2026-4887 [MEDIUM] CVE-2026-4887: gimp - A flaw was found in GIMP. This issue is a heap buffer over-read in GIMP PCX file... A flaw was found in GIMP. This issue is a heap buffer over-read in GIMP PCX file loader due to an off-by-one error. A remote attacker could exploit this by convincing a user to open a specially crafted PCX image. Successful exploitation could lead to out-of-bounds memory disclosure and a possible application crash, resulting in a Denial of Service (DoS). Scope: local b
debian
CVE-2026-2239P4LOWCVSS 2.8fixed in gimp 2.10.34-1+deb12u8 (bookworm)2026
CVE-2026-2239 [LOW] CVE-2026-2239: gimp - A flaw was found in GIMP. Heap-buffer-overflow vulnerability exists in the fread... A flaw was found in GIMP. Heap-buffer-overflow vulnerability exists in the fread_pascal_string function when processing a specially crafted PSD (Photoshop Document) file. This occurs because the buffer allocated for a Pascal string is not properly null-terminated, leading to an out-of-bounds read when strlen() is subsequently called. Successfully exploiting this vulnerabi
debian
CVE-2013-1953P4MEDIUMCVSS 6.8fixed in gimp 2.6.10-1 (bookworm)2013
CVE-2013-1953 [MEDIUM] CVE-2013-1953: gimp - Integer underflow in the input_bmp_reader function in input-bmp.c in AutoTrace 0... Integer underflow in the input_bmp_reader function in input-bmp.c in AutoTrace 0.31.1 allows context-dependent attackers to have an unspecified impact via a small value in the biSize field in the header of a BMP file, which triggers a buffer overflow. Scope: local bookworm: resolved (fixed in 2.6.10-1) bullseye: resolved (fixed in 2.6.10-1) forky: resolved (fixed in 2.
debian
CVE-2006-3404P4MEDIUMCVSS 5.1fixed in gimp 2.2.11-3.1 (bookworm)2006
CVE-2006-3404 [MEDIUM] CVE-2006-3404: gimp - Buffer overflow in the xcf_load_vector function in app/xcf/xcf-load.c for gimp b... Buffer overflow in the xcf_load_vector function in app/xcf/xcf-load.c for gimp before 2.2.12 allows user-assisted attackers to cause a denial of service (crash) and possibly execute arbitrary code via an XCF file with a large num_axes value in the VECTORS property. Scope: local bookworm: resolved (fixed in 2.2.11-3.1) bullseye: resolved (fixed in 2.2.11-3.1) forky: res
debian
CVE-2026-2271P4LOWCVSS 3.3fixed in gimp 2.10.34-1+deb12u8 (bookworm)2026
CVE-2026-2271 [LOW] CVE-2026-2271: gimp - A flaw was found in GIMP's PSP (Paint Shop Pro) file parser. A remote attacker c... A flaw was found in GIMP's PSP (Paint Shop Pro) file parser. A remote attacker could exploit an integer overflow vulnerability in the read_creator_block() function by providing a specially crafted PSP image file. This vulnerability occurs when a 32-bit length value from the file is used for memory allocation without proper validation, leading to a heap overflow and an out
debian
Debian Gimp vulnerabilities | cvebase