cbcvebase.

Debian Gimp vulnerabilities

66 known vulnerabilities affecting debian/gimp.

Total CVEs
66
CISA KEV
0
Public exploits
4
Exploited in wild
0
Severity breakdown
CRITICAL1HIGH24MEDIUM14LOW27

Vulnerabilities

Page 4 of 4
CVE-2022-30067P4LOWCVSS 5.5fixed in gimp 2.10.32-1 (bookworm)2022
CVE-2022-30067 [MEDIUM] CVE-2022-30067: gimp - GIMP 2.10.30 and 2.99.10 are vulnerable to Buffer Overflow. Through a crafted XC... GIMP 2.10.30 and 2.99.10 are vulnerable to Buffer Overflow. Through a crafted XCF file, the program will allocate for a huge amount of memory, resulting in insufficient memory or program crash. Scope: local bookworm: resolved (fixed in 2.10.32-1) bullseye: resolved (fixed in 2.10.22-4+deb11u5) forky: resolved (fixed in 2.10.32-1) sid: resolved (fixed in 2.10.32-1) tr
debian
CVE-2017-17788P4LOWCVSS 5.5fixed in gimp 2.8.20-1.1 (bookworm)2017
CVE-2017-17788 [MEDIUM] CVE-2017-17788: gimp - In GIMP 2.8.22, there is a stack-based buffer over-read in xcf_load_stream in ap... In GIMP 2.8.22, there is a stack-based buffer over-read in xcf_load_stream in app/xcf/xcf.c when there is no '\0' character after the version string. Scope: local bookworm: resolved (fixed in 2.8.20-1.1) bullseye: resolved (fixed in 2.8.20-1.1) forky: resolved (fixed in 2.8.20-1.1) sid: resolved (fixed in 2.8.20-1.1) trixie: resolved (fixed in 2.8.20-1.1)
debian
CVE-2022-32990P4LOWCVSS 5.5fixed in gimp 2.10.32-1 (bookworm)2022
CVE-2022-32990 [MEDIUM] CVE-2022-32990: gimp - An issue in gimp_layer_invalidate_boundary of GNOME GIMP 2.10.30 allows attacker... An issue in gimp_layer_invalidate_boundary of GNOME GIMP 2.10.30 allows attackers to trigger an unhandled exception via a crafted XCF file, causing a Denial of Service (DoS). Scope: local bookworm: resolved (fixed in 2.10.32-1) bullseye: open forky: resolved (fixed in 2.10.32-1) sid: resolved (fixed in 2.10.32-1) trixie: resolved (fixed in 2.10.32-1)
debian
CVE-2007-3126P4LOWCVSS 5.5fixed in gimp 2.8.22-1 (bookworm)2007
CVE-2007-3126 [MEDIUM] CVE-2007-3126: gimp - Gimp before 2.8.22 allows context-dependent attackers to cause a denial of servi... Gimp before 2.8.22 allows context-dependent attackers to cause a denial of service (crash) via an ICO file with an InfoHeader containing a Height of zero, a similar issue to CVE-2007-2237. Scope: local bookworm: resolved (fixed in 2.8.22-1) bullseye: resolved (fixed in 2.8.22-1) forky: resolved (fixed in 2.8.22-1) sid: resolved (fixed in 2.8.22-1) trixie: resolved (fix
debian
CVE-2007-3741P4LOWCVSS 4.3fixed in gimp 2.2.17-1 (bookworm)2007
CVE-2007-3741 [MEDIUM] CVE-2007-3741: gimp - The (1) psp (aka .tub), (2) bmp, (3) pcx, and (4) psd plugins in gimp allow user... The (1) psp (aka .tub), (2) bmp, (3) pcx, and (4) psd plugins in gimp allow user-assisted remote attackers to cause a denial of service (crash or memory consumption) via crafted image files, as discovered using the fusil fuzzing tool. Scope: local bookworm: resolved (fixed in 2.2.17-1) bullseye: resolved (fixed in 2.2.17-1) forky: resolved (fixed in 2.2.17-1) sid: reso
debian
CVE-2026-2046LOWfixed in gimp 3.2.0-1 (forky)2026
CVE-2026-2046 [LOW] CVE-2026-2046: gimp bookworm: open bullseye: open forky: resolved (fixed in 3.2.0-1) sid: resolved (fixed in 3.2.0-1) trixie: open
debian
Debian Gimp vulnerabilities | cvebase