Gnome Gdkpixbuf vulnerabilities
9 known vulnerabilities affecting gnome/gdkpixbuf.
Total CVEs
9
CISA KEV
0
Public exploits
0
Exploited in wild
0
Severity breakdown
HIGH5MEDIUM3LOW1
Vulnerabilities
Page 1 of 1
CVE-2025-6199LOWCVSS 3.3v2.0.02025-06-17
CVE-2025-6199 [LOW] CWE-200 CVE-2025-6199: A flaw was found in the GIF parser of GdkPixbuf’s LZW decoder. When an invalid symbol is encountered
A flaw was found in the GIF parser of GdkPixbuf’s LZW decoder. When an invalid symbol is encountered during decompression, the decoder sets the reported output size to the full buffer length rather than the actual number of written bytes. This logic error results in uninitialized sections of the buffer being included in the output, potentially leaking ar
nvd
CVE-2022-48622HIGHCVSS 7.8≤ 2.42.102024-01-26
CVE-2022-48622 [HIGH] CWE-787 CVE-2022-48622: In GNOME GdkPixbuf (aka gdk-pixbuf) through 2.42.10, the ANI (Windows animated cursor) decoder encou
In GNOME GdkPixbuf (aka gdk-pixbuf) through 2.42.10, the ANI (Windows animated cursor) decoder encounters heap memory corruption (in ani_load_chunk in io-ani.c) when parsing chunks in a crafted .ani file. A crafted file could allow an attacker to overwrite heap metadata, leading to a denial of service or code execution attack. This occurs in gdk_pixbu
nvd
CVE-2021-44648HIGHCVSS 8.8v2.42.62022-01-12
CVE-2021-44648 [HIGH] CWE-787 CVE-2021-44648: GNOME gdk-pixbuf 2.42.6 is vulnerable to a heap-buffer overflow vulnerability when decoding the lzw
GNOME gdk-pixbuf 2.42.6 is vulnerable to a heap-buffer overflow vulnerability when decoding the lzw compressed stream of image data in GIF files with lzw minimum code size equals to 12.
nvd
CVE-2005-2976HIGHCVSS 7.5v0.222005-11-18
CVE-2005-2976 [HIGH] CWE-190 CVE-2005-2976: Integer overflow in io-xpm.c in gdk-pixbuf 0.22.0 in GTK+ before 2.8.7 allows attackers to cause a d
Integer overflow in io-xpm.c in gdk-pixbuf 0.22.0 in GTK+ before 2.8.7 allows attackers to cause a denial of service (crash) or execute arbitrary code via an XPM file with large height, width, and colour values, a different vulnerability than CVE-2005-3186.
nvd
CVE-2004-0782HIGHCVSS 7.5v0.17v0.18+2 more2004-10-20
CVE-2004-0782 [HIGH] CVE-2004-0782: Integer overflow in pixbuf_create_from_xpm (io-xpm.c) in the XPM image decoder for gtk+ 2.4.4 (gtk2)
Integer overflow in pixbuf_create_from_xpm (io-xpm.c) in the XPM image decoder for gtk+ 2.4.4 (gtk2) and earlier, and gdk-pixbuf before 0.22, allows remote attackers to execute arbitrary code via certain n_col and cpp values that enable a heap-based buffer overflow. NOTE: this identifier is ONLY for gtk+. It was incorrectly referenced in an advisory for a diffe
nvd
CVE-2004-0783HIGHCVSS 7.5v0.17v0.18+2 more2004-10-20
CVE-2004-0783 [HIGH] CVE-2004-0783: Stack-based buffer overflow in xpm_extract_color (io-xpm.c) in the XPM image decoder for gtk+ 2.4.4
Stack-based buffer overflow in xpm_extract_color (io-xpm.c) in the XPM image decoder for gtk+ 2.4.4 (gtk2) and earlier, and gdk-pixbuf before 0.22, may allow remote attackers to execute arbitrary code via a certain color string. NOTE: this identifier is ONLY for gtk+. It was incorrectly referenced in an advisory for a different issue (CVE-2004-0688).
nvd
CVE-2004-0753MEDIUMCVSS 5.0v0.17v0.18+2 more2004-10-20
CVE-2004-0753 [MEDIUM] CWE-835 CVE-2004-0753: The BMP image processor for (1) gdk-pixbuf before 0.22 and (2) gtk2 before 2.2.4 allows remote attac
The BMP image processor for (1) gdk-pixbuf before 0.22 and (2) gtk2 before 2.2.4 allows remote attackers to cause a denial of service (infinite loop) via a crafted BMP file.
nvd
CVE-2004-0788MEDIUMCVSS 5.0v0.17v0.18+2 more2004-10-20
CVE-2004-0788 [MEDIUM] CWE-190 CVE-2004-0788: Integer overflow in the ICO image decoder for (1) gdk-pixbuf before 0.22 and (2) gtk2 before 2.2.4 a
Integer overflow in the ICO image decoder for (1) gdk-pixbuf before 0.22 and (2) gtk2 before 2.2.4 allows remote attackers to cause a denial of service (application crash) via a crafted ICO file.
nvd
CVE-2004-0111MEDIUMCVSS 5.0v0.18v0.202004-04-15
CVE-2004-0111 [MEDIUM] CVE-2004-0111: gdk-pixbuf before 0.20 allows attackers to cause a denial of service (crash) via a malformed bitmap
gdk-pixbuf before 0.20 allows attackers to cause a denial of service (crash) via a malformed bitmap (BMP) file.
nvd