VulnSea

gimp vulnerabilities

CVEs whose affected-version data names the gimp package. Each record lists the affected and patched versions; check a specific version with the dependency checker or POST /api/sbom.

9 CVEsRSS

CVE-2026-92248High· 7.8
1w ago

A flaw was found in the file-psd plugin in GIMP

A flaw was found in the file-psd plugin in GIMP. When generating a thumbnail preview for a specially crafted PSD (Photoshop Document) image file, an integer overflow occurs during the multiplication of values from an embedded JPEG header…

TwilightGNOME · gimpEPSS 0.18%via NVD
CVE-2026-90947High· 7.8
1w ago

A flaw was found in GIMP

A flaw was found in GIMP. When processing a specially crafted lighting preset file, the Lighting Effects filter does not properly validate the number of light sources. This can lead to an out-of-bounds write, corrupting memory. An attack…

TwilightRed Hat · gimpEPSS 0.13%via NVD
CVE-2026-90949High· 7.8
1w ago

A flaw was found in GIMP's PSP (Paint Shop Pro) file loader

A flaw was found in GIMP's PSP (Paint Shop Pro) file loader. When processing a compressed selection channel, a heap-based buffer overflow can occur due to a mismatch between the allocated buffer size and the amount of data decompressed. …

TwilightRed Hat · gimpEPSS 0.22%via NVD
CVE-2026-90948High· 7.8
1w ago

A flaw was found in GIMP's ICO file loader

A flaw was found in GIMP's ICO file loader. When processing an ICO file containing an embedded PNG image, an integer overflow can occur during the calculation of the required buffer size. This leads to an undersized buffer being allocate…

TwilightRed Hat · gimpEPSS 0.22%via NVD
CVE-2026-58384High· 7.3
2mo ago

A flaw was found in GIMP's PSD parser

A flaw was found in GIMP's PSD parser. An integer overflow in read_RLE_channel() can cause an undersized heap allocation for the RLE row-length table, after which subsequent per-row writes corrupt heap memory. This could lead to memory c…

Twilightgimp · gimpEPSS 0.26%via NVD
CVE-2026-58380High· 7.3
2mo ago

A flaw was found in GIMP's PNM file format parser

A flaw was found in GIMP's PNM file format parser. When parsing a specially crafted PNM file, the pnmscanner_gettoken() function writes a null terminator one byte past the end of a stack-allocated buffer due to an off-by-one error in the…

Twilightgimp · gimpEPSS 0.26%via NVD
CVE-2026-2050High· 7.80day
3mo ago

GIMP HDR File Parsing Heap-based Buffer Overflow Remote Code Execution Vulnerability

GIMP HDR File Parsing Heap-based Buffer Overflow Remote Code Execution Vulnerability. This vulnerability allows remote attackers to execute arbitrary code on affected installations of GIMP. User interaction is required to exploit this vu…

Abyssalgimp · gimpEPSS 0.61%via NVD
CVE-2025-15059High· 7.80day
8mo ago

GIMP PSP File Parsing Heap-based Buffer Overflow Remote Code Execution Vulnerability

GIMP PSP File Parsing Heap-based Buffer Overflow Remote Code Execution Vulnerability. This vulnerability allows remote attackers to execute arbitrary code on affected installations of GIMP. User interaction is required to exploit this vu…

Abyssalgimp · gimpEPSS 0.85%via NVD
CVE-2025-6035Medium· 6.1
1y ago

A flaw was found in GIMP

A flaw was found in GIMP. An integer overflow vulnerability exists in the GIMP "Despeckle" plug-in. The issue occurs due to unchecked multiplication of image dimensions, such as width, height, and bytes-per-pixel (img_bpp), which can re…

Sunlitgimp · gimpEPSS 0.57%via NVD
gimp vulnerabilities (CVEs) · VulnSea