Vulmon
Recent Vulnerabilities
Research Posts
Trends
Blog
About
Contact
Vulmon Alerts
By Relevance
By Risk Score
By Publish Date
gimp gimp vulnerabilities and exploits
(subscribe to this query)
5
CVSSv2
CVE-2005-0654
gifload.exe in GIMP 2.0.5, 2.2.3, and possibly 2.2.4 allows remote attackers or local users to cause a denial of service (application crash) via the image descriptor (1) height or (2) width fields set to zero.
Gimp Gimp 2.0.5
Gimp Gimp 2.2.3
Gimp Gimp 2.2.4
4.3
CVSSv2
CVE-2022-30067
GIMP 2.10.30 and 2.99.10 are vulnerable to Buffer Overflow. Through a crafted XCF file, the program will allocate for a huge amount of memory, resulting in insufficient memory or program crash.
Gimp Gimp 2.99.10
Gimp Gimp 2.10.30
6.8
CVSSv2
CVE-2012-3403
Heap-based buffer overflow in the KiSS CEL file format plug-in in GIMP 2.8.x and previous versions allows remote malicious users to cause a denial of service and possibly execute arbitrary code via a crafted KiSS palette file, which triggers an "invalid free."
Gimp Gimp
6.8
CVSSv2
CVE-2012-3481
Integer overflow in the ReadImage function in plug-ins/common/file-gif-load.c in the GIF image format plug-in in GIMP 2.8.x and previous versions allows remote malicious users to cause a denial of service (application crash) and possibly execute arbitrary code via crafted height ...
Gimp Gimp
5
CVSSv2
CVE-2007-3126
Gimp prior to 2.8.22 allows context-dependent malicious users to cause a denial of service (crash) via an ICO file with an InfoHeader containing a Height of zero, a similar issue to CVE-2007-2237.
Gimp Gimp
4.3
CVSSv2
CVE-2012-3236
fits-io.c in GIMP prior to 2.8.1 allows remote malicious users to cause a denial of service (NULL pointer dereference and application crash) via a malformed XTENSION header of a .fit file, as demonstrated using a long string.
Gimp Gimp
1 EDB exploit
6.8
CVSSv2
CVE-2012-3402
Integer overflow in plug-ins/common/psd.c in the Adobe Photoshop PSD plugin in GIMP 2.2.13 and previous versions allows remote malicious users to cause a denial of service and possibly execute arbitrary code via a crafted channels header value in a PSD image file, which triggers ...
Gimp Gimp
7.5
CVSSv2
CVE-2012-2763
Buffer overflow in the readstr_upto function in plug-ins/script-fu/tinyscheme/scheme.c in GIMP 2.6.12 and previous versions, and possibly 2.6.13, allows remote malicious users to execute arbitrary code via a long string in a command to the script-fu server.
Gimp Gimp
2 EDB exploits
6.8
CVSSv2
CVE-2011-1178
Multiple integer overflows in the load_image function in file-pcx.c in the Personal Computer Exchange (PCX) plugin in GIMP 2.6.x and previous versions allow remote malicious users to cause a denial of service (application crash) or possibly execute arbitrary code via a crafted PC...
Gimp Gimp
6.8
CVSSv2
CVE-2012-4245
The scriptfu network server in GIMP 2.6 does not require authentication, which allows remote malicious users to execute arbitrary commands via the python-fu-eval command.
Gimp Gimp
CVSSv2
CVSSv2
CVSSv3
VMScore
Recommendations:
CVE-2023-7028
memory leak
log injection
CVE-2024-3400
CVE-2022-48695
CVE-2022-48675
CVE-2024-34487
CVE-2024-33792
spoof
Vulnerability Notification Service
You don’t have to wait for vulnerability scanning results
Get Started
1
2
3
4
5
NEXT »