Vulnerabilities
Vulnerable Software
Gimp:  >> Gimp  Security Vulnerabilities
An issue in gimp_layer_invalidate_boundary of GNOME GIMP 2.10.30 allows attackers to trigger an unhandled exception via a crafted XCF file, causing a Denial of Service (DoS).
CVSS Score
5.5
EPSS Score
0.001
Published
2022-06-24
GIMP 2.10.30 and 2.99.10 are vulnerable to Buffer Overflow. Through a crafted XCF file, the program will allocate for a huge amount of memory, resulting in insufficient memory or program crash.
CVSS Score
5.5
EPSS Score
0.001
Published
2022-05-17
load_cache in GEGL before 0.4.34 allows shell expansion when a pathname in a constructed command line is not escaped or filtered. This is caused by use of the system library function for execution of the ImageMagick convert fallback in magick-load. NOTE: GEGL releases before 0.4.34 are used in GIMP releases before 2.10.30; however, this does not imply that GIMP builds enable the vulnerable feature.
CVSS Score
7.8
EPSS Score
0.016
Published
2021-12-23
GIMP through 2.10.2 makes g_get_tmp_dir calls to establish temporary filenames, which may result in a filename that already exists, as demonstrated by the gimp_write_and_read_file function in app/tests/test-xcf.c. This might be leveraged by attackers to overwrite files or read file content that was intended to be private.
CVSS Score
9.1
EPSS Score
0.002
Published
2018-06-24
In GIMP 2.8.22, there is a heap-based buffer over-read in ReadImage in plug-ins/common/file-tga.c (related to bgr2rgb.part.1) via an unexpected bits-per-pixel value for an RGBA image.
CVSS Score
7.8
EPSS Score
0.003
Published
2017-12-20
In GIMP 2.8.22, there is a heap-based buffer over-read in read_creator_block in plug-ins/common/file-psp.c.
CVSS Score
7.8
EPSS Score
0.003
Published
2017-12-20
In GIMP 2.8.22, there is a stack-based buffer over-read in xcf_load_stream in app/xcf/xcf.c when there is no '\0' character after the version string.
CVSS Score
5.5
EPSS Score
0.005
Published
2017-12-20
In GIMP 2.8.22, there is a heap-based buffer overflow in read_channel_data in plug-ins/common/file-psp.c.
CVSS Score
7.8
EPSS Score
0.002
Published
2017-12-20
In GIMP 2.8.22, there is a heap-based buffer over-read in load_image in plug-ins/common/file-gbr.c in the gbr import parser, related to mishandling of UTF-8 data.
CVSS Score
7.8
EPSS Score
0.002
Published
2017-12-20
In GIMP 2.8.22, there is a heap-based buffer overflow in the fli_read_brun function in plug-ins/file-fli/fli.c.
CVSS Score
7.8
EPSS Score
0.004
Published
2017-12-20


Contact Us

Shodan ® - All rights reserved