GIMP
GNOME · 12 CVEs
Gimp: integer overflow when generating a thumbnail preview for a psd file
Sep 15, 2026
Gimp: heap out-of-bounds read and stack out-of-bounds access in psd loader from channel-count handling
Aug 28, 2026
Gimp: heap out-of-bounds read in pvr vq (compressed) decoder due to missing bounds check
Aug 28, 2026
Gimp: heap out-of-bounds read in ico loader via unvalidated used_clrs palette count
Aug 28, 2026
Gimp: heap out-of-bounds reads in iff/ilbm loader from ham row size mismatch and nplanes=0
Aug 28, 2026
Gimp: stack vla size underflow denial of service in seattle
Aug 26, 2026
Gimp: multiple heap out-of-bounds reads in xwd loader from unrelated width and bytes-per-line validation
Aug 25, 2026
Gimp: unbounded stack vla and 21-byte stack over-read in pix (esm) loader
Aug 24, 2026
Gimp: integer overflow in pcx loader (planes=4) leads to heap overflow on 32-bit
Aug 24, 2026
Gimp: out-of-bounds read in file-icns plugin causes information disclosure or crash on crafted icns images
Jul 27, 2026
Gimp: signed integer overflow in file-sgi (sgi-lib) causes the plugin to crash on rle sgi images
Jul 27, 2026
Gimp: integer overflow in file-fits plugin causes a heap-based buffer overflow on crafted fits images
Jul 27, 2026
| CVE ID | Description | Severity | EPSS | Published |
|---|---|---|---|---|
| CVE-2026-92248 | Gimp: integer overflow when generating a thumbnail preview for a psd file | HIGH | 0.18% | Sep 15, 2026 |
| CVE-2026-82343 | Gimp: heap out-of-bounds read and stack out-of-bounds access in psd loader from channel-count handling | MEDIUM | 0.26% | Aug 28, 2026 |
| CVE-2026-82330 | Gimp: heap out-of-bounds read in pvr vq (compressed) decoder due to missing bounds check | MEDIUM | 0.26% | Aug 28, 2026 |
| CVE-2026-82328 | Gimp: heap out-of-bounds read in ico loader via unvalidated used_clrs palette count | MEDIUM | 0.26% | Aug 28, 2026 |
| CVE-2026-82324 | Gimp: heap out-of-bounds reads in iff/ilbm loader from ham row size mismatch and nplanes=0 | MEDIUM | 0.27% | Aug 28, 2026 |
| CVE-2026-79902 | Gimp: stack vla size underflow denial of service in seattle | MEDIUM | 0.27% | Aug 26, 2026 |
| CVE-2026-80101 | Gimp: multiple heap out-of-bounds reads in xwd loader from unrelated width and bytes-per-line validation | MEDIUM | 0.23% | Aug 25, 2026 |
| CVE-2026-78475 | Gimp: unbounded stack vla and 21-byte stack over-read in pix (esm) loader | MEDIUM | 0.26% | Aug 24, 2026 |
| CVE-2026-78465 | Gimp: integer overflow in pcx loader (planes=4) leads to heap overflow on 32-bit | HIGH | 0.28% | Aug 24, 2026 |
| CVE-2026-66759 | Gimp: out-of-bounds read in file-icns plugin causes information disclosure or crash on crafted icns images | HIGH | 0.30% | Jul 27, 2026 |
| CVE-2026-66757 | Gimp: signed integer overflow in file-sgi (sgi-lib) causes the plugin to crash on rle sgi images | MEDIUM | 0.23% | Jul 27, 2026 |
| CVE-2026-66758 | Gimp: integer overflow in file-fits plugin causes a heap-based buffer overflow on crafted fits images | HIGH | 0.30% | Jul 27, 2026 |
Showing 1 to 12 of 12 CVEs