GIMP records
110 published records for vendor gimp.
Researcher profile
- Entered KEV
- 0 · 0%
- Weaponized
- 1 · 0.9%
- Pre-auth RCE
- 26
- With a fix record
- 98.2%
- Median publish → KEV
- No record has entered KEV
Recurring classes
- CWE-190 Integer Overflow or Wraparound36
- CWE-787 Out-of-bounds Write21
- CWE-122 Heap-based Buffer Overflow14
- CWE-125 Out-of-bounds Read11
- CWE-120 Buffer Copy without Checking Size of Input ('Classic Buffer Overflow')5
- CWE-121 Stack-based Buffer Overflow3
The weakness classes this vendor ships most often: where to look.
CWEAll records
110 records| Action | CVE | Vulnerability | Severity | KEV | EPSS | Published |
|---|---|---|---|---|---|---|
59Plan | CVE-2023-44443No exploit | GIMP PSP File Parsing Integer Overflow Remote Code Execution Vulnerabilitygimp · gimp · CWE-190 | High7.8 | — | 93.6% | May 2, 2024 |
55Plan | CVE-2012-2763Weaponized | Buffer overflow in the readstr_upto function in plug-ins/script-fu/tinyscheme/scheme.c in GIMP 2.6.12 and earlier, and possibly 2.6.13, allogimp · gimp · CWE-120 | High7.5 | — | 81.7% | Jul 12, 2012 |
49Plan | CVE-2023-44442No exploit | GIMP PSD File Parsing Heap-based Buffer Overflow Remote Code Execution Vulnerabilitygimp · gimp · CWE-122 | High7.8 | — | 61.4% | May 2, 2024 |
48Plan | CVE-2023-44444No exploit | GIMP PSP File Parsing Off-By-One Remote Code Execution Vulnerabilitygimp · gimp · CWE-193 | High7.8 | — | 56.4% | May 2, 2024 |
42Plan | CVE-2025-5473No exploit | GIMP ICO File Parsing Integer Overflow Remote Code Execution Vulnerabilitygimp · gimp · CWE-190 | High8.8 | — | 23.5% | Jun 6, 2025 |
40Plan | CVE-2009-3909No exploit | Integer overflow in the read_channel_data function in plug-ins/file-psd/psd-load.c in GIMP 2.6.7 might allow remote attackers to execute arbgimp · gimp · CWE-190 | Critical9.3 | — | 8.7% | Nov 18, 2009 |
39Monitor | CVE-2023-44441No exploit | GIMP DDS File Parsing Heap-based Buffer Overflow Remote Code Execution Vulnerabilitygimp · gimp · CWE-122 | High7.8 | — | 27.3% | May 2, 2024 |
39Monitor | CVE-2009-1570No exploit | Integer overflow in the ReadImage function in plug-ins/file-bmp/bmp-read.c in GIMP 2.6.7 might allow remote attackers to execute arbitrary cgimp · gimp · CWE-190 | Critical9.3 | — | 8.0% | Nov 13, 2009 |
39Monitor | CVE-2010-4541No exploit | Stack-based buffer overflow in the loadit function in plug-ins/common/sphere-designer.c in the SPHERE DESIGNER plugin in GIMP 2.6.11 allows gimp · gimp · CWE-787 | Critical9.3 | — | 6.8% | Jan 7, 2011 |
39Monitor | CVE-2009-0733No exploit | Multiple stack-based buffer overflows in the ReadSetOfCurves function in LittleCMS (aka lcms or liblcms) before 1.18beta2, as used in Firefolittlecms · little cms · CWE-787 | Critical9.3 | — | 5.5% | Mar 23, 2009 |
39Monitor | CVE-2009-0723No exploit | Multiple integer overflows in LittleCMS (aka lcms or liblcms) before 1.18beta2, as used in Firefox 3.1beta, OpenJDK, and GIMP, allow contextgimp · gimp · CWE-190 | Critical9.3 | — | 5.0% | Mar 23, 2009 |
39Monitor | CVE-2026-59090No exploit | Gimp: gimp: arbitrary code execution in psd plugin due to unsigned underflowgimp · gimp · CWE-191 | Critical9.9 | — | 0.6% | Aug 10, 2026 |
37Monitor | CVE-2025-2760No exploit | GIMP XWD File Parsing Integer Overflow Remote Code Execution Vulnerabilitygimp · gimp · CWE-190 | High7.8 | — | 18.8% | Apr 23, 2025 |
37Monitor | CVE-2018-12713No exploit | GIMP through 2.10.2 makes g_get_tmp_dir calls to establish temporary filenames, which may result in a filename that already exists, as demongimp · gimp | Critical9.1 | — | 1.9% | Jun 24, 2018 |
35Monitor | CVE-2010-4543Proof of concept | Heap-based buffer overflow in the read_channel_data function in file-psp.c in the Paint Shop Pro (PSP) plugin in GIMP 2.6.11 allows remote agimp · gimp · CWE-787 | High7.5 | — | 16.3% | Jan 7, 2011 |
35Monitor | CVE-2026-0797No exploit | GIMP ICO File Parsing Heap-based Buffer Overflow Remote Code Execution Vulnerabilitygimp · gimp · CWE-122 | High8.8 | — | 1.2% | Feb 20, 2026 |
35Monitor | CVE-2026-2044No exploit | GIMP PGM File Parsing Uninitialized Memory Remote Code Execution Vulnerabilitygimp · gimp · CWE-908 | High8.8 | — | 1.0% | Feb 20, 2026 |
32Monitor | CVE-2007-2356Proof of concept | Stack-based buffer overflow in the set_color_table function in sunras.c in the SUNRAS plugin in Gimp 2.2.14 allows user-assisted remote attagimp · gimp · CWE-787 | Medium6.8 | — | 15.7% | Apr 30, 2007 |
32Monitor | CVE-2012-5576No exploit | Multiple stack-based buffer overflows in file-xwd.c in the X Window Dump (XWD) plug-in in GIMP 2.8.2 allow remote attackers to cause a deniagimp · gimp · CWE-787 | High7.5 | — | 6.8% | Dec 17, 2012 |
32Monitor | CVE-2016-4994No exploit | Use-after-free vulnerability in the xcf_load_image function in app/xcf/xcf-load.c in GIMP allows remote attackers to cause a denial of servigimp · gimp · CWE-416 | High7.8 | — | 3.1% | Jul 12, 2016 |
32Monitor | CVE-2025-10925No exploit | GIMP ILBM File Parsing Stack-based Buffer Overflow Remote Code Execution Vulnerabilitygimp · gimp · CWE-121 | High7.8 | — | 3.1% | Oct 29, 2025 |
32Monitor | CVE-2025-2761No exploit | GIMP FLI File Parsing Out-Of-Bounds Write Remote Code Execution Vulnerabilitygimp · gimp · CWE-787 | High7.8 | — | 2.9% | Apr 23, 2025 |
32Monitor | CVE-2017-17789No exploit | In GIMP 2.8.22, there is a heap-based buffer overflow in read_channel_data in plug-ins/common/file-psp.c.gimp · gimp · CWE-787 | High7.8 | — | 2.0% | Dec 20, 2017 |
31Monitor | CVE-2011-1782No exploit | Heap-based buffer overflow in the read_channel_data function in file-psp.c in the Paint Shop Pro (PSP) plugin in GIMP 2.6.11 allows remote agimp · gimp · CWE-787 | High7.5 | — | 3.4% | Jul 26, 2011 |
31Monitor | CVE-2017-17784No exploit | In GIMP 2.8.22, there is a heap-based buffer over-read in load_image in plug-ins/common/file-gbr.c in the gbr import parser, related to mishgimp · gimp · CWE-125 | High7.8 | — | 1.5% | Dec 20, 2017 |
- CVE-2023-4444359Plan
GIMP PSP File Parsing Integer Overflow Remote Code Execution Vulnerability
HighCVSS 7.8No exploitEPSS 94%gimp · gimpMay 2, 2024
- CVE-2012-276355Plan
Buffer overflow in the readstr_upto function in plug-ins/script-fu/tinyscheme/scheme.c in GIMP 2.6.12 and earlier, and possibly 2.6.13, allo
HighCVSS 7.5WeaponizedEPSS 82%gimp · gimpJul 12, 2012
- CVE-2023-4444249Plan
GIMP PSD File Parsing Heap-based Buffer Overflow Remote Code Execution Vulnerability
HighCVSS 7.8No exploitEPSS 61%gimp · gimpMay 2, 2024
- CVE-2023-4444448Plan
GIMP PSP File Parsing Off-By-One Remote Code Execution Vulnerability
HighCVSS 7.8No exploitEPSS 56%gimp · gimpMay 2, 2024
- CVE-2025-547342Plan
GIMP ICO File Parsing Integer Overflow Remote Code Execution Vulnerability
HighCVSS 8.8No exploitEPSS 23%gimp · gimpJun 6, 2025
- CVE-2009-390940Plan
Integer overflow in the read_channel_data function in plug-ins/file-psd/psd-load.c in GIMP 2.6.7 might allow remote attackers to execute arb
CriticalCVSS 9.3No exploitEPSS 9%gimp · gimpNov 18, 2009
- CVE-2023-4444139Monitor
GIMP DDS File Parsing Heap-based Buffer Overflow Remote Code Execution Vulnerability
HighCVSS 7.8No exploitEPSS 27%gimp · gimpMay 2, 2024
- CVE-2009-157039Monitor
Integer overflow in the ReadImage function in plug-ins/file-bmp/bmp-read.c in GIMP 2.6.7 might allow remote attackers to execute arbitrary c
CriticalCVSS 9.3No exploitEPSS 8%gimp · gimpNov 13, 2009
- CVE-2010-454139Monitor
Stack-based buffer overflow in the loadit function in plug-ins/common/sphere-designer.c in the SPHERE DESIGNER plugin in GIMP 2.6.11 allows
CriticalCVSS 9.3No exploitEPSS 7%gimp · gimpJan 7, 2011
- CVE-2009-073339Monitor
Multiple stack-based buffer overflows in the ReadSetOfCurves function in LittleCMS (aka lcms or liblcms) before 1.18beta2, as used in Firefo
CriticalCVSS 9.3No exploitEPSS 6%littlecms · little cmsMar 23, 2009
- CVE-2009-072339Monitor
Multiple integer overflows in LittleCMS (aka lcms or liblcms) before 1.18beta2, as used in Firefox 3.1beta, OpenJDK, and GIMP, allow context
CriticalCVSS 9.3No exploitEPSS 5%gimp · gimpMar 23, 2009
- CVE-2026-5909039Monitor
Gimp: gimp: arbitrary code execution in psd plugin due to unsigned underflow
CriticalCVSS 9.9No exploitEPSS 1%gimp · gimpAug 10, 2026
- CVE-2025-276037Monitor
GIMP XWD File Parsing Integer Overflow Remote Code Execution Vulnerability
HighCVSS 7.8No exploitEPSS 19%gimp · gimpApr 23, 2025
- CVE-2018-1271337Monitor
GIMP through 2.10.2 makes g_get_tmp_dir calls to establish temporary filenames, which may result in a filename that already exists, as demon
CriticalCVSS 9.1No exploitEPSS 2%gimp · gimpJun 24, 2018
- CVE-2010-454335Monitor
Heap-based buffer overflow in the read_channel_data function in file-psp.c in the Paint Shop Pro (PSP) plugin in GIMP 2.6.11 allows remote a
HighCVSS 7.5Proof of conceptEPSS 16%gimp · gimpJan 7, 2011
- CVE-2026-079735Monitor
GIMP ICO File Parsing Heap-based Buffer Overflow Remote Code Execution Vulnerability
HighCVSS 8.8No exploitEPSS 1%gimp · gimpFeb 20, 2026
- CVE-2026-204435Monitor
GIMP PGM File Parsing Uninitialized Memory Remote Code Execution Vulnerability
HighCVSS 8.8No exploitEPSS 1%gimp · gimpFeb 20, 2026
- CVE-2007-235632Monitor
Stack-based buffer overflow in the set_color_table function in sunras.c in the SUNRAS plugin in Gimp 2.2.14 allows user-assisted remote atta
MediumCVSS 6.8Proof of conceptEPSS 16%gimp · gimpApr 30, 2007
- CVE-2012-557632Monitor
Multiple stack-based buffer overflows in file-xwd.c in the X Window Dump (XWD) plug-in in GIMP 2.8.2 allow remote attackers to cause a denia
HighCVSS 7.5No exploitEPSS 7%gimp · gimpDec 17, 2012
- CVE-2016-499432Monitor
Use-after-free vulnerability in the xcf_load_image function in app/xcf/xcf-load.c in GIMP allows remote attackers to cause a denial of servi
HighCVSS 7.8No exploitEPSS 3%gimp · gimpJul 12, 2016
- CVE-2025-1092532Monitor
GIMP ILBM File Parsing Stack-based Buffer Overflow Remote Code Execution Vulnerability
HighCVSS 7.8No exploitEPSS 3%gimp · gimpOct 29, 2025
- CVE-2025-276132Monitor
GIMP FLI File Parsing Out-Of-Bounds Write Remote Code Execution Vulnerability
HighCVSS 7.8No exploitEPSS 3%gimp · gimpApr 23, 2025
- CVE-2017-1778932Monitor
In GIMP 2.8.22, there is a heap-based buffer overflow in read_channel_data in plug-ins/common/file-psp.c.
HighCVSS 7.8No exploitEPSS 2%gimp · gimpDec 20, 2017
- CVE-2011-178231Monitor
Heap-based buffer overflow in the read_channel_data function in file-psp.c in the Paint Shop Pro (PSP) plugin in GIMP 2.6.11 allows remote a
HighCVSS 7.5No exploitEPSS 3%gimp · gimpJul 26, 2011
- CVE-2017-1778431Monitor
In GIMP 2.8.22, there is a heap-based buffer over-read in load_image in plug-ins/common/file-gbr.c in the gbr import parser, related to mish
HighCVSS 7.8No exploitEPSS 1%gimp · gimpDec 20, 2017