Skip to content
Noroxi

GIMP records

110 published records for vendor gimp.

Researcher profile

Entered KEV
0 · 0%
Weaponized
1 · 0.9%
Pre-auth RCE
26
With a fix record
98.2%
Median publish → KEV
No record has entered KEV

All records

110 records
  • GIMP PSP File Parsing Integer Overflow Remote Code Execution Vulnerability

    HighCVSS 7.8No exploitEPSS 94%

    gimp · gimpMay 2, 2024

  • Buffer overflow in the readstr_upto function in plug-ins/script-fu/tinyscheme/scheme.c in GIMP 2.6.12 and earlier, and possibly 2.6.13, allo

    HighCVSS 7.5WeaponizedEPSS 82%

    gimp · gimpJul 12, 2012

  • GIMP PSD File Parsing Heap-based Buffer Overflow Remote Code Execution Vulnerability

    HighCVSS 7.8No exploitEPSS 61%

    gimp · gimpMay 2, 2024

  • GIMP PSP File Parsing Off-By-One Remote Code Execution Vulnerability

    HighCVSS 7.8No exploitEPSS 56%

    gimp · gimpMay 2, 2024

  • GIMP ICO File Parsing Integer Overflow Remote Code Execution Vulnerability

    HighCVSS 8.8No exploitEPSS 23%

    gimp · gimpJun 6, 2025

  • Integer overflow in the read_channel_data function in plug-ins/file-psd/psd-load.c in GIMP 2.6.7 might allow remote attackers to execute arb

    CriticalCVSS 9.3No exploitEPSS 9%

    gimp · gimpNov 18, 2009

  • GIMP DDS File Parsing Heap-based Buffer Overflow Remote Code Execution Vulnerability

    HighCVSS 7.8No exploitEPSS 27%

    gimp · gimpMay 2, 2024

  • CVE-2009-1570
    39Monitor

    Integer overflow in the ReadImage function in plug-ins/file-bmp/bmp-read.c in GIMP 2.6.7 might allow remote attackers to execute arbitrary c

    CriticalCVSS 9.3No exploitEPSS 8%

    gimp · gimpNov 13, 2009

  • CVE-2010-4541
    39Monitor

    Stack-based buffer overflow in the loadit function in plug-ins/common/sphere-designer.c in the SPHERE DESIGNER plugin in GIMP 2.6.11 allows

    CriticalCVSS 9.3No exploitEPSS 7%

    gimp · gimpJan 7, 2011

  • CVE-2009-0733
    39Monitor

    Multiple stack-based buffer overflows in the ReadSetOfCurves function in LittleCMS (aka lcms or liblcms) before 1.18beta2, as used in Firefo

    CriticalCVSS 9.3No exploitEPSS 6%

    littlecms · little cmsMar 23, 2009

  • CVE-2009-0723
    39Monitor

    Multiple integer overflows in LittleCMS (aka lcms or liblcms) before 1.18beta2, as used in Firefox 3.1beta, OpenJDK, and GIMP, allow context

    CriticalCVSS 9.3No exploitEPSS 5%

    gimp · gimpMar 23, 2009

  • Gimp: gimp: arbitrary code execution in psd plugin due to unsigned underflow

    CriticalCVSS 9.9No exploitEPSS 1%

    gimp · gimpAug 10, 2026

  • CVE-2025-2760
    37Monitor

    GIMP XWD File Parsing Integer Overflow Remote Code Execution Vulnerability

    HighCVSS 7.8No exploitEPSS 19%

    gimp · gimpApr 23, 2025

  • GIMP through 2.10.2 makes g_get_tmp_dir calls to establish temporary filenames, which may result in a filename that already exists, as demon

    CriticalCVSS 9.1No exploitEPSS 2%

    gimp · gimpJun 24, 2018

  • CVE-2010-4543
    35Monitor

    Heap-based buffer overflow in the read_channel_data function in file-psp.c in the Paint Shop Pro (PSP) plugin in GIMP 2.6.11 allows remote a

    HighCVSS 7.5Proof of conceptEPSS 16%

    gimp · gimpJan 7, 2011

  • CVE-2026-0797
    35Monitor

    GIMP ICO File Parsing Heap-based Buffer Overflow Remote Code Execution Vulnerability

    HighCVSS 8.8No exploitEPSS 1%

    gimp · gimpFeb 20, 2026

  • CVE-2026-2044
    35Monitor

    GIMP PGM File Parsing Uninitialized Memory Remote Code Execution Vulnerability

    HighCVSS 8.8No exploitEPSS 1%

    gimp · gimpFeb 20, 2026

  • CVE-2007-2356
    32Monitor

    Stack-based buffer overflow in the set_color_table function in sunras.c in the SUNRAS plugin in Gimp 2.2.14 allows user-assisted remote atta

    MediumCVSS 6.8Proof of conceptEPSS 16%

    gimp · gimpApr 30, 2007

  • CVE-2012-5576
    32Monitor

    Multiple stack-based buffer overflows in file-xwd.c in the X Window Dump (XWD) plug-in in GIMP 2.8.2 allow remote attackers to cause a denia

    HighCVSS 7.5No exploitEPSS 7%

    gimp · gimpDec 17, 2012

  • CVE-2016-4994
    32Monitor

    Use-after-free vulnerability in the xcf_load_image function in app/xcf/xcf-load.c in GIMP allows remote attackers to cause a denial of servi

    HighCVSS 7.8No exploitEPSS 3%

    gimp · gimpJul 12, 2016

  • GIMP ILBM File Parsing Stack-based Buffer Overflow Remote Code Execution Vulnerability

    HighCVSS 7.8No exploitEPSS 3%

    gimp · gimpOct 29, 2025

  • CVE-2025-2761
    32Monitor

    GIMP FLI File Parsing Out-Of-Bounds Write Remote Code Execution Vulnerability

    HighCVSS 7.8No exploitEPSS 3%

    gimp · gimpApr 23, 2025

  • In GIMP 2.8.22, there is a heap-based buffer overflow in read_channel_data in plug-ins/common/file-psp.c.

    HighCVSS 7.8No exploitEPSS 2%

    gimp · gimpDec 20, 2017

  • CVE-2011-1782
    31Monitor

    Heap-based buffer overflow in the read_channel_data function in file-psp.c in the Paint Shop Pro (PSP) plugin in GIMP 2.6.11 allows remote a

    HighCVSS 7.5No exploitEPSS 3%

    gimp · gimpJul 26, 2011

  • In GIMP 2.8.22, there is a heap-based buffer over-read in load_image in plug-ins/common/file-gbr.c in the gbr import parser, related to mish

    HighCVSS 7.8No exploitEPSS 1%

    gimp · gimpDec 20, 2017