Записи GIMP
110 опубликованных записей вендора gimp.
Профиль для исследователя
- Попали в KEV
- 0 · 0 %
- С эксплойтом
- 1 · 0,9 %
- Pre-auth RCE
- 26
- С записью об исправлении
- 98,2 %
- Медиана: публикация → KEV
- Ни одна запись не попала в KEV
Повторяющиеся классы
- CWE-190 Integer Overflow or Wraparound36
- CWE-787 Out-of-bounds Write21
- CWE-122 Heap-based Buffer Overflow14
- CWE-125 Out-of-bounds Read11
- CWE-120 Buffer Copy without Checking Size of Input ('Classic Buffer Overflow')5
- CWE-121 Stack-based Buffer Overflow3
Классы уязвимостей, которые чаще всего встречаются у этого вендора: куда смотреть.
CWEВсе записи
110 записей| Срочность | CVE | Уязвимость | Критичность | KEV | EPSS | Опубликовано |
|---|---|---|---|---|---|---|
59В плане | CVE-2023-44443Эксплойта нет | GIMP PSP File Parsing Integer Overflow Remote Code Execution Vulnerabilitygimp · gimp · CWE-190 | Высокая7,8 | — | 93,6 % | 2 мая 2024 г. |
55В плане | CVE-2012-2763Готовый эксплойт | Buffer overflow in the readstr_upto function in plug-ins/script-fu/tinyscheme/scheme.c in GIMP 2.6.12 and earlier, and possibly 2.6.13, allogimp · gimp · CWE-120 | Высокая7,5 | — | 81,7 % | 12 июл. 2012 г. |
49В плане | CVE-2023-44442Эксплойта нет | GIMP PSD File Parsing Heap-based Buffer Overflow Remote Code Execution Vulnerabilitygimp · gimp · CWE-122 | Высокая7,8 | — | 61,4 % | 2 мая 2024 г. |
48В плане | CVE-2023-44444Эксплойта нет | GIMP PSP File Parsing Off-By-One Remote Code Execution Vulnerabilitygimp · gimp · CWE-193 | Высокая7,8 | — | 56,4 % | 2 мая 2024 г. |
42В плане | CVE-2025-5473Эксплойта нет | GIMP ICO File Parsing Integer Overflow Remote Code Execution Vulnerabilitygimp · gimp · CWE-190 | Высокая8,8 | — | 23,5 % | 6 июн. 2025 г. |
40В плане | CVE-2009-3909Эксплойта нет | Integer overflow in the read_channel_data function in plug-ins/file-psd/psd-load.c in GIMP 2.6.7 might allow remote attackers to execute arbgimp · gimp · CWE-190 | Критическая9,3 | — | 8,7 % | 18 нояб. 2009 г. |
39Наблюдать | CVE-2023-44441Эксплойта нет | GIMP DDS File Parsing Heap-based Buffer Overflow Remote Code Execution Vulnerabilitygimp · gimp · CWE-122 | Высокая7,8 | — | 27,3 % | 2 мая 2024 г. |
39Наблюдать | CVE-2009-1570Эксплойта нет | Integer overflow in the ReadImage function in plug-ins/file-bmp/bmp-read.c in GIMP 2.6.7 might allow remote attackers to execute arbitrary cgimp · gimp · CWE-190 | Критическая9,3 | — | 8,0 % | 13 нояб. 2009 г. |
39Наблюдать | CVE-2010-4541Эксплойта нет | Stack-based buffer overflow in the loadit function in plug-ins/common/sphere-designer.c in the SPHERE DESIGNER plugin in GIMP 2.6.11 allows gimp · gimp · CWE-787 | Критическая9,3 | — | 6,8 % | 7 янв. 2011 г. |
39Наблюдать | CVE-2009-0733Эксплойта нет | Multiple stack-based buffer overflows in the ReadSetOfCurves function in LittleCMS (aka lcms or liblcms) before 1.18beta2, as used in Firefolittlecms · little cms · CWE-787 | Критическая9,3 | — | 5,5 % | 23 мар. 2009 г. |
39Наблюдать | CVE-2009-0723Эксплойта нет | Multiple integer overflows in LittleCMS (aka lcms or liblcms) before 1.18beta2, as used in Firefox 3.1beta, OpenJDK, and GIMP, allow contextgimp · gimp · CWE-190 | Критическая9,3 | — | 5,0 % | 23 мар. 2009 г. |
39Наблюдать | CVE-2026-59090Эксплойта нет | Gimp: gimp: arbitrary code execution in psd plugin due to unsigned underflowgimp · gimp · CWE-191 | Критическая9,9 | — | 0,6 % | 10 авг. 2026 г. |
37Наблюдать | CVE-2025-2760Эксплойта нет | GIMP XWD File Parsing Integer Overflow Remote Code Execution Vulnerabilitygimp · gimp · CWE-190 | Высокая7,8 | — | 18,8 % | 23 апр. 2025 г. |
37Наблюдать | CVE-2018-12713Эксплойта нет | GIMP through 2.10.2 makes g_get_tmp_dir calls to establish temporary filenames, which may result in a filename that already exists, as demongimp · gimp | Критическая9,1 | — | 1,9 % | 24 июн. 2018 г. |
35Наблюдать | CVE-2010-4543Proof of concept | Heap-based buffer overflow in the read_channel_data function in file-psp.c in the Paint Shop Pro (PSP) plugin in GIMP 2.6.11 allows remote agimp · gimp · CWE-787 | Высокая7,5 | — | 16,3 % | 7 янв. 2011 г. |
35Наблюдать | CVE-2026-0797Эксплойта нет | GIMP ICO File Parsing Heap-based Buffer Overflow Remote Code Execution Vulnerabilitygimp · gimp · CWE-122 | Высокая8,8 | — | 1,2 % | 20 февр. 2026 г. |
35Наблюдать | CVE-2026-2044Эксплойта нет | GIMP PGM File Parsing Uninitialized Memory Remote Code Execution Vulnerabilitygimp · gimp · CWE-908 | Высокая8,8 | — | 1,0 % | 20 февр. 2026 г. |
32Наблюдать | CVE-2007-2356Proof of concept | Stack-based buffer overflow in the set_color_table function in sunras.c in the SUNRAS plugin in Gimp 2.2.14 allows user-assisted remote attagimp · gimp · CWE-787 | Средняя6,8 | — | 15,7 % | 30 апр. 2007 г. |
32Наблюдать | CVE-2012-5576Эксплойта нет | Multiple stack-based buffer overflows in file-xwd.c in the X Window Dump (XWD) plug-in in GIMP 2.8.2 allow remote attackers to cause a deniagimp · gimp · CWE-787 | Высокая7,5 | — | 6,8 % | 17 дек. 2012 г. |
32Наблюдать | CVE-2016-4994Эксплойта нет | Use-after-free vulnerability in the xcf_load_image function in app/xcf/xcf-load.c in GIMP allows remote attackers to cause a denial of servigimp · gimp · CWE-416 | Высокая7,8 | — | 3,1 % | 12 июл. 2016 г. |
32Наблюдать | CVE-2025-10925Эксплойта нет | GIMP ILBM File Parsing Stack-based Buffer Overflow Remote Code Execution Vulnerabilitygimp · gimp · CWE-121 | Высокая7,8 | — | 3,1 % | 29 окт. 2025 г. |
32Наблюдать | CVE-2025-2761Эксплойта нет | GIMP FLI File Parsing Out-Of-Bounds Write Remote Code Execution Vulnerabilitygimp · gimp · CWE-787 | Высокая7,8 | — | 2,9 % | 23 апр. 2025 г. |
32Наблюдать | CVE-2017-17789Эксплойта нет | In GIMP 2.8.22, there is a heap-based buffer overflow in read_channel_data in plug-ins/common/file-psp.c.gimp · gimp · CWE-787 | Высокая7,8 | — | 2,0 % | 20 дек. 2017 г. |
31Наблюдать | CVE-2011-1782Эксплойта нет | Heap-based buffer overflow in the read_channel_data function in file-psp.c in the Paint Shop Pro (PSP) plugin in GIMP 2.6.11 allows remote agimp · gimp · CWE-787 | Высокая7,5 | — | 3,4 % | 26 июл. 2011 г. |
31Наблюдать | CVE-2017-17784Эксплойта нет | In GIMP 2.8.22, there is a heap-based buffer over-read in load_image in plug-ins/common/file-gbr.c in the gbr import parser, related to mishgimp · gimp · CWE-125 | Высокая7,8 | — | 1,5 % | 20 дек. 2017 г. |
- CVE-2023-4444359В плане
GIMP PSP File Parsing Integer Overflow Remote Code Execution Vulnerability
ВысокаяCVSS 7,8Эксплойта нетEPSS 94 %gimp · gimp2 мая 2024 г.
- CVE-2012-276355В плане
Buffer overflow in the readstr_upto function in plug-ins/script-fu/tinyscheme/scheme.c in GIMP 2.6.12 and earlier, and possibly 2.6.13, allo
ВысокаяCVSS 7,5Готовый эксплойтEPSS 82 %gimp · gimp12 июл. 2012 г.
- CVE-2023-4444249В плане
GIMP PSD File Parsing Heap-based Buffer Overflow Remote Code Execution Vulnerability
ВысокаяCVSS 7,8Эксплойта нетEPSS 61 %gimp · gimp2 мая 2024 г.
- CVE-2023-4444448В плане
GIMP PSP File Parsing Off-By-One Remote Code Execution Vulnerability
ВысокаяCVSS 7,8Эксплойта нетEPSS 56 %gimp · gimp2 мая 2024 г.
- CVE-2025-547342В плане
GIMP ICO File Parsing Integer Overflow Remote Code Execution Vulnerability
ВысокаяCVSS 8,8Эксплойта нетEPSS 23 %gimp · gimp6 июн. 2025 г.
- CVE-2009-390940В плане
Integer overflow in the read_channel_data function in plug-ins/file-psd/psd-load.c in GIMP 2.6.7 might allow remote attackers to execute arb
КритическаяCVSS 9,3Эксплойта нетEPSS 9 %gimp · gimp18 нояб. 2009 г.
- CVE-2023-4444139Наблюдать
GIMP DDS File Parsing Heap-based Buffer Overflow Remote Code Execution Vulnerability
ВысокаяCVSS 7,8Эксплойта нетEPSS 27 %gimp · gimp2 мая 2024 г.
- CVE-2009-157039Наблюдать
Integer overflow in the ReadImage function in plug-ins/file-bmp/bmp-read.c in GIMP 2.6.7 might allow remote attackers to execute arbitrary c
КритическаяCVSS 9,3Эксплойта нетEPSS 8 %gimp · gimp13 нояб. 2009 г.
- CVE-2010-454139Наблюдать
Stack-based buffer overflow in the loadit function in plug-ins/common/sphere-designer.c in the SPHERE DESIGNER plugin in GIMP 2.6.11 allows
КритическаяCVSS 9,3Эксплойта нетEPSS 7 %gimp · gimp7 янв. 2011 г.
- CVE-2009-073339Наблюдать
Multiple stack-based buffer overflows in the ReadSetOfCurves function in LittleCMS (aka lcms or liblcms) before 1.18beta2, as used in Firefo
КритическаяCVSS 9,3Эксплойта нетEPSS 6 %littlecms · little cms23 мар. 2009 г.
- CVE-2009-072339Наблюдать
Multiple integer overflows in LittleCMS (aka lcms or liblcms) before 1.18beta2, as used in Firefox 3.1beta, OpenJDK, and GIMP, allow context
КритическаяCVSS 9,3Эксплойта нетEPSS 5 %gimp · gimp23 мар. 2009 г.
- CVE-2026-5909039Наблюдать
Gimp: gimp: arbitrary code execution in psd plugin due to unsigned underflow
КритическаяCVSS 9,9Эксплойта нетEPSS 1 %gimp · gimp10 авг. 2026 г.
- CVE-2025-276037Наблюдать
GIMP XWD File Parsing Integer Overflow Remote Code Execution Vulnerability
ВысокаяCVSS 7,8Эксплойта нетEPSS 19 %gimp · gimp23 апр. 2025 г.
- CVE-2018-1271337Наблюдать
GIMP through 2.10.2 makes g_get_tmp_dir calls to establish temporary filenames, which may result in a filename that already exists, as demon
КритическаяCVSS 9,1Эксплойта нетEPSS 2 %gimp · gimp24 июн. 2018 г.
- CVE-2010-454335Наблюдать
Heap-based buffer overflow in the read_channel_data function in file-psp.c in the Paint Shop Pro (PSP) plugin in GIMP 2.6.11 allows remote a
ВысокаяCVSS 7,5Proof of conceptEPSS 16 %gimp · gimp7 янв. 2011 г.
- CVE-2026-079735Наблюдать
GIMP ICO File Parsing Heap-based Buffer Overflow Remote Code Execution Vulnerability
ВысокаяCVSS 8,8Эксплойта нетEPSS 1 %gimp · gimp20 февр. 2026 г.
- CVE-2026-204435Наблюдать
GIMP PGM File Parsing Uninitialized Memory Remote Code Execution Vulnerability
ВысокаяCVSS 8,8Эксплойта нетEPSS 1 %gimp · gimp20 февр. 2026 г.
- CVE-2007-235632Наблюдать
Stack-based buffer overflow in the set_color_table function in sunras.c in the SUNRAS plugin in Gimp 2.2.14 allows user-assisted remote atta
СредняяCVSS 6,8Proof of conceptEPSS 16 %gimp · gimp30 апр. 2007 г.
- CVE-2012-557632Наблюдать
Multiple stack-based buffer overflows in file-xwd.c in the X Window Dump (XWD) plug-in in GIMP 2.8.2 allow remote attackers to cause a denia
ВысокаяCVSS 7,5Эксплойта нетEPSS 7 %gimp · gimp17 дек. 2012 г.
- CVE-2016-499432Наблюдать
Use-after-free vulnerability in the xcf_load_image function in app/xcf/xcf-load.c in GIMP allows remote attackers to cause a denial of servi
ВысокаяCVSS 7,8Эксплойта нетEPSS 3 %gimp · gimp12 июл. 2016 г.
- CVE-2025-1092532Наблюдать
GIMP ILBM File Parsing Stack-based Buffer Overflow Remote Code Execution Vulnerability
ВысокаяCVSS 7,8Эксплойта нетEPSS 3 %gimp · gimp29 окт. 2025 г.
- CVE-2025-276132Наблюдать
GIMP FLI File Parsing Out-Of-Bounds Write Remote Code Execution Vulnerability
ВысокаяCVSS 7,8Эксплойта нетEPSS 3 %gimp · gimp23 апр. 2025 г.
- CVE-2017-1778932Наблюдать
In GIMP 2.8.22, there is a heap-based buffer overflow in read_channel_data in plug-ins/common/file-psp.c.
ВысокаяCVSS 7,8Эксплойта нетEPSS 2 %gimp · gimp20 дек. 2017 г.
- CVE-2011-178231Наблюдать
Heap-based buffer overflow in the read_channel_data function in file-psp.c in the Paint Shop Pro (PSP) plugin in GIMP 2.6.11 allows remote a
ВысокаяCVSS 7,5Эксплойта нетEPSS 3 %gimp · gimp26 июл. 2011 г.
- CVE-2017-1778431Наблюдать
In GIMP 2.8.22, there is a heap-based buffer over-read in load_image in plug-ins/common/file-gbr.c in the gbr import parser, related to mish
ВысокаяCVSS 7,8Эксплойта нетEPSS 1 %gimp · gimp20 дек. 2017 г.