| BDSA-2025-8455 |
|
Medium |
Aug 12, 2025 |
GIMP for macOS is vulnerable to privilege escalation due to the bundled Python interpreter inheriting Transparency, Consent, and Control (TCC) permissi
more...
GIMP for macOS is vulnerable to privilege escalation due to the bundled Python interpreter inheriting Transparency, Consent, and Control (TCC) permissions granted to the main application. This could allow an attacker with local access to execute arbitrary commands or scripts, potentially accessing privacy-protected files without user prompts or disguising malicious actions under the application's permissions.
less...
|
|
| BDSA-2025-12480 |
|
Medium |
Sep 25, 2025 |
GIMP is vulnerable to arbitrary code execution due to a stack-based buffer overflow in the ILBM file parsing functionality. This could allow an attacke
more...
GIMP is vulnerable to arbitrary code execution due to a stack-based buffer overflow in the ILBM file parsing functionality. This could allow an attacker to execute arbitrary code if a user opens a malicious file or visits a malicious page.
less...
|
|
| BDSA-2025-12479 |
|
Medium |
Sep 25, 2025 |
GIMP is vulnerable to arbitrary code execution (ACE) due to an integer overflow in the FF file parsing functionality. This could allow an attacker to e
more...
GIMP is vulnerable to arbitrary code execution (ACE) due to an integer overflow in the FF file parsing functionality. This could allow an attacker to execute arbitrary code if a user opens a malicious file or visits a malicious page.
less...
|
|
| BDSA-2025-12478 |
|
Medium |
Sep 25, 2025 |
GIMP is vulnerable to arbitrary code execution (ACE) due to an integer overflow in the `WBMP` file parsing functionality. This could allow an attacker
more...
GIMP is vulnerable to arbitrary code execution (ACE) due to an integer overflow in the `WBMP` file parsing functionality. This could allow an attacker to execute arbitrary code if a user opens a malicious file.
less...
|
|
| BDSA-2025-12477 |
|
Medium |
Sep 25, 2025 |
GIMP is vulnerable to arbitrary code execution (ACE) due to a heap-based buffer overflow in the parsing of `DCM` files. This could allow an attacker to
more...
GIMP is vulnerable to arbitrary code execution (ACE) due to a heap-based buffer overflow in the parsing of `DCM` files. This could allow an attacker to execute arbitrary code on the system if a user opens a malicious file or visits a malicious page.
less...
|
|
| BDSA-2025-12475 |
|
Medium |
Sep 25, 2025 |
GIMP is vulnerable to an arbitrary code execution (ACE) issue due to an out-of-bounds write in the ICNS file parsing component. This could allow an att
more...
GIMP is vulnerable to an arbitrary code execution (ACE) issue due to an out-of-bounds write in the ICNS file parsing component. This could allow an attacker to execute arbitrary code if a user opens a malicious file.
less...
|
|