| CVE-2026-82343 |
|
Medium |
Aug 28, 2026 |
A flaw was found in the file-psd plugin in GIMP. When processing a specially crafted PSD image file, the plugin does not properly validate the channel-
more...
A flaw was found in the file-psd plugin in GIMP. When processing a specially crafted PSD image file, the plugin does not properly validate the channel-count parameter. This incorrect validation leads to improper memory bounds checking, resulting in both a heap out-of-bounds read and a stack out-of-bounds access. This issue can result in an application crash, leading to a denial of service or a limited information disclosure of memory contents.
less...
|
3.2.6, 3.2.4, 3.2.2, 3.2.0, 3.0.8, 3.0.6, 3.0.4, 3.0.2, 3.0.0, 2.38
|
| CVE-2026-82330 |
|
Medium |
Aug 28, 2026 |
A flaw was found in the file-pvr plugin in GIMP. When processing a specially crafted PVR image file, the VQ (compressed) decoder does not properly perf
more...
A flaw was found in the file-pvr plugin in GIMP. When processing a specially crafted PVR image file, the VQ (compressed) decoder does not properly perform memory bounds checking. This missing validation results in a heap out-of-bounds read. This issue can result in an application crash, leading to a denial of service or a limited information disclosure of heap memory contents.
less...
|
3.2.6, 3.2.4, 3.2.2, 3.2.0, 3.0.8, 3.0.6, 3.0.4, 3.0.2, 3.0.0, 2.38
|
| CVE-2026-82328 |
|
Medium |
Aug 28, 2026 |
A flaw was found in the file-ico plugin in GIMP. When processing a specially crafted ICO image file, the plugin does not properly validate the used_clr
more...
A flaw was found in the file-ico plugin in GIMP. When processing a specially crafted ICO image file, the plugin does not properly validate the used_clrs (palette count) parameter. This incorrect validation leads to improper memory bounds checking, resulting in a heap out-of-bounds read. This issue can result in an application crash, leading to a denial of service or a limited information disclosure of heap memory contents.
less...
|
3.2.6, 3.2.4, 3.2.2, 3.2.0, 3.0.8, 3.0.6, 3.0.4, 3.0.2, 3.0.0, 2.38
|
| CVE-2026-82324 |
|
Medium |
Aug 28, 2026 |
A flaw was found in the file-iff (IFF/ILBM) plugin in GIMP. When processing a specially crafted IFF/ILBM image file, the plugin does not properly valid
more...
A flaw was found in the file-iff (IFF/ILBM) plugin in GIMP. When processing a specially crafted IFF/ILBM image file, the plugin does not properly validate the HAM row size and improperly handles cases where the number of color planes (nPlanes) is zero. This causes a row size mismatch that bypasses memory bounds checking, resulting in heap out-of-bounds reads. This issue can result in an application crash, leading to a denial of service or a limited information disclosure of heap memory contents.
less...
|
3.2.6, 3.2.4, 3.2.2, 3.2.0, 3.0.8, 3.0.6, 3.0.4, 3.0.2, 3.0.0, 2.38
|
| CVE-2026-80101 |
|
Medium |
Aug 25, 2026 |
A flaw was found in the file-xwd plugin in GIMP. When processing a specially crafted XWD image file, the plugin validates the image width and bytes-per
more...
A flaw was found in the file-xwd plugin in GIMP. When processing a specially crafted XWD image file, the plugin validates the image width and bytes-per-line parameters independently rather than ensuring their combined values are consistent with the allocated buffer size. This incorrect validation leads to improper bounds checking, causing a heap out-of-bounds read. This issue can result in an application crash, leading to a denial of service, or a limited information disclosure of heap memory contents into the produced image.
less...
|
3.2.6, 3.2.4, 3.2.2, 3.2.0, 3.0.8, 3.0.6, 3.0.4, 3.0.2, 3.0.0, 2.38
|
| CVE-2026-79902 |
|
Medium |
Aug 26, 2026 |
A flaw was found in the Seattle FilmWorks plugin in GIMP. When processing a specially crafted SFW image file, the plugin allocates a Variable-Length Ar
more...
A flaw was found in the Seattle FilmWorks plugin in GIMP. When processing a specially crafted SFW image file, the plugin allocates a Variable-Length Array (VLA) on the stack without integer overflow checks, causing an unbounded stack allocation. This issue leads to an application crash, resulting in a denial of service.
less...
|
3.2.6, 3.2.4, 3.2.2, 3.2.0, 3.0.8, 3.0.6, 3.0.4, 3.0.2, 3.0.0, 2.38
|
| CVE-2026-78475 |
|
Medium |
Aug 24, 2026 |
A flaw was found in the file-pix (ESM) plugin in GIMP. When processing a specially crafted PIX image file, the plugin allocates a Variable-Length Array
more...
A flaw was found in the file-pix (ESM) plugin in GIMP. When processing a specially crafted PIX image file, the plugin allocates a Variable-Length Array (VLA) on the stack without proper bounds checking, causing an unbounded stack allocation followed by a 21-byte stack over-read. This can result in a denial of service due to stack exhaustion and a limited information disclosure of stack memory contents into an intermediate file.
less...
|
3.2.6, 3.2.4, 3.2.2, 3.2.0, 3.0.8, 3.0.6, 3.0.4, 3.0.2, 3.0.0
|
| CVE-2026-66757 |
|
Medium |
Jul 27, 2026 |
A flaw was found in the file-sgi plugin in GIMP. When processing an RLE-compressed SGI image, the plugin allocates memory for a row table. The image he
more...
A flaw was found in the file-sgi plugin in GIMP. When processing an RLE-compressed SGI image, the plugin allocates memory for a row table. The image header dimensions (ysize and zsize) are read as 16-bit unsigned integers. If a crafted file sets both dimensions to their maximum value (65535), the multiplication ysize * zsize overflows the standard 32-bit int boundary before being passed to calloc. This integer overflow issue results in undefined behavior, aborting the plugin and causing a denial of service.
less...
|
3.2.6
|
| CVE-2026-59091 |
|
High |
Aug 10, 2026 |
A flaw was found in GIMP's file format plugins, including those for PSD and PAA files. A remote attacker could exploit these vulnerabilities by trickin
more...
A flaw was found in GIMP's file format plugins, including those for PSD and PAA files. A remote attacker could exploit these vulnerabilities by tricking a user into opening a specially crafted image file. This could lead to unexpected application behavior or other potential security impacts without requiring further user interaction.
less...
|
3.2.6
|
| CVE-2026-59089 |
|
Medium |
Jul 06, 2026 |
A flaw was found in GIMP. The PlayStation TIM loader, responsible for handling PlayStation image files, incorrectly calculates the size of the Color Lo
more...
A flaw was found in GIMP. The PlayStation TIM loader, responsible for handling PlayStation image files, incorrectly calculates the size of the Color Look-Up Table (CLUT) due to an integer overflow. This occurs when multiplying num_colors and num_cluts, both 16-bit unsigned short integers, resulting in a value exceeding the maximum integer limit. An attacker could exploit this by providing a specially crafted image file, leading to undefined behavior and causing the GIMP plug-in to abort, effectively resulting in a denial of service.
less...
|
3.2.6
|