Search CVE reports


Toggle filters

1 – 10 of 49 results


CVE-2025-8672

Medium priority
Not affected

MacOS version of GIMP bundles a Python interpreter that inherits the Transparency, Consent, and Control (TCC) permissions granted by the user to the main application bundle. An attacker with local user access can invoke this...

1 affected package

gimp

Package 24.04 LTS 22.04 LTS 20.04 LTS 18.04 LTS
gimp Not affected Not affected Not affected Not affected
Show less packages

CVE-2025-6035

Medium priority
Needs evaluation

A flaw was found in GIMP. An integer overflow vulnerability exists in the GIMP “Despeckle” plug-in. The issue occurs due to unchecked multiplication of image dimensions, such as width, height, and bytes-per-pixel (img_bpp), which...

1 affected package

gimp

Package 24.04 LTS 22.04 LTS 20.04 LTS 18.04 LTS
gimp Needs evaluation Needs evaluation Needs evaluation Needs evaluation
Show less packages

CVE-2025-5473

Medium priority
Needs evaluation

GIMP ICO File Parsing Integer Overflow Remote Code Execution Vulnerability. This vulnerability allows remote attackers to execute arbitrary code on affected installations of GIMP. User interaction is required to exploit this...

1 affected package

gimp

Package 24.04 LTS 22.04 LTS 20.04 LTS 18.04 LTS
gimp Needs evaluation Needs evaluation Needs evaluation Needs evaluation
Show less packages

CVE-2025-48798

Medium priority
Needs evaluation

A flaw was found in GIMP when processing XCF image files. If a user opens one of these image files that has been specially crafted by an attacker, GIMP can be tricked into making serious memory errors, potentially leading to...

1 affected package

gimp

Package 24.04 LTS 22.04 LTS 20.04 LTS 18.04 LTS
gimp Needs evaluation Needs evaluation Needs evaluation Needs evaluation
Show less packages

CVE-2025-48797

Medium priority
Needs evaluation

A flaw was found in GIMP when processing certain TGA image files. If a user opens one of these image files that has been specially crafted by an attacker, GIMP can be tricked into making serious memory errors, potentially leading...

1 affected package

gimp

Package 24.04 LTS 22.04 LTS 20.04 LTS 18.04 LTS
gimp Needs evaluation Needs evaluation Needs evaluation Needs evaluation
Show less packages

CVE-2025-48796

Medium priority
Needs evaluation

A flaw was found in GIMP. The GIMP ani_load_image() function is vulnerable to a stack-based overflow. If a user opens.ANI files, GIMP may be used to store more information than the capacity allows. This flaw allows a malicious ANI...

1 affected package

gimp

Package 24.04 LTS 22.04 LTS 20.04 LTS 18.04 LTS
gimp Needs evaluation Needs evaluation Needs evaluation Needs evaluation
Show less packages

CVE-2025-2761

Medium priority
Needs evaluation

GIMP FLI File Parsing Out-Of-Bounds Write Remote Code Execution Vulnerability. This vulnerability allows remote attackers to execute arbitrary code on affected installations of GIMP. User interaction is required to exploit this...

1 affected package

gimp

Package 24.04 LTS 22.04 LTS 20.04 LTS 18.04 LTS
gimp Needs evaluation Needs evaluation Needs evaluation Needs evaluation
Show less packages

CVE-2025-2760

Medium priority
Needs evaluation

GIMP XWD File Parsing Integer Overflow Remote Code Execution Vulnerability. This vulnerability allows remote attackers to execute arbitrary code on affected installations of GIMP. User interaction is required to exploit this...

1 affected package

gimp

Package 24.04 LTS 22.04 LTS 20.04 LTS 18.04 LTS
gimp Needs evaluation Needs evaluation Needs evaluation Needs evaluation
Show less packages

CVE-2023-44444

Medium priority

Some fixes available 4 of 6

GIMP PSP File Parsing Off-By-One Remote Code Execution Vulnerability. This vulnerability allows remote attackers to execute arbitrary code on affected installations of GIMP. User interaction is required to exploit...

1 affected package

gimp

Package 24.04 LTS 22.04 LTS 20.04 LTS 18.04 LTS
gimp Not affected Fixed Fixed Needs evaluation
Show less packages

CVE-2023-44443

Medium priority
Fixed

GIMP PSP File Parsing Integer Overflow Remote Code Execution Vulnerability. This vulnerability allows remote attackers to execute arbitrary code on affected installations of GIMP. User interaction is required to exploit this...

1 affected package

gimp

Package 24.04 LTS 22.04 LTS 20.04 LTS 18.04 LTS
gimp Fixed Not affected Not affected
Show less packages