📦 Gimp

by Gimp

🔍 What is Gimp?

Description coming soon...

🛡️ Security Overview

Click on a severity to filter vulnerabilities

⚠️ Known Vulnerabilities

CVE-2026-2047

HIGH CVSS 7.8 Feb 20, 2026

This CVE describes a heap-based buffer overflow vulnerability in GIMP's ICNS file parser that allows remote code execution. Attackers can exploit this by tricking users into opening malicious ICNS fil...

CVE-2026-2044

HIGH CVSS 7.8 Feb 20, 2026

This vulnerability allows remote attackers to execute arbitrary code by tricking users into opening malicious PGM image files in GIMP. The flaw exists due to uninitialized memory access during PGM fil...

CVE-2025-15059

HIGH CVSS 7.8 Jan 23, 2026

This vulnerability allows remote attackers to execute arbitrary code by tricking users into opening malicious PSP files in GIMP. The heap-based buffer overflow occurs during PSP file parsing due to in...

CVE-2025-14422

HIGH CVSS 7.8 Dec 23, 2025

This vulnerability allows remote attackers to execute arbitrary code by tricking users into opening malicious PNM image files in GIMP. The integer overflow during PNM file parsing enables buffer overf...

CVE-2025-14423

HIGH CVSS 7.8 Dec 23, 2025

This vulnerability allows remote attackers to execute arbitrary code by tricking users into opening malicious LBM image files in GIMP. The flaw is a stack-based buffer overflow during LBM file parsing...

CVE-2025-14424

HIGH CVSS 7.8 Dec 23, 2025

This vulnerability allows remote attackers to execute arbitrary code by tricking users into opening malicious XCF files in GIMP. The use-after-free flaw in XCF file parsing can lead to full system com...

CVE-2025-14425

HIGH CVSS 7.8 Dec 23, 2025

This vulnerability in GIMP allows remote attackers to execute arbitrary code by tricking users into opening malicious JP2 image files. The flaw exists in how GIMP handles JP2 file data without proper ...

CVE-2025-10923

HIGH CVSS 7.8 Oct 29, 2025

This vulnerability allows remote attackers to execute arbitrary code on GIMP installations by tricking users into opening malicious WBMP image files. The integer overflow during WBMP parsing enables b...

CVE-2025-10924

HIGH CVSS 7.8 Oct 29, 2025

This vulnerability allows remote attackers to execute arbitrary code by tricking users into opening malicious FF files in GIMP. The integer overflow during file parsing enables buffer overflow leading...

CVE-2025-10934

HIGH CVSS 7.8 Oct 29, 2025

This vulnerability allows remote attackers to execute arbitrary code by tricking users into opening malicious XWD image files in GIMP. The heap-based buffer overflow occurs due to improper length vali...

CVE-2025-10921

HIGH CVSS 7.8 Oct 29, 2025

A heap-based buffer overflow vulnerability in GIMP's HDR file parser allows remote attackers to execute arbitrary code when users open malicious HDR files. This affects all GIMP installations that pro...

CVE-2025-10920

HIGH CVSS 7.8 Oct 29, 2025

This vulnerability allows remote attackers to execute arbitrary code by tricking users into opening malicious ICNS files in GIMP. The flaw exists in ICNS file parsing where improper data validation le...

CVE-2025-8672

HIGH CVSS 7.8 Aug 11, 2025

This vulnerability allows local attackers on macOS to abuse GIMP's bundled Python interpreter to access privacy-protected files without user consent. The Python interpreter inherits the Transparency, ...

CVE-2025-5473

HIGH CVSS 8.8 Jun 6, 2025

This vulnerability allows remote attackers to execute arbitrary code by tricking users into opening malicious ICO files in GIMP. An integer overflow during ICO file parsing enables memory corruption t...

CVE-2025-2760

HIGH CVSS 7.8 Apr 23, 2025

This vulnerability allows remote attackers to execute arbitrary code by tricking users into opening malicious XWD image files in GIMP. The integer overflow during file parsing enables buffer overflow ...

CVE-2023-44443

HIGH CVSS 7.8 May 3, 2024

This vulnerability allows remote attackers to execute arbitrary code by tricking users into opening malicious PSP image files in GIMP. An integer overflow during PSP file parsing enables memory corrup...

CVE-2023-44441

HIGH CVSS 7.8 May 3, 2024

This vulnerability allows remote attackers to execute arbitrary code on vulnerable GIMP installations by tricking users into opening malicious DDS image files. The heap-based buffer overflow occurs du...