Show filters
42 Total Results
Displaying 11-20 of 42
Sort by:
Attacker Value
Unknown
CVE-2017-17785
Disclosure Date: December 20, 2017 (last updated November 26, 2024)
In GIMP 2.8.22, there is a heap-based buffer overflow in the fli_read_brun function in plug-ins/file-fli/fli.c.
0
Attacker Value
Unknown
CVE-2017-17789
Disclosure Date: December 20, 2017 (last updated November 26, 2024)
In GIMP 2.8.22, there is a heap-based buffer overflow in read_channel_data in plug-ins/common/file-psp.c.
0
Attacker Value
Unknown
CVE-2017-17786
Disclosure Date: December 20, 2017 (last updated November 26, 2024)
In GIMP 2.8.22, there is a heap-based buffer over-read in ReadImage in plug-ins/common/file-tga.c (related to bgr2rgb.part.1) via an unexpected bits-per-pixel value for an RGBA image.
0
Attacker Value
Unknown
CVE-2017-17788
Disclosure Date: December 20, 2017 (last updated November 26, 2024)
In GIMP 2.8.22, there is a stack-based buffer over-read in xcf_load_stream in app/xcf/xcf.c when there is no '\0' character after the version string.
0
Attacker Value
Unknown
CVE-2016-4994
Disclosure Date: July 12, 2016 (last updated November 25, 2024)
Use-after-free vulnerability in the xcf_load_image function in app/xcf/xcf-load.c in GIMP allows remote attackers to cause a denial of service (program crash) or possibly execute arbitrary code via a crafted XCF file.
0
Attacker Value
Unknown
CVE-2013-1978
Disclosure Date: December 12, 2013 (last updated October 05, 2023)
Heap-based buffer overflow in the read_xwd_cols function in file-xwd.c in the X Window Dump (XWD) plug-in in GIMP 2.6.9 and earlier allows remote attackers to cause a denial of service (crash) and possibly execute arbitrary code via an X Window System (XWD) image dump with more colors than color map entries.
0
Attacker Value
Unknown
CVE-2013-1913
Disclosure Date: December 12, 2013 (last updated October 05, 2023)
Integer overflow in the load_image function in file-xwd.c in the X Window Dump (XWD) plug-in in GIMP 2.6.9 and earlier, when used with glib before 2.24, allows remote attackers to cause a denial of service (crash) and possibly execute arbitrary code via a large color entries value in an X Window System (XWD) image dump.
0
Attacker Value
Unknown
CVE-2012-5576
Disclosure Date: December 18, 2012 (last updated October 05, 2023)
Multiple stack-based buffer overflows in file-xwd.c in the X Window Dump (XWD) plug-in in GIMP 2.8.2 allow remote attackers to cause a denial of service (crash) and possibly execute arbitrary code via a large (1) red, (2) green, or (3) blue color mask in an XWD file.
0
Attacker Value
Unknown
CVE-2012-4245
Disclosure Date: August 31, 2012 (last updated October 05, 2023)
The scriptfu network server in GIMP 2.6 does not require authentication, which allows remote attackers to execute arbitrary commands via the python-fu-eval command.
0
Attacker Value
Unknown
CVE-2012-3481
Disclosure Date: August 25, 2012 (last updated November 08, 2023)
Integer overflow in the ReadImage function in plug-ins/common/file-gif-load.c in the GIF image format plug-in in GIMP 2.8.x and earlier allows remote attackers to cause a denial of service (application crash) and possibly execute arbitrary code via crafted height and len properties in a GIF image file, which triggers a heap-based buffer overflow. NOTE: some of these details are obtained from third party information.
0