Vulnerabilidades
Resumen — últimos 7 días
Vulnerabilidades nuevas2855▼ 333 respecto a la semana anterior
Críticas / altas1381▼ 36 respecto a la semana anterior
Nueva explotación activa (KEV)4▼ 5 respecto a la semana anterior
Sin puntuar (sin CVSS)296▼ 213 respecto a la semana anterior
127 resultados, ordenados por fecha de publicación (más recientes primero)
| CVE | Estado | Severidad | EPSS | Explotación activa | Tecnologías afectadas | Publicada ▼ | Modificada | Descripción |
|---|---|---|---|---|---|---|---|---|
| Analizada | Media (4.8) | 0.33% | — | Gimp | 11/8/2025 | 17/6/2026 | MacOS version of GIMP bundles a Python interpreter that inherits the Transparency, Consent, and Control (TCC) permissions granted by the user to the main application bundle. An attacker with local user access can invoke this interpreter with arbitrary commands or scripts, leveraging the application's previously… | |
| Modificada | Alta (7.8) | 0.57% | — | Gimp | 13/6/2025 | 30/6/2026 | A flaw was found in GIMP. An integer overflow vulnerability exists in the GIMP "Despeckle" plug-in. The issue occurs due to unchecked multiplication of image dimensions, such as width, height, and bytes-per-pixel (img_bpp), which can result in allocating insufficient memory and subsequently performing out-of-bounds… | |
| Modificada | Alta (8.8) | 23% | — | Gimp | 6/6/2025 | 17/6/2026 | GIMP ICO File Parsing Integer Overflow Remote Code Execution Vulnerability. This vulnerability allows remote attackers to execute arbitrary code on affected installations of GIMP. User interaction is required to exploit this vulnerability in that the target must visit a malicious page or open a malicious file. The… | |
| Aplazada | Alta (7.3) | 0.24% | — | GimpAI | 27/5/2025 | 30/6/2026 | A flaw was found in GIMP when processing XCF image files. If a user opens one of these image files that has been specially crafted by an attacker, GIMP can be tricked into making serious memory errors, potentially leading to crashes and causing use-after-free issues. | |
| Aplazada | Alta (7.3) | 0.27% | — | GimpAI | 27/5/2025 | 30/6/2026 | A flaw was found in GIMP when processing certain TGA image files. If a user opens one of these image files that has been specially crafted by an attacker, GIMP can be tricked into making serious memory errors, potentially leading to crashes and causing a heap buffer overflow. | |
| Aplazada | Alta (7.3) | 0.20% | — | GimpAI | 27/5/2025 | 30/6/2026 | A flaw was found in GIMP. The GIMP ani_load_image() function is vulnerable to a stack-based overflow. If a user opens.ANI files, GIMP may be used to store more information than the capacity allows. This flaw allows a malicious ANI file to trigger arbitrary code execution. | |
| Modificada | Alta (7.8) | 2.8% | — | Gimp | 23/4/2025 | 17/6/2026 | GIMP FLI File Parsing Out-Of-Bounds Write Remote Code Execution Vulnerability. This vulnerability allows remote attackers to execute arbitrary code on affected installations of GIMP. User interaction is required to exploit this vulnerability in that the target must visit a malicious page or open a malicious file. The… | |
| Modificada | Alta (7.8) | 19% | — | Gimp | 23/4/2025 | 17/6/2026 | GIMP XWD File Parsing Integer Overflow Remote Code Execution Vulnerability. This vulnerability allows remote attackers to execute arbitrary code on affected installations of GIMP. User interaction is required to exploit this vulnerability in that the target must visit a malicious page or open a malicious file. The… | |
| Modificada | Alta (7.8) | 56% | — | Gimp | 3/5/2024 | 17/6/2026 | GIMP PSP File Parsing Off-By-One Remote Code Execution Vulnerability. This vulnerability allows remote attackers to execute arbitrary code on affected installations of GIMP. User interaction is required to exploit this vulnerability in that the target must visit a malicious page or open a malicious file. The specific… | |
| Analizada | Alta (7.8) | 94% | — | Gimp | 3/5/2024 | 17/6/2026 | GIMP PSP File Parsing Integer Overflow Remote Code Execution Vulnerability. This vulnerability allows remote attackers to execute arbitrary code on affected installations of GIMP. User interaction is required to exploit this vulnerability in that the target must visit a malicious page or open a malicious file. The… | |
| Modificada | Alta (7.8) | 61% | — | Gimp | 3/5/2024 | 17/6/2026 | GIMP PSD File Parsing Heap-based Buffer Overflow Remote Code Execution Vulnerability. This vulnerability allows remote attackers to execute arbitrary code on affected installations of GIMP. User interaction is required to exploit this vulnerability in that the target must visit a malicious page or open a malicious… | |
| Modificada | Alta (7.8) | 27% | — | Gimp | 3/5/2024 | 17/6/2026 | GIMP DDS File Parsing Heap-based Buffer Overflow Remote Code Execution Vulnerability. This vulnerability allows remote attackers to execute arbitrary code on affected installations of GIMP. User interaction is required to exploit this vulnerability in that the target must visit a malicious page or open a malicious… | |
| Modificada | Media (5.5) | 0.67% | — | Gimp | 24/6/2022 | 17/6/2026 | An issue in gimp_layer_invalidate_boundary of GNOME GIMP 2.10.30 allows attackers to trigger an unhandled exception via a crafted XCF file, causing a Denial of Service (DoS). | |
| Modificada | Media (5.5) | 0.76% | — | Gimp | 17/5/2022 | 17/6/2026 | GIMP 2.10.30 and 2.99.10 are vulnerable to Buffer Overflow. Through a crafted XCF file, the program will allocate for a huge amount of memory, resulting in insufficient memory or program crash. | |
| Modificada | Alta (7.8) | 1.4% | — | GeglGimpRedhat Enterprise LinuxFedoraproject Fedora | 23/12/2021 | 17/6/2026 | load_cache in GEGL before 0.4.34 allows shell expansion when a pathname in a constructed command line is not escaped or filtered. This is caused by use of the system library function for execution of the ImageMagick convert fallback in magick-load. NOTE: GEGL releases before 0.4.34 are used in GIMP releases before… | |
| Modificada | Crítica (9.1) | 1.9% | — | Gimp | 24/6/2018 | 17/6/2026 | GIMP through 2.10.2 makes g_get_tmp_dir calls to establish temporary filenames, which may result in a filename that already exists, as demonstrated by the gimp_write_and_read_file function in app/tests/test-xcf.c. This might be leveraged by attackers to overwrite files or read file content that was intended to be… | |
| Modificada | Alta (7.8) | 2.0% | — | GimpDebian LinuxCanonical Ubuntu Linux | 20/12/2017 | 17/6/2026 | In GIMP 2.8.22, there is a heap-based buffer overflow in read_channel_data in plug-ins/common/file-psp.c. | |
| Modificada | Media (5.5) | 1.1% | — | GimpDebian LinuxCanonical Ubuntu Linux | 20/12/2017 | 17/6/2026 | In GIMP 2.8.22, there is a stack-based buffer over-read in xcf_load_stream in app/xcf/xcf.c when there is no '\0' character after the version string. | |
| Modificada | Alta (7.8) | 1.2% | — | GimpDebian LinuxCanonical Ubuntu Linux | 20/12/2017 | 17/6/2026 | In GIMP 2.8.22, there is a heap-based buffer over-read in read_creator_block in plug-ins/common/file-psp.c. | |
| Modificada | Alta (7.8) | 1.3% | — | GimpDebian LinuxCanonical Ubuntu Linux | 20/12/2017 | 17/6/2026 | In GIMP 2.8.22, there is a heap-based buffer over-read in ReadImage in plug-ins/common/file-tga.c (related to bgr2rgb.part.1) via an unexpected bits-per-pixel value for an RGBA image. | |
| Modificada | Alta (7.8) | 1.1% | — | GimpDebian LinuxCanonical Ubuntu Linux | 20/12/2017 | 17/6/2026 | In GIMP 2.8.22, there is a heap-based buffer overflow in the fli_read_brun function in plug-ins/file-fli/fli.c. | |
| Modificada | Alta (7.8) | 1.5% | — | GimpDebian LinuxCanonical Ubuntu Linux | 20/12/2017 | 17/6/2026 | In GIMP 2.8.22, there is a heap-based buffer over-read in load_image in plug-ins/common/file-gbr.c in the gbr import parser, related to mishandling of UTF-8 data. | |
| Modificada | Alta (7.3) | 0.27% | — | Gentoo Sci-mathematics-gimps | 15/9/2017 | 17/6/2026 | The Gentoo sci-mathematics/gimps package before 28.10-r1 for Great Internet Mersenne Prime Search (GIMPS) allows local users to gain privileges by creating a hard link under /var/lib/gimps, because an unsafe "chown -R" command is executed. | |
| Modificada | Alta (7.8) | 3.1% | — | Gimp | 12/7/2016 | 17/6/2026 | Use-after-free vulnerability in the xcf_load_image function in app/xcf/xcf-load.c in GIMP allows remote attackers to cause a denial of service (program crash) or possibly execute arbitrary code via a crafted XCF file. | |
| Modificada | Media (6.8) | 4.2% | — | GimpRedhat Enterprise Linux | 12/12/2013 | 16/6/2026 | Heap-based buffer overflow in the read_xwd_cols function in file-xwd.c in the X Window Dump (XWD) plug-in in GIMP 2.6.9 and earlier allows remote attackers to cause a denial of service (crash) and possibly execute arbitrary code via an X Window System (XWD) image dump with more colors than color map entries. |