Vendor
Out-of-Bounds Write Vulnerability in GIMP Lighting Effects Filter (CVE-2026-90947)
1 TTPGIMP contains an out-of-bounds write vulnerability in its Lighting Effects filter, allowing potential arbitrary code execution when processing a maliciously crafted lighting preset file.
Heap-Based Buffer Overflow in GIMP PSP File Loader
1 TTP 1 CVEA heap-based buffer overflow in GIMP's PSP file loader, tracked as CVE-2026-90949, allows attackers to trigger crashes or arbitrary code execution via crafted image files.
Multiple Vulnerabilities in GIMP Lead to DoS and Information Disclosure
1 CVEMultiple vulnerabilities in GIMP (CVE-2024-10332, CVE-2024-10333) allow a local attacker to cause a denial-of-service condition or perform information disclosure via malicious input files.
Heap-based Buffer Overflows in GIMP APNG and DDS Loaders
1 TTP 5 CVEsGIMP contains multiple heap-buffer-overflow vulnerabilities in its APNG and DDS file format loaders, which can lead to arbitrary code execution when a victim opens a specially crafted image file.
CVE-2026-66759: Out-of-Bounds Read in GIMP file-icns Plugin
1 CVEA critical out-of-bounds read vulnerability (CVE-2026-66759) has been identified in the GIMP file-icns plugin, where processing a crafted ICNS file with a truncated mask resource can lead to information disclosure of heap contents via leaked alpha channel pixel values or a denial of service due to an application crash.
CVE-2026-66758 - Integer Overflow in GIMP's file-fits Plugin Leads to RCE
1 CVEA vulnerability in the GIMP file-fits plugin allows for an integer overflow when processing crafted FITS image files, occurring during memory allocation calculations for width and height, which leads to an undersized heap-based buffer, and subsequent writing of pixel data to this buffer causes a heap-based buffer overflow and memory corruption, resulting in arbitrary code execution or a denial of service.
GIMP Vulnerability Allows Remote Code Execution
2 rules 1 TTPA remote, anonymous attacker can exploit a vulnerability in GIMP to execute arbitrary program code.
GIMP Multiple Vulnerabilities Allow Remote Code Execution
2 rules 1 TTPA remote, anonymous attacker can exploit multiple unspecified vulnerabilities in GIMP to execute arbitrary program code, potentially leading to complete system compromise.
Multiple Vulnerabilities in GIMP
2 rules 3 TTPsMultiple vulnerabilities in GIMP could allow an attacker to execute arbitrary code, disclose sensitive information, manipulate data, or cause a denial-of-service condition.