Goal Reached Thanks to every supporter — we hit 100%!

Goal: 1000 CNY · Raised: 1359 CNY

100%

GIMP — Vulnerabilities & Security Advisories 42

Browse all 42 CVE security advisories affecting GIMP. AI-powered Chinese analysis, POCs, and references for each vulnerability.

GIMP is a free and open-source raster graphics editor primarily used for image manipulation, composition, and conversion. As a desktop application rather than a web service, it does not typically suffer from remote code execution or cross-site scripting vulnerabilities common in server-side software. Its security profile is largely defined by local privilege escalation risks and memory corruption issues within its core libraries, such as ImageMagick, which it relies on for parsing various file formats. Historically, flaws have allowed attackers to execute arbitrary code or crash the application through malformed images, though these rarely impact system integrity beyond the user’s session. The current record of thirty Common Vulnerabilities and Exposures highlights ongoing maintenance challenges in its complex codebase. While no major widespread breaches have occurred, the reliance on external libraries necessitates rigorous patching to mitigate potential exploitation vectors for local users.

Top products by GIMP: GIMP
CVE ID Title CVSS Severity Published
CVE-2025-10923 GIMP WBMP File Parsing Integer Overflow Remote Code Execution Vulnerability — GIMP CWE-190 7.8AI High AI 2025-10-29
CVE-2025-10922 GIMP DCM File Parsing Heap-based Buffer Overflow Remote Code Execution Vulnerability — GIMP CWE-122 7.8AI High AI 2025-10-29
CVE-2025-10921 GIMP HDR File Parsing Heap-based Buffer Overflow Remote Code Execution Vulnerability — GIMP CWE-122 7.8AI High AI 2025-10-29
CVE-2025-10920 GIMP ICNS File Parsing Out-Of-Bounds Write Remote Code Execution Vulnerability — GIMP CWE-787 7.8AI High AI 2025-10-29
CVE-2025-8672 TCC Bypass via Inherited Permissions in Bundled Interpreter in GIMP.app — GIMP CWE-276 6.6AI Medium AI 2025-08-11
CVE-2025-5473 GIMP ICO File Parsing Integer Overflow Remote Code Execution Vulnerability — GIMP CWE-190 7.8AI High AI 2025-06-06
CVE-2025-2761 GIMP FLI File Parsing Out-Of-Bounds Write Remote Code Execution Vulnerability — GIMP CWE-787 7.8 - 2025-04-23
CVE-2025-2760 GIMP XWD File Parsing Integer Overflow Remote Code Execution Vulnerability — GIMP CWE-190 7.8 - 2025-04-23
CVE-2023-44444 GIMP PSP File Parsing Off-By-One Remote Code Execution Vulnerability — GIMP CWE-193 7.8 - 2024-05-03
CVE-2023-44443 GIMP PSP File Parsing Integer Overflow Remote Code Execution Vulnerability — GIMP CWE-190 7.8 - 2024-05-03
CVE-2023-44442 GIMP PSD File Parsing Heap-based Buffer Overflow Remote Code Execution Vulnerability — GIMP CWE-122 7.8 - 2024-05-03
CVE-2023-44441 GIMP DDS File Parsing Heap-based Buffer Overflow Remote Code Execution Vulnerability — GIMP CWE-122 7.8 - 2024-05-03

This page lists every published CVE security advisory associated with GIMP. Each entry links to a detailed page with CVSS scoring, CWE classification, affected products and references. AI-generated Chinese analysis is provided for fast triage.